Daily OT Security News: August 19, 2026

Today’s OT/ICS security news highlights persistent ransomware pressure, vulnerabilities in monitoring and engineering tools, a mapped campaign against U.S. water systems with contested attribution, and a U.S. federal R&D strategy that elevates OT/ICS resilience as a priority area.

FBI, CISA, and HHS update Medusa ransomware advisory

The agencies state that Medusa is a ransomware-as-a-service operation using double extortion and say developers and affiliates had affected more than 500 victims across critical-infrastructure sectors, including manufacturing and healthcare, as of April 2026. The update highlights opportunistic exploitation of unpatched vulnerabilities, affiliate/initial-access broker activity, and recommends risk-informed patching, network segmentation, and restricting remote-service access.

Source: IC3

CISA publishes Malcolm network-analysis-suite advisory

CISA says affected Malcolm releases contain six vulnerabilities, including an authenticated arbitrary-code-execution issue (CVE-2026-55676, CVSS 8.8) and authorization-bypass and archive-handling flaws. CISA cites vendor fixes in Malcolm 26.06.1, 26.07.0, and 26.08.0 and reports no known public exploitation specifically targeting these issues.

Source: CISA

CISA republishes Siemens Simcenter Nastran advisory

CISA republishes that Siemens Simcenter Femap and Simcenter Nastran versions earlier than V2606 are affected by CVE-2026-59086, a stack-based buffer overflow with CVSS 7.8 where a malicious file argument may enable code execution in the current process. Siemens and CISA list affected sectors including critical manufacturing, energy, healthcare, transportation, and defense and advise upgrading to V2606 or later.

Source: CISA

CSIS maps Iranian-linked cyberattacks against U.S. water systems

CSIS reports that water systems in at least 12 states were targeted and that open-source research identified the locations of 55 of 100 facilities reported as targeted; it notes no reported water-quality harm but describes a Georgia pump-station shutdown and a resulting boil-water advisory. The report says CyberAv3ngers has claimed responsibility, and it also explicitly states that U.S. agencies have not publicly attributed the campaign.

Source: CSIS

White House National Security Science and Technology Strategy elevates OT/ICS resilience

The strategy, framed as a federal R&D priority framework, identifies four pillars—technology competition, building technological resilience, accelerating innovation, and protecting national-security S&T—and names information management and cybersecurity among 14 critical and emerging technology areas. It includes OT and ICS security among its listed cyber-priority capabilities alongside computing supply-chain security, digital identity, and post-quantum cryptography; the document is presented as guidance for federal research and development priorities rather than an operational mandate for asset owners.

Source: MeriTalk

Watch for follow-ups on exploit activity and vendor- or sector-specific mitigation actions as organizations implement the advisories and the federal strategy matures into funded programs.

Share this