Daily OT Security News: August 4, 2026

Welcome to today’s Daily OT Security News briefing. We bring you the latest developments impacting industrial control systems, operational technology, and connected devices to help you stay ahead of emerging threats.

Widespread Cyberattacks Target U.S. Water Infrastructure

A coordinated cyberattack campaign linked to Iranian threat actors has targeted vulnerable industrial devices at thousands of drinking and wastewater treatment facilities across the United States. Striking about 30 systems in Minnesota alone, the attackers exploited internet-exposed programmable logic controllers (PLCs) using default passwords and lacking multifactor authentication. The Operational Technology Cybersecurity Coalition is urging CISA to issue a Binding Operational Directive requiring immediate risk mitigation at critical government sites.

Source: Cybersecurity Dive

New York Expedites $9 Million for Water Sector Cyber Defense

In response to the nationwide attacks on water utilities, New York State is fast-tracking over $9 million in cybersecurity grants to harden local government water and wastewater systems. The funds will support risk assessments, operator training, and the implementation of required cybersecurity controls. This initiative aligns with the state’s recently finalized mandatory cybersecurity rules designed to protect these historically underfunded and exposed critical infrastructure systems.

Source: GovInfoSecurity

Cloud ERP Outages Expose Hidden OT Vulnerabilities

As manufacturing operations increasingly rely on cloud-based Enterprise Resource Planning (ERP) systems, experts warn that ERP outages can halt plant floors even without a direct breach of the operational technology (OT) network. Disruptions to cloud connectivity or identity services can severely impact production scheduling and inventory management, highlighting a critical structural dependency. Security leaders are emphasizing the need for tested outage response plans and manual fallback procedures to ensure production continuity during IT disruptions.

Source: Industrial Cyber

Critical N-able N-central Vulnerability Under Active Exploitation

A critical authentication bypass vulnerability (CVE-2026-18577) in N-able’s N-central remote monitoring and management platform is currently being exploited in the wild. Attackers are using the flaw to gain administrative access to vulnerable servers and abuse the built-in Take Control feature to pivot into managed endpoints. Organizations are urged to immediately apply the hotfix and monitor their environments for suspicious remote-control sessions, particularly those targeting domain controllers.

Source: Huntress

Multiple Vulnerabilities Disclosed in TP-Link Omada Ecosystem

Security researchers have detailed several vulnerabilities affecting device management and Zero-Touch Provisioning technologies within the TP-Link Omada ecosystem. The findings, presented at Black Hat USA 2026, reveal weaknesses in device adoption workflows, credential handling, and controller communications that could be chained together in attack scenarios. TP-Link has released firmware updates and security advisories, advising customers to update affected devices and controllers to mitigate the risks.

Source: TP-Link Security Advisory

Thank you for reading today’s briefing. Stay vigilant and ensure your critical systems remain secure.

Share this