Daily OT Security News: July 29, 2026

Today’s OT/IoT briefing underscores a familiar but escalating pattern: coordinated attacks on operational technology, prolific connected‑device and SCADA targeting in manufacturing, and a steady flow of vulnerability advisories driving regulatory and operator guidance toward stronger isolation, patching and supplier accountability. Public‑private response activity and new national guidance reinforce that segmentation, rapid patch management, and tested contingency plans remain essential to preserving critical services.

Coordinated cyberattacks targeting OT at 30+ Minnesota community water systems

Minnesota authorities reported a two‑day coordinated cyberattack that targeted OT at more than 30 community water systems. South St. Paul said some automated controls were impacted but contingency procedures kept drinking water and wastewater operations from suffering major service disruption; MNIT, FBI, EPA, CISA, local utilities and private partners are involved in the response.

Source: https://www.cybersecuritydive.com/news/authorities-investigating-a-coordinated-cyberattack-against-minnesota-water/826427/

SonicWall: IT/OT convergence driving connected‑device attacks in manufacturing

SonicWall’s 2026 Manufacturing Protect Brief found manufacturers saw 474 million IPS events in H1 2026 and identified 46.2 million IoT attack events, 539 devices with SCADA attack attempts, and roughly 43 million attempts tied to a Hikvision IP camera command‑injection signature. The analysis warns that IT/OT convergence expands the attack surface and reiterates defenses such as timely firmware updates, network segmentation and zero‑trust remote access for industrial environments.

Source: https://industrialcyber.co/manufacturing/sonicwall-warns-ot-it-convergence-expanding-manufacturing-cybersecurity-risks-despite-fewer-detected-attacks/

New Zealand NCSC advises isolating vital OT and enabling systems

New Zealand’s National Cyber Security Centre published guidance urging critical‑infrastructure operators to be able to isolate vital OT and enabling systems from the internet and other networks. The NCSC highlights isolation as a means to disrupt malicious activity, contain active incidents, support safe rebuilding and preserve continuity of critical services.

Source: https://www.ncsc.govt.nz/protect-your-organisation/advice-for-isolating-vital-systems/

JVN notes seven new CISA ICS and medical advisories

Japan Vulnerability Notes (JVN) published an official vulnerability note summarizing seven CISA advisories affecting products including Siemens Desigo CC, Siemens Mendix Runtime, Siemens SIMATIC S7‑PLCSIM Advanced and SIMATIC S7‑1500 CPU 1518(F)‑4 PN/DP MFP, MikroTik RouterOS/Cloud Hosted Router, the igloohome smart‑lock mobile application, and the ABB KNX Update Tool. Operators should review the advisories for mitigation and patch instructions and treat affected devices in ICS and healthcare environments as high priority for remediation.

Source: https://jvn.jp/vu/JVNVU90008749/

Closing note: Operators should validate isolation and contingency plans, prioritize vendor‑issued patches and mitigations, enforce segmentation and zero‑trust access, and maintain active information‑sharing with regulators and peers to reduce the impact of coordinated and device‑focused campaigns.

Share this