Daily OT Security News: July 18, 2026

Welcome to today’s OT/ICS/IoT cybersecurity briefing for July 18, 2026. We cover critical incidents, vulnerability disclosures, and innovative initiatives shaping the security landscape of operational technology and industrial environments.

Fairlife Ransomware Attack Halts All U.S. Milk Production, Coca-Cola Files SEC 8-K

Coca-Cola subsidiary Fairlife disclosed a ransomware attack that forced the suspension of all U.S. milk production across three facilities. The breach impacted production-related systems during Fairlife’s largest expansion, generating approximately $4 billion in annual sales. Investigations continue to determine if OT systems were directly compromised or if production was halted as a precaution following IT system outages.

Source: Tech Times

Inc Ransomware Exploits SonicWall SMA Zero-Days (CVE-2026-15409, CVE-2026-15410) — CISA Orders Immediate Remediation

SonicWall revealed two critical zero-day vulnerabilities in its SMA 1000 Series appliances that allow unauthenticated root-level remote code execution. The Inc ransomware group has actively exploited these flaws since late June, leading to credential theft and ransomware deployment. CISA added these CVEs to its Known Exploited Vulnerabilities catalog with a federal remediation deadline of July 17, urging organizations to adopt an assume-breach mindset for edge devices.

Source: Dark Reading

CISA Adds Fortinet FortiSandbox and Microsoft SharePoint Critical Flaws to Known Exploited Vulnerabilities Catalog

CISA included three high-severity vulnerabilities in Fortinet FortiSandbox and Microsoft SharePoint to its KEV catalog, requiring federal agencies to remediate by July 19. The FortiSandbox flaws enable unauthenticated remote code execution via HTTP requests, while the SharePoint vulnerability allows deserialization attacks without authentication. These additions follow Microsoft’s largest-ever Patch Tuesday addressing 622 CVEs.

Source: Security Affairs

Nozomi Networks Joins Anthropic’s Project Glasswing to Bring AI-Driven Vulnerability Discovery to OT and IoT

Nozomi Networks announced its participation in Anthropic’s Project Glasswing, leveraging advanced AI models to proactively identify and mitigate vulnerabilities in critical OT and IoT infrastructure. The collaboration aims to address unique challenges such as long device lifecycles and patching constraints, enhancing defensive capabilities before exploitation occurs. Nozomi was recently recognized by Gartner as a leader in AI for CPS security.

Source: Nozomi Networks

Jaguar Land Rover Cyberattack: £1.9B Economic Impact and Five-Week Production Shutdown Offers Lessons for All Manufacturers

A retrospective analysis of the August 2025 Jaguar Land Rover cyberattack highlights a five-week production halt across three plants and a £1.9 billion economic impact. The incident underscores the risks of IT/OT convergence, where IT containment efforts can inadvertently stop factory operations. Experts emphasize the importance of OT asset visibility, configuration tracking, and vulnerability management to prevent cascading shutdowns.

Source: Industrial Defender

Stay vigilant and proactive in securing your operational environments as threat actors continue to evolve their tactics. Timely patching, comprehensive visibility, and innovative defenses remain critical to safeguarding critical infrastructure.

Share this