News Summary week 31, 2026

A coordinated OT intrusion campaign hit water and wastewater utilities across seven U.S. states, with Minnesota alone reporting roughly 36 affected systems, while CISA’s updated advisory AA26-097A confirmed Iran-affiliated actors have expanded PLC targeting from Rockwell Automation to Siemens and Schneider Electric devices.
threat-intelligence
ICS
CPS
automotive
medical-devices
Published

August 4, 2026

Executive Summary

The dominant story this week was a coordinated attack on internet-facing programmable logic controllers at water and wastewater utilities in at least seven states, with Minnesota bearing the brunt at roughly 36 affected community water systems. Attackers reprogrammed Rockwell Automation MicroLogix 1100 and 1400 ladder logic rather than simply changing passwords, a technique that can leave hidden control changes in place even after credentials are reset. CISA’s updated joint advisory AA26-097A now attributes the broader campaign to Iran-affiliated actors and, for the first time, documents targeting of Siemens and Schneider Electric PLCs alongside Rockwell hardware. Elsewhere, a ransomware attack shut down every U.S. production line at Coca-Cola’s Fairlife subsidiary, a Bluetooth flaw in KARR anti-theft systems left roughly two million vehicles exposed to remote unlocking, and a design-level flaw in Insulet’s OmniPod Eros insulin pump resurfaced as a reminder that legacy medical devices still in active production carry unresolved cybersecurity risk.

This report focuses on Cyber-Physical Systems (CPS), Industrial Control Systems (ICS), and critical infrastructure security.


Week of July 24 - July 31, 2026

Critical Alerts & Advisories

CISA, the FBI, NSA, EPA, DOE, and U.S. Cyber Command jointly updated advisory AA26-097A on July 22, and the update dominated ICS advisory traffic through the end of the month. Originally published in April to describe Iran-affiliated actors exploiting internet-exposed Rockwell Automation Logix controllers, the revised advisory expands the manufacturer scope to Schneider Electric and Siemens equipment, documents PLC project file exfiltration for the first time, and adds detection guidance for manipulation of reusable code modules embedded in PLC programs. The attackers’ core technique is notable for its simplicity: rather than developing custom exploit tooling, they connect to internet-exposed controllers using the vendors’ own legitimate engineering software, including Rockwell’s Studio 5000, Schneider Electric’s EcoStruxure Control Expert, and Siemens’ TIA Portal. CVE-2021-22681, a critical authentication bypass in Rockwell Logix controllers scoring 9.8 on CVSS and lacking a full vendor patch, remains the anchor vulnerability for the campaign and has been in CISA’s Known Exploited Vulnerabilities catalog since March.

CISA’s routine ICS advisory output continued alongside the AA26-097A update, with releases earlier in the month covering products from Siemens, Schneider Electric, Rockwell, and other vendors, plus advisories for niche but consequential targets such as Hydro-Québec’s Le Circuit Electrique EV charging backend and ST Engineering iDirect satellite terminals. The volume and breadth of these releases underscore a pattern that has held throughout 2026: OT vulnerability disclosure is accelerating faster than most asset owners can patch, particularly for devices that were never intended to sit on the public internet in the first place.

Automotive CPS Security

Researchers at UC San Diego disclosed a Bluetooth Low Energy vulnerability affecting KARR aftermarket anti-theft systems, exposing roughly two million vehicles largely sold through Honda, Toyota, Mazda, Ford, and Jeep dealerships in Southern California, with additional affected vehicles scattered across the United States, Canada, and Japan. An attacker within about five yards of a vulnerable vehicle can exploit the flaw to wirelessly unlock doors or prevent the engine from starting. Acrisure Protection Group, which owns the KARR brand, reportedly learned of the issue from researchers in January 2025 but did not ship a software patch until July 20, 2026, an eighteen-month gap that drew criticism even though KARR says it has seen no evidence of real-world exploitation.

The broader vulnerability trend supports concern about that kind of delay. PCA Cyber Security’s Q2 2026 Global Automotive Threat Intelligence Report found 345 unique automotive vulnerabilities disclosed in the quarter, with high-severity flaws capable of enabling control of major vehicle functions or exposure of sensitive personal data more than doubling to 161. The report ties part of the acceleration to AI-assisted exploit development, which researchers say has roughly doubled the volume of attacks against the sector over the past year, and it argues the industry needs to move beyond simply tracking CVEs toward verifying that patches are actually present across the full software bill of materials for fielded vehicles and fleets.

Medical Device CPS Security

A design-level protocol vulnerability in Insulet’s OmniPod Eros insulin management system drew renewed attention this week. Security researchers at Lyrebirds found that an attacker can interrupt or replay the wireless pairing communication between an OmniPod controller and pump without the device properly invalidating the associated session nonce, potentially enabling an attacker to take control of the pump and issue programming commands, including an unauthorized insulin injection. Insulet is steering patients toward its newer OmniPod DASH platform, but the older Eros system remains in active production and is still the most widely deployed model, meaning the exposure is not merely historical.

