Daily OT Security News: July 28, 2026

This edition highlights five timely cyber developments affecting industrial, operational, and connected-device environments.

Cyberattack Temporarily Disrupts Minnesota Municipal Water Operations

Braham, Minnesota, said a malicious cyberattack against computerized operating systems temporarily shut down operating controls, stopping the well and water treatment plant. Braham said the incident did not affect the physical plant, water quality, or safety, and officials restored the system later that day. MPR reported that Braham was told at least four other Minnesota communities had experienced the same type of attack and that attribution remains unknown.

Source: Minnesota Public Radio News

CISA Adds Actively Exploited Arista VeloCloud and Fortinet Flaws to KEV Catalog

CISA added CVE-2026-16812 and CVE-2025-68686 to its Known Exploited Vulnerabilities Catalog based on evidence of active exploitation. CISA encouraged organizations to prioritize KEV vulnerabilities through risk-based vulnerability management. Supporting reporting said the Arista issue affects on-premises VeloCloud Orchestrator management deployments and was patched by the vendor.

Source: CISA

CISA Bulletin Lists High-Severity GeoVision Device-Management Vulnerability

CISA’s Vulnerability Summary listed CVE-2026-16607 for the GeoVision GV-IP Device Utility and described a DLL hijacking vulnerability in the desktop application. The bulletin assigned a CVSS score of 7.8 and listed July 22, 2026 as the publication date. The item is relevant to physical-security teams that use IP-camera management tooling.

Source: CISA

Japan Threat Report Highlights Rising Ransomware and Internet-Exposed Device Risk

Forescout reported tracking 124 threat actors targeting Japan, an 82% increase from 68 in 2024, and said ransomware breach claims against Japanese organizations rose 39% year over year in early 2026. It reported 22 million internet-exposed devices in Japan, a 34% increase from 2024, and recommended inventorying connected assets and avoiding direct internet exposure of unmanaged devices. Forescout specifically recommended segmenting IT, IoT, and OT and using IoT/OT-capable monitoring.

Source: Forescout Research – Vedere Labs

GAO Finds Duplicative Cyber Reporting Requirements Can Burden Critical Infrastructure

A new GAO report identified 117 cybersecurity regulations issued by 37 federal agencies covering private entities in nine critical-infrastructure sectors. GAO found that 80 of those regulations include at least one reporting requirement, yielding at least 125 separate reporting obligations, and noted inconsistent thresholds and processes can create potentially duplicative burdens. The report also highlighted that CIRCIA final rulemaking was planned for September 2026 after delays.

Source: U.S. Government Accountability Office

These developments underscore the value of risk-based prioritization and attention to operational resilience across industrial and connected-device environments.

Share this