Daily OT Security News: August 21, 2026

Daily OT/ICS/IoT briefing — August 21, 2026. Four concise items covering an active PLC threat advisory, a vendor vulnerability notice, a procurement-assurance initiative, and an industry ransomware/legacy-device review.

U.S. agencies warn of an active threat to Siemens S7 PLCs

CISA, NSA, FBI, DOE, and EPA warn that threat actors are conducting reconnaissance and capability development targeting U.S.-based Siemens S7 PLC installations. The advisory highlights AI‑generated exploitation scripts disguised as monitoring tools, internet scanning, outdated software, weak protections, and insufficient network segmentation as central risks. Affected sectors named include critical manufacturing, energy, water and wastewater, chemical, food and agriculture, and commercial facilities. Recommended mitigations include inventorying devices, patching, removing Internet exposure, strengthening access controls, monitoring and hunting for anomalies, and hardening services, protocols, and ladder‑logic integrity.

Source: CISA Cybersecurity Advisory AA26-231A

Johnson Controls advisory flags affected building and control‑system products

The Canadian Centre for Cyber Security advisory lists affected Johnson Controls products and versions: Airwall before 4.1.0; Metasys 12 and 13 (all versions); Metasys 14 before 14.1.5; Metasys 15 before 15.0.1; and TL280 before 5.62. The advisory directs users and administrators to review Johnson Controls product security advisories and apply updates as they become available. This item is a vulnerability advisory and does not assert active exploitation.

Source: Canadian Centre for Cyber Security advisory AV26-837

ISASecure and NSA develop high‑criticality OT component assurance scheme

ISASecure and the NSA are developing the High Criticality Component Security Assurance (HCSA) certification scheme for commercial OT components acquired for National Security Systems. The scheme will incorporate ISA/IEC 62443‑4‑2 requirements plus six additional technical requirements developed through the NSA Operational Technology Assurance Partnership (OTAP). After completion and acceptance by the OTAP program office, NSA plans to use HCSA as an approved certification mechanism for evaluating OEM components for the NSS OT Product Compliant List.

Source: Industrial Cyber report on ISASecure and NSA announcement

Industry review underscores ransomware growth and legacy‑device exposure in IoT/OT

Channel Insider, citing Dragos analysis, reports that Dragos tracked 1,211 ransomware incidents affecting industrial organizations worldwide in Q4 2025, up from 742 in Q3 2025; manufacturing represented 819 of those incidents. The article highlights legacy and resource‑constrained devices, public connectivity, supply‑chain exposure, and limitations of traditional endpoint tools as ongoing operational‑security concerns. The figures are provided as historical context in the current analysis.

Source: Channel Insider (citing Dragos industrial ransomware analysis)

Operational takeaway: Immediately inventory and prioritize Siemens S7 PLCs and Johnson Controls products listed in the advisories; remove or isolate Internet‑exposed OT devices, apply vendor patches and updates where available, and strengthen access controls and segmentation. Deploy targeted monitoring and hunt for anomalies (including malicious tools disguised as monitoring software), harden protocols and ladder logic integrity, and accelerate backup, isolation, and recovery plans for ransomware response. For future procurements and high‑value NSS/OT components, require or evaluate suppliers against the emerging HCSA assurance criteria or equivalent third‑party validation.

Share this