Daily OT Security News: August 27, 2026

Daily OT Security News: August 27, 2026

Briefing window: verified reporting published August 27, 2026. Summaries focus on operational-technology and industrial-control impacts, official filings, and sector guidance drawn only from the cited sources.

U.S. disrupts alleged China-linked IoT botnet infrastructure

PCMag reported that U.S. authorities obtained a court order to disrupt two platforms — QScan and QTRouter — which the article says were allegedly developed by the China-based QTFY group. According to the Justice Department affidavit cited in the report, QScan compromised IoT devices such as routers, cameras, and smart appliances and added them to a proxy network used to mask intrusions, including activity the affidavit described as targeting U.S. federal agencies. The domain seizures reportedly rendered the malware inoperable.

Read the source: PCMag

Boston Scientific reports cybersecurity incident affecting order processing

SecurityWeek reported that Boston Scientific disclosed a cybersecurity incident detected on August 25 that affected some IT systems, causing a network outage and disrupting certain operating systems and business applications. According to the company’s statement and SEC filing cited by the article, the disruption affected its ability to process and ship customer orders; the scope, restoration timeline, and operational and financial effects remain under investigation.

Read the source: SecurityWeek

CISA guidance follows cyberattacks on internet-exposed water-sector PLCs

Security Affairs reported that more than 100 internet-exposed U.S. water and wastewater systems were affected by cyberattacks in July 2026, prompting CISA to publish exposure-reduction guidance. The reported pattern involved PLCs directly connected through cellular modems, and the article says attacker actions reportedly included changing device IP addresses and passwords and, in some cases, disabling shutdown processes and alarms. CISA recommends continuing external exposure discovery and routing necessary remote access through secured, centrally managed access points, the report states.

Read the source: Security Affairs

Energy-sector analysis highlights rising CPS and OT cyber exposure

pv magazine India published a commentary describing how IT/OT convergence in energy environments is expanding the attack surface around legacy devices, unpatched systems, and proprietary protocols. Citing Australia’s Annual Cyber Threat Report, the piece notes a reported 11% year-on-year increase in attacks affecting critical infrastructure, including energy, and the analysis argues for OT-specific asset visibility, exposure management, network protection, threat detection, and secure access rather than relying solely on conventional IT security controls.

Read the source: pv magazine India

Share this