Today’s OT, IoT, and critical-infrastructure security developments include incidents affecting healthcare manufacturing, airport services, print-management software, vendor cyber-resilience guidance, and a control-system intrusion analysis.
Boston Scientific Still Recovering From Cyberattack
SecurityWeek reported on August 31, 2026 that Boston Scientific was still recovering from a cyberattack detected on August 25. The resulting network outage disrupted global operations, including manufacturing, customer-order processing, and shipping. Existing implantable cardiac rhythm management devices were not affected, but new remote activations for some cardiac monitors were disrupted.
Source: SecurityWeek
Extortion Group Claims Manchester Airports Group Data Breach
SecurityWeek reported on August 31, 2026 that the FulcrumSec extortion group claimed responsibility for a data breach at Manchester Airports Group, which operates Manchester, London Stansted, and East Midlands airports. MAG said the incident involved data associated with car-park, lounge, and Fast Track bookings, plus in-airport Wi‑Fi sign-ups, and that exposed data included email addresses, phone numbers, vehicle registrations, and postcodes. MAG said no payment information was accessed and that airport operations, customer parking services, passenger safety, and aviation security were unaffected.
Source: SecurityWeek
More Details Emerge on Exploited PaperCut Vulnerabilities
SecurityWeek reported on August 31, 2026 that PaperCut Software issued a second emergency patch for two actively exploited zero-day vulnerabilities in PaperCut NG/MF. The flaws include a high-severity authentication bypass (CVE-2026-81578) and a critical unsafe dynamic class-loading issue (CVE-2026-82078) that together can enable unauthenticated attackers to modify configuration and achieve remote code execution. Huntress observed activity at at least two customers, about 1,000 PaperCut instances were reportedly exposed to the internet, and PaperCut made indicators of compromise available while continuing work on an official release addressing both flaws.
Source: SecurityWeek
Toshiba Publishes English Edition of Cyber Security Report 2026
On August 31, 2026, Toshiba Corporation released the English edition of its Cyber Security Report 2026, covering fiscal year 2025. Toshiba said cyber threats have expanded into control systems and industrial equipment, with ransomware, targeted attacks, and supply-chain threats increasingly disrupting corporate activity and critical social infrastructure. The report describes a cyber-resilience strategy for information and control systems, products, systems, and services, with attention to supply-chain risk, attack-surface assessment, and AI-risk management.
Source: Toshiba Corporation
OT Networks Still Need Monitoring
Netresec described an attack path from an internet-facing FortiGate VPN at a wind farm, through a Teltonika cellular 5G router, to a WAGO PLC and the plant control-system network. The attackers reportedly switched multiple Siemens S7 PLCs to STOP mode, enabled password protection that prevented operators from returning them to RUN mode, and changed serial-server and switch configurations. The analysis stressed segmentation, traffic monitoring, logging, and detecting early reconnaissance, and it noted a joint agency advisory on active threats to Siemens S7 PLCs.
Source: Netresec
Together these items underscore the importance of inventory, device-health monitoring, and coordinated firmware management across OT/IoT and critical-infrastructure environments.