Daily OT Security News: August 11, 2026

Polish CHP Intrusion Shows How Private APNs Can Become an OT Pivot Path

Security Affairs reports a CERT Polska follow-up on an attack against a smaller combined heat and power plant serving about 50,000 residents in which the reported path began at an internet-exposed Fortinet device at a wind farm, moved through a Teltonika cellular router and a private APN, and reached the plant’s OT network; reported activity included access to a Wago PLC and Siemens PLCs, controller stop-mode changes, password locking, damage to a Wago controller, and reconfiguration of Moxa equipment. Security Affairs

Industrial Ransomware Activity Rose in Q2, With IT Disruption Still a Production Risk

Help Net Security, citing Dragos, reports 1,140 ransomware incidents involving industrial organizations in Q2 2026 (up 12% from 1,020 in Q1), with manufacturing accounting for 747 incidents and engineering firms, system integrators, and equipment manufacturers supporting ICS environments accounting for 117, and emphasizes that ransomware can interrupt production by disrupting enterprise IT even when there is no evidence of direct control-system access or OT manipulation. Help Net Security

Minnesota Water Incidents Reinforce the Risk of Internet-Reachable PLCs and Remote Assets

IOActive reports Minnesota IT Services characterized activity across more than 30 community water systems on July 26 and 27, 2026 as a coordinated cyberattack with automated control functions affected at several utilities, and the reporting notes authorities had not publicly named an actor, exploited vulnerability, or affected product line while highlighting the July 22 update to joint advisory AA26-097A and recommending verification of controller exposure (including cellular and other remote links), preservation of offline controller logic baselines, and application of remote-access safeguards. IOActive

Share this