Regulatory context continues to shift underneath device makers. The FDA’s cybersecurity guidance, reissued to align with the Quality Management System Regulation that took effect earlier this year, requires manufacturers of qualifying “cyber devices” to embed security into ISO 13485-aligned quality systems, submit a Security Risk Management Report and a machine-readable software bill of materials with premarket filings, and maintain a postmarket Cybersecurity Management Plan with a coordinated vulnerability disclosure process. A recent industry study scanning nearly a thousand medical devices from over a hundred vendors found close to a thousand distinct vulnerabilities across device hardware, operating systems, and applications, reinforcing that the compliance burden reflects a genuine and not merely theoretical risk surface.

Water & Wastewater Sector

The week’s most significant CPS incident was a coordinated attack on water and wastewater operational technology across at least seven U.S. states beginning July 26 and 27, with Minnesota hit hardest at roughly 36 affected community water systems and at least one treatment plant forced entirely offline. The intrusions targeted internet-facing Rockwell Automation MicroLogix 1100 and 1400 PLCs, and the attackers went well beyond simply changing IP addresses and passwords to lock out operators. Investigators found that the attackers modified the PLC project files themselves, altering ladder logic in ways that can introduce hidden control changes persisting even after affected utilities reset credentials. No drinking water contamination has been confirmed, but several utilities experienced pressure loss and localized flooding, some issued boil-water notices, and recovery in multiple cases required falling back to manual operation of treatment processes.

Attribution remains preliminary. U.S. investigators are examining a possible Iranian connection, and Tenable researchers have assessed the operational pattern as consistent with CyberAv3ngers, the IRGC-linked group the Treasury Department previously sanctioned for attacks on Unitronics PLCs at U.S. water utilities. Officials are also weighing whether the campaign was deliberately staged to resemble Iranian tradecraft, and no formal attribution has been made public. Regardless of the ultimate source, CISA is now urging water utilities nationwide to remove PLCs from direct internet exposure, a recommendation that echoes years of prior guidance the sector has been slow to adopt.

Energy & Power Grid

No new grid-specific intrusion was confirmed this week, but the Iran-linked PLC campaign detailed in AA26-097A carries direct relevance for energy operators, since Siemens and Schneider Electric equipment named in the update is widely deployed in substation automation and distributed energy resource management. NERC has stated it is actively monitoring the grid in response to the broader Iran-linked threat picture, consistent with a sector that CISA continues to rank as the top target among critical infrastructure categories. Industry surveys published this year found energy professionals reporting significantly greater vulnerability to OT incidents due to sprawling legacy infrastructure, with a majority acknowledging that OT defenses continue to lag behind IT security investment even as distributed energy resources expand the attack surface.

Manufacturing & Industrial

Coca-Cola’s Fairlife dairy subsidiary disclosed a ransomware attack that forced a shutdown of every U.S. production facility, halting output for a business that generates close to four billion dollars in annual sales. The company has not confirmed whether the intrusion reached plant-floor operational technology directly or whether production was suspended out of caution following a corporate IT compromise, but the incident illustrates how tightly integrated IT and OT environments in food and beverage manufacturing have become, and how quickly a breach on the business network can cascade into a full production stoppage. Manufacturing continues to absorb a disproportionate share of ransomware activity industry-wide, a trend attributed to ransomware-as-a-service proliferation, aging OT assets that are difficult to patch without production downtime, and supply chain access points that give attackers multiple routes into plant networks.

Threat Intelligence Highlights

CyberAv3ngers remains the actor most closely associated with sustained targeting of water sector PLCs, and the group’s suspected involvement in this week’s seven-state attack, if confirmed, would mark a significant escalation from its earlier pattern of exploiting default credentials on Unitronics controllers toward direct manipulation of ladder logic on Rockwell hardware. Separately, Volt Typhoon, the China-linked actor focused on pre-positioning within U.S. critical infrastructure using living-off-the-land techniques, continues to be assessed as active, with recent analysis describing its intent as extending beyond traditional espionage toward disruptive capability. The convergence of Iran-linked disruptive OT operations and China-linked pre-positioning within the same critical infrastructure sectors leaves defenders managing two distinct threat models simultaneously, one oriented toward immediate operational disruption and the other toward long-term persistent access.

Defensive Recommendations

Water utility operators should treat AA26-097A as an urgent, action-forcing document rather than routine guidance: remove MicroLogix and other Rockwell, Siemens, and Schneider Electric PLCs from direct internet exposure immediately, rotate all credentials, and, critically, verify the integrity of ladder logic and project files against known-good backups rather than assuming a password reset alone restores safe operation. Organizations using vendor engineering software such as Studio 5000, EcoStruxure Control Expert, or TIA Portal for remote access should restrict that access to VPN-gated connections with multi-factor authentication and log all project file uploads and downloads for anomaly review.

Energy and manufacturing operators should audit their exposure to the same PLC families named in AA26-097A and prioritize network segmentation between corporate IT and plant-floor OT, given how quickly the Fairlife ransomware incident cascaded into a full production shutdown. Medical device users and clinical engineering teams should track Insulet’s guidance on migrating OmniPod Eros patients to the DASH platform where clinically appropriate, and hospital procurement teams should factor the FDA’s premarket cybersecurity documentation requirements into new device evaluations. Fleet operators and vehicle owners with KARR aftermarket security systems installed since 2017 should apply the July 20 patch as soon as possible.

Sources Referenced

Government Advisories & Directives

Web Search Discoveries