Daily OT Security News — August 11, 2026. OT, IoT, ICS, and other critical‑infrastructure systems remain in focus as incidents and advisories this week span water utilities, manufacturing, and consumer‑grade devices that interface with operational environments. Below are five verified developments and their immediate defensive implications.
Multistate Water-System Attacks Widen as Internet-Exposed PLCs Remain a Target
Dark Reading reports cyberattacks on water and wastewater organizations in at least a dozen U.S. states. Reported tactics include low‑complexity attacks against industrial controllers such as changing PLC passwords to lock out operators and altering PLC IP addresses to disconnect devices; attribution is not definitive, and possible Iranian links are suspected but not established.
Source: Dark Reading
CISA, FBI, and Partners Warn of Gunra Ransomware Targeting Critical Infrastructure
Meritalk reports that on August 10 CISA, the FBI, and U.S. and international partners issued a joint advisory on the Gunra ransomware‑as‑a‑service operation. The advisory says affiliates exploit vulnerabilities in internet‑facing systems to steal and encrypt data using a Tor‑based double‑extortion model and urges urgent remediation, current software and firmware, segmentation, and immutable, offline‑tested backups.
Source: Meritalk
Kimwolf v7 Adds Stealthier DDoS and Resilient C2 Capabilities for Android IoT Devices
Unit 42 identifies Kimwolf v7 as an Android and IoT botnet affecting Android TV boxes and set‑top boxes; the variant introduces an HTTP/2 DDoS flood that constructs browser fingerprints and layered C2 resolution using the Ethereum Name Service, Tor, and a local proxy. The malware can spread by reaching unauthenticated Android Debug Bridge instances on port 5555 via residential proxies; Unit 42 recommends disabling or restricting ADB and segmenting these devices.
Source: Unit 42 (Palo Alto Networks)
Manufacturers Urged to Test Cyber Recovery Plans Across Production and Supply Chains
Coverage of Make UK’s Cyber Security in Manufacturing report emphasizes that cyber resilience must encompass production, logistics, and safety rather than only IT restoration, and it recommends mapping machinery, platforms, service providers, and supply‑chain dependencies. The report cites patch management at 36% of surveyed manufacturers and notes 10% reported an incident with financial or business impact, advising tests of recovery for production schedules, order management, logistics, and customer commitments.
Source: IoT Tech News
Water Watch Center Launches Funded MDR Support for Small Water Utilities
Cybersecurity Dive reports that DEF CON Franklin will fund monitoring and protection products for water utilities serving fewer than 10,000 people, with five MDR providers initially participating. The National Rural Water Association will run the Water Watch Center and share anonymized threat intelligence with WaterISAC; when a participating vendor detects a potential attack or vulnerability it alerts the utility and provides a report so the utility can remediate or seek volunteer assistance.
Source: Cybersecurity Dive
Practical defensive priorities: ensure internet‑facing systems are patched and firmware/software current, maintain immutable offline‑tested backups, enforce network segmentation, map and test production and supply‑chain recovery plans, restrict or disable unauthenticated ADB on consumer/OT devices, and evaluate MDR or shared threat‑intelligence options for small utilities.