Daily OT Security News: August 26, 2026

Daily OT Security News — August 26, 2026

FBI Investigates Breach at Water-Sector PLC Supplier

Reuters reported that U.S. authorities are investigating a breach at Micro-Comm, a Kansas supplier of programmable logic controllers used in wastewater processing. The ransomware group Barracuda claimed responsibility and posted what it said were nearly 850,000 files totaling roughly 644 GB. Micro-Comm said customer credentials and remote-access information were not in the released data, and the FBI characterized the event as opportunistic rather than part of the concurrent water-system campaign. The report said Censys found about 200 Micro-Comm SCADAview CSX systems internet-accessible.

Source: Reuters via WHTC

CISA Urges Water Utilities to Reduce Internet Exposure

CISA’s exposure-reduction guidance says it observed malicious cyber activity in July 2026 targeting more than 100 internet-exposed systems in the Water and Wastewater Systems sector, commonly involving PLCs directly connected to cellular modems. CISA says attackers remotely accessed exposed PLCs, changed IP addresses and passwords, and caused loss of monitoring and control functionality, including some operational disruption. The agency recommends identifying exposed assets, removing unnecessary remote access, and routing necessary OT remote access through a centrally managed gateway, firewall, VPN, or similar controlled solution with strong authentication and monitoring.

Source: CISA

Canada’s CCSPA Raises the OT Cybersecurity Bar for Critical Infrastructure

An August 25 OT security analysis notes that Canada’s Bill C-8 received Royal Assent on June 16, 2026, introducing the Critical Cyber Systems Protection Act and new cybersecurity obligations for designated critical infrastructure operators. The article identifies interprovincial pipelines, nuclear energy, transportation, and telecommunications as examples of affected sectors and emphasizes accurate OT asset inventories, vulnerability prioritization, network monitoring, supply-chain risk management, incident planning, and assessment of operational consequences as readiness priorities.

Source: Honeywell Technologies

Energy-Sector IT/OT Convergence Expands Cyber-Physical Risk

A current energy-sector analysis argues that rapid convergence of IT and OT is exposing legacy industrial assets to a larger attack surface. Citing Australia’s Annual Cyber Threat Report, it says attacks against critical infrastructure including energy increased 11% year over year. The article argues that heterogeneous OT devices and proprietary protocols require a CPS-specific approach centered on complete asset visibility, exposure management, network protection, threat detection, and secure access rather than relying solely on conventional IT controls.

Source: pv magazine Australia

Share this