Daily OT Security News: July 30, 2026

Daily OT Security News: July 30, 2026 — This briefing covers reporting current through July 30, 2026, on water‑sector response to a coordinated incident, joint continuity and isolation guidance for critical infrastructure, data‑center CPS exposure findings, and industrial threat telemetry.

Coordinated Cyberattack Affects More Than 30 Minnesota Water Utilities

Help Net Security reported a July 26–27 coordinated attack on operational technology systems at more than 30 Minnesota community water utilities. Minnesota IT Services confirmed the incident on July 28 and activated incident‑response processes; the investigation remains active. The report said no city had asked residents to change drinking‑water use; Maple Plain reported no service disruption and no indication that water safety or quality was affected. Help Net Security relayed Tenable’s view that the activity appeared suspicious, and the source did not present that view as an official attribution.

Source: Help Net Security

Joint CI Fortify Guidance Calls for Tested OT Isolation Plans

Australia’s Cyber.gov.au published the CI Fortify guidance on July 28, developed with international partners and presented as joint guidance for critical‑infrastructure organizations. The document advises organisations to develop and test the ability to isolate vital operational‑technology and enabling systems during cyber incidents, to map dependencies and candidate isolation points, and to invest in recovery capabilities to preserve essential services. The source frames these measures as recommended guidance rather than as binding regulation; implementation and any legal obligations will depend on jurisdiction and organisation‑specific circumstances.

Source: Cyber.gov.au

Claroty Research Finds Data-Center CPS Assets One Hop From Risky Internet Connections

Claroty Team82 reported that, in its survey of 174,577 data‑center infrastructure assets, 32,157 assets (about 18%) were one hop from systems making risky public‑internet outbound connections, and Claroty presented these figures as findings of its vendor research. The report identifies exposure indicators across power monitoring, UPS equipment, OT control systems, and building‑management systems, and highlights instances of known exploited vulnerabilities, insecure protocols, and outdated firmware. These findings reflect Claroty’s telemetry and analysis and are reported as vendor research results, not as universal prevalence statistics.

Source: Claroty

Kaspersky ICS CERT Reports 19.6% Global ICS Malware-Block Rate in Q1

Kaspersky ICS CERT’s Q1 2026 telemetry reported malicious‑object blocking on 19.6% of the ICS computers it monitored globally, with regional blocking rates ranging from 9.1% in Northern Europe to 27.4% in Africa. The report noted quarter‑over‑quarter increases in five regions, with particularly notable rises in Southern Europe, Northern Europe, and Russia. Kaspersky characterizes this metric as telemetry from ICS systems monitored or protected by Kaspersky; the source does not present the figure as a count of unique incidents or as an estimate of all global ICS compromises.

Source: Kaspersky

This briefing synthesizes publicly available reporting and source materials current as of July 30, 2026; summaries preserve the attribution caveats and the scope limitations noted by the original sources.

Share this