Today’s OT security briefing highlights active risks to water and energy operations, newly disclosed industrial-device vulnerabilities, connected-vehicle malware, and practical lessons for improving resilience across IT, cloud, and OT environments.
CISA Says More Than 100 Internet-Exposed Water Systems Were Targeted in July
CISA reported malicious activity against more than 100 internet-exposed water and wastewater systems, often involving PLCs directly connected to cellular modems. The incidents were linked in reporting to Iran-linked actors and did not cause significant disruption; CISA advised operators to inventory exposed assets, remove unnecessary exposure, change default passwords, apply updates, use secure remote access and multifactor authentication, and monitor traffic.
Source: SecurityWeek
CISA Issues Seven New ICS Advisories, With Nine Advisory Pages Updated on August 25
CISA released seven new ICS advisories and revised two others, covering products including Siemens SIMATIC IoT2050 Advanced, Ebyte NE2-D11, FURUNO FA-50, Bendix EC80, Rently Smart Home, Zoneminder and PayRange; five of the nine advisories carry a highest CVSS score of at least 9.1. The Siemens Node-RED interface was described as lacking authentication and able to permit code execution with maximum privileges, and CISA noted some affected products have no announced fix or are end of life.
Source: Berigo, citing CISA ICS Advisories
Cyber Incident Leaves a Small UK Electricity Generator Unavailable for Several Days
A cyber incident in July affected a small UK electricity generator and caused several days of operational unavailability, though authorities reported no threat to the broader grid and no customer outages. Public reporting has linked the event to Iran-linked actors, but the operator, location, technical path, depth of OT access and attribution remain unconfirmed; the analysis highlights remote management, third-party connectivity and industrial controls as potential exposure areas.
Source: LevelBlue SpiderLabs
Kaspersky Finds Malware Campaign Targeting Android Automotive Head Units
Kaspersky researchers identified malware delivered via the built-in software update mechanism of Android-based DoFun automotive head units that abused a legitimate system application called TWCore. The multi-stage payload could display ads, conduct ad fraud, download further code and deploy a reverse-proxy component; Kaspersky reported the vendor fixed the issues after notification and attributed the campaign with high confidence to MoYu Group, previously linked to BADBOX IoT activity.
Source: The Security Ledger
CISA Red-Team Advisory Shows How Detection, Response and OT Segmentation Change Outcomes
In two simultaneous red-team assessments, CISA achieved full domain compromise and access to sensitive systems and cloud resources; one organization failed to detect or contain the activity while the other promptly isolated initial workstations and later detected activity at an OT DMZ bastion host. CISA emphasized lessons including alert tuning, reducing organizational silos, cloud identity controls, response procedures and OT network segmentation for critical-infrastructure organizations.
Source: CISA
End of briefing. Monitor official advisories and follow recommended mitigations for immediate risk reduction in OT environments.