Daily OT Security News: July 29, 2026
A concise roundup of recent operational technology security developments affecting water, critical infrastructure guidance, manufacturing, IoT, and energy resilience.
Minnesota Water Utilities Report Coordinated OT Cyberattack
Minnesota IT Services said more than 30 community water systems were targeted on July 26 and 27; affected cities reported some automated control functions were affected while contingency procedures generally kept water and wastewater operations running. Braham briefly took its water plant offline after attackers shut down operating controls, the well, and the treatment plant, and Plymouth said its issue was limited to equipment connected via cellular communications. At publication, investigators had not attributed the campaign to a specific actor.
Source: SecurityWeek
US and Australia Issue Guidance for Isolating Vital OT Systems
CISA and the Australian Cyber Security Centre issued CI Fortify guidance to help critical-infrastructure organizations isolate vital OT and enabling systems. The guidance calls for identifying critical assets and dependencies, documenting relevant connections, establishing isolation points, planning and testing graduated isolation, and monitoring isolation effectiveness, and it warns that isolation can create risks such as reduced external visibility, patching constraints, and removable-media exposure.
Source: SecurityWeek
Manufacturing Faces Persistent IoT and OT Exposure Despite Fewer IPS Detections
Industrial Cyber reports SonicWall research showing 474 million manufacturing IPS events in the first half of 2026 despite a year-over-year decrease in IPS detections; the research reports 43 million attempts against a Hikvision IP-camera command-injection signature and 46.2 million IoT attack events. It identifies remote monitoring, predictive maintenance, and vendor access as IT-to-OT pathways and recommends application-level remote access, firmware remediation or device isolation, strict IT/OT segmentation, and investigation of concentrated ransomware detections.
Source: Industrial Cyber
IoT Defenders Urged to Reduce Internet Exposure and Patch Faster
An IoT For All analysis of Verizon’s 2026 Data Breach Investigations Report says software vulnerabilities are the leading initial-access path in breaches and notes a median 43 days to fully remediate known vulnerabilities. The analysis highlights publicly reachable connected devices, edge gateways, and weak administrative controls as exposure pathways, and recommends asset auditing, disabling unused services, strong authentication, restricted administrative access, and risk-based prioritization of externally exploitable flaws.
Source: IoT For All
Energy-Sector OT Resilience Depends on Recovery Knowledge, Not Just Backups
Help Net Security reports that retiring OT personnel can leave organizations without the knowledge needed to verify or safely restore controller configurations, and describes unmanaged temporary workarounds, open panels, and long-lived temporary network connections as resilience concerns. It recommends validating recovery plans against live restoration conditions, retaining configuration knowledge, governing exceptions, and treating patch assessment as a recurring operational activity.
Source: Help Net Security