Daily OT Security News — August 18, 2026. This briefing highlights the most consequential recent reporting on operational technology, cyber-physical systems, and connected-device security. It distinguishes reported events from vendor and industry analysis where appropriate.
Water-Sector Intrusion Highlights Internet-Exposed PLC Risk
A recent Palo Alto Networks analysis reports that a coordinated intrusion locked operators out of water and wastewater controls in more than 30 Minnesota communities. The account says attackers reached internet-exposed controllers, relied on weak or default credentials, and in some cases exploited CVE-2021-22681 before altering device network settings and passwords; the article also reports modified ladder logic on at least one system. The incident analysis reinforces that internet exposure, unmanaged credentials, and flat IT/OT networks can turn legacy, difficult-to-patch controllers into operationally significant risk. The account and its technical details are attributed to the vendor-authored analysis.
Source: Palo Alto Networks — The Water-Sector Reckoning Is Here
Data-Centre HVAC and Building Systems Face Significant CPS Exposure
HVAC&R News reports that Claroty research found 32% of data-centre HVAC and cooling systems either directly exposed to the internet or one network hop from risky public-internet connectivity. The report also describes exposure among power-distribution and building-management systems, legacy insecure protocols in OT and IoT communications, and known exploited vulnerabilities in connected devices. It notes that fixes are available for vulnerabilities affecting Danfoss AK-SM 800A, Copeland XWEB Pro, and Trane Tracer platforms, emphasizing the need to isolate equipment-management interfaces from public networks and apply vendor remediation where operationally feasible.
Source: HVAC&R News — Heads up on hacker risks for HVAC
Industry Perspective: IoT Connectivity Remains a Security-Control Blind Spot
An IoT Now industry commentary argues that large connected-device fleets can retain a visibility and control gap at the carrier, SIM, and eSIM connectivity layer even when enterprises deploy conventional asset-discovery, SIEM, identity, and OT/IoT security tooling. The author advocates treating connectivity profiles as security identities that can be monitored and acted upon, particularly for field devices that operate outside enterprise-managed networks. This is an industry viewpoint rather than independent incident reporting, but it raises a practical governance consideration for organizations operating distributed IoT, utility, automotive, and public-safety device estates.
Editorial note: Sources include a vendor analysis, a secondary industry news report, and an industry commentary. Readers should consult the linked materials and relevant vendor or government advisories before making technical or operational decisions.