Water-utility incidents highlight the risk of internet-exposed PLCs
The report says intrusions connected to an attack originating in Minnesota affected public water treatment and delivery systems in as many as a dozen states, and affected operators restored operations or adopted manual controls for pressure or communications issues; the FBI had not found evidence of water-supply tampering, malware deployment, or ransomware demands at publication, and attribution remained unproven; the article cites CISA guidance to remove directly exposed PLCs and OT from the internet, use mediated remote access, protect credentials, and allowlist remote access. https://www.foodmanufacturing.com/facility/article/22971902/update-insights-from-water-infrastructure-hacks
Exposed EtherNet/IP controllers remain a measurable water-sector attack surface
Forescout reported 4,407 internet-facing controllers exposing EtherNet/IP on port 44818, with 65 percent located in the United States; it identified 22 hosts in cities targeted in the current campaign but said it had no confirmation that a CVE was exploited; the analysis also identified expired certificates, unrenewed remote-access hostnames, and abandoned servers as signals of incomplete asset visibility at municipal utilities. https://www.forescout.com/blog/ot-security-analysis-exposed-devices-attacked-in-us-water-systems/
Zero-knowledge proofs proposed for privacy-preserving OT vulnerability reporting
FDD’s pilot modeled three oil-and-gas providers assessing 38 real CVEs relevant to comparable production networks, finding all providers had confirmed exposure and no CVE was remediated across all three providers; the paper proposes zero-knowledge proofs as a means to attest to defined security conditions without disclosing raw scan data while warning that the method can prove only the statement encoded in the proof and requires sound governance. https://www.fdd.org/analysis/2026/08/04/zero-knowledge-proofs/