Daily OT Security News — August 12, 2026. Below are summaries of the top operational-technology and IoT security stories affecting healthcare, energy, manufacturing, and physical security environments.
August ICS Patch Tuesday Brings Critical Fixes for Siemens, Schneider Electric, and Phoenix Contact
Siemens published 10 August 2026 advisories, including a maximum-severity missing-authentication flaw in SIMATIC IoT2050 Advanced that can let a remote unauthenticated attacker execute arbitrary code with elevated privileges. Siemens also addressed a critical code-execution issue in Siveillance Video Management Servers. Schneider issued advisories for NetBotz 5 and PowerChute Serial Shutdown, while Phoenix Contact issued an advisory for PLCnext firmware vulnerabilities.
Source: SecurityWeek
CISA Warns of Critical Mira Hormone Monitor and Companion-App Vulnerabilities
CISA released ICS Medical Advisory ICSMA-26-223-01 on August 11, 2026 for Mira Monitor firmware 1.7.1.47 and the Mira Android App 4.5.15.4, noting potential impacts including unauthorized access or modification of health profiles, denial of service, session-token disclosure, and account takeover. CISA says users should update the Android app to 4.5.18 and firmware to 01.07.01.53 via the app. CISA also states that no targeted public exploitation has been reported.
Source: CISA
CERT.PL Details Private-APN Path Into a Polish Combined Heat and Power Plant
CERT.PL’s post mortem describes an intrusion that began with a compromised FortiGate at a wind farm, then used a Teltonika cellular router and a private APN to reach a WAGO PFC200 at a combined heat and power plant where default administrative credentials were used. The actors placed three Siemens PLCs into STOP mode and password-protected them, interrupting the plant’s steam turbine and process-water system. Recovery was completed before customer power loss occurred.
Source: Infosecurity Magazine
Joint Advisory Urges Urgent Defenses Against Gunra Ransomware
CISA, the FBI, other U.S. agencies, and the Korean National Police issued a joint advisory on Gunra ransomware-as-a-service that describes affiliates exploiting known vulnerabilities in internet-facing devices and stealing data before encryption. The advisory says Gunra affiliates have targeted sectors including critical manufacturing, utilities, transportation, and healthcare. Recommended actions include keeping firmware and software current, patching internet-facing known-exploited vulnerabilities urgently, maintaining isolated tested backups, and segmenting networks.
Source: ExecutiveGov
Make UK Research Finds Manufacturing Cyber-Resilience Gaps Remain Material
New Make UK research reports that 30% of manufacturers experienced a cyber incident directly or through their supply chain in the last year, and 46% cited increased operating costs and production downtime. The research highlights persistent gaps in patching, incident response planning, senior ownership, and recovery testing. Of manufacturers affected by supplier incidents, 31% reported delays and 31% reduced capacity, while 23% reported shortages of components or materials.
Source: ITPro
Monitor vendor advisories, prioritize vulnerable Internet-facing devices, and align patching and credential hygiene with operational priorities to reduce exposure across OT and IoT environments.