News Summary week 33, 2026

The Iran-linked water utility intrusion campaign spread to New Jersey and Alabama, CISA warned of a critical unauthenticated RCE in Johnson Controls’ C-CURE 9000 access control platform and disclosed unauthenticated Bluetooth flaws in two consumer health wearables, and a joint federal advisory detailed Gunra ransomware’s exploitation of Fortinet devices against hospitals and government targets.
threat-intelligence
ICS
CPS
automotive
medical-devices
Published

August 15, 2026

Executive Summary

The water and wastewater intrusion campaign that has dominated the past several weeks widened further, with utilities in New Jersey and Alabama confirming the same pattern of unauthorized access to internet-exposed programmable logic controllers seen across a dozen other states since late July. CISA closed out the week with an unusually consumer-facing pair of medical device advisories, warning that a Bluetooth vagus nerve stimulator and a fertility-tracking hormone monitor both accept unauthenticated commands over BLE, alongside a critical remote code execution flaw in Johnson Controls’ C-CURE 9000 access control and video platform. A joint advisory from CISA, the FBI, and international partners detailed Gunra, a Conti-derived ransomware-as-a-service operation that has hit at least 51 healthcare, government, and critical infrastructure victims by exploiting long-patched Fortinet authentication bypass flaws. Separately, Dragos reported that industrial ransomware incidents rose 12 percent quarter over quarter, with manufacturing absorbing nearly two-thirds of all attacks, and a cyberattack on North Carolina’s three state-run ports forced manual gate operations for several days.

This report focuses on Cyber-Physical Systems (CPS), Industrial Control Systems (ICS), and critical infrastructure security.


Week of August 7 - August 14, 2026

Critical Alerts & Advisories

CISA’s most consequential advisory of the week landed on August 11, when the agency updated ICSA-26-204-01 to detail CVE-2026-21655, a deserialization vulnerability in Johnson Controls’ C-CURE 9000 access control platform, version 3.10.1 and earlier, and its companion Victor video management application server, version 4.10 and earlier. The flaw sits in a service listening on TCP port 8999, and because the deserialization path requires no authentication, an attacker positioned on an adjacent network segment can achieve arbitrary code execution against the application server and, from there, potentially reach connected operator workstations and door controllers. Johnson Controls is directing customers to Victor Application Server 4.20, Victor 8.0, and C-CURE 9000 3.20, and until upgrades are complete recommends blocking inbound connections to port 8999 from any untrusted segment and deploying intrusion detection signatures tuned to known .NET deserialization payloads. No public exploitation has been confirmed, but the combination of a physical access control product and an unauthenticated network-adjacent RCE makes this one of the more urgent patches of the month for commercial facilities and government buildings running the platform.

August 13 brought a coordinated Patch Tuesday batch from Siemens, Schneider Electric, and Phoenix Contact, with Siemens alone publishing around ten advisories spanning its engineering and licensing software. Siemens Parasolid, the geometric modeling kernel embedded in numerous CAD and PLM products, carries CVE-2026-64629, an out-of-bounds read triggered when the application parses malformed X_T format files, capable of crashing the application or, in the worst case, enabling arbitrary code execution on an engineer’s workstation. Siemens License Server, used to manage entitlements across Solid Edge, Simcenter Nastran, and Simcenter Femap deployments, carries two flaws in versions prior to 5.1 and 5.3: CVE-2026-69108, an insecure sudoers policy that lets a local attacker plant malicious files and execute arbitrary commands as root, and CVE-2026-69109, a path traversal bug that lets a remote attacker read arbitrary files off the server. None of these affect production control logic directly, but license servers and engineering workstations sit adjacent to the same networks that reach PLCs and HMIs, making them a soft entry point into otherwise segmented OT environments.

CISA also issued a joint advisory, AA26-222A, on August 10 detailing Gunra, a double-extortion ransomware-as-a-service operation that first surfaced in April 2025 as a derivative of leaked Conti source code. Coordinated with the FBI, the Department of Defense Cyber Crime Center, the NSA, the Secret Service, and South Korea’s National Police Agency, the advisory states that Gunra affiliates have breached at least 51 organizations across the Americas, Europe, the Middle East, Africa, and Asia-Pacific, with a concentration in healthcare, government, and financial services. The group’s primary initial access vector is exploitation of two authentication bypass vulnerabilities in Fortinet FortiOS and FortiProxy, CVE-2024-55591 and CVE-2025-24472, both of which have been publicly known and patchable for well over a year. Researchers at Breakglass Intelligence separately found a cryptographic implementation error in Gunra’s Linux-specific encryptor that allows victims of Linux-targeted attacks to recover files without paying, though the Windows variant carries no such flaw.

Automotive CPS Security

No automotive-specific CISA advisory landed this week, a quiet stretch following last week’s disclosure of the shared-key flaw in Acrisure’s KARR anti-theft system. The broader trend lines from this year’s industry reporting remain worth noting as background context, though: vehicle theft and unauthorized control of vehicle systems each account for roughly a quarter of tracked automotive incidents in 2026, ransom-related attacks against the sector have roughly doubled year over year, and researchers continue to flag the CAN bus, OBD-II port, and cellular telematics modules as the most consistently exploited entry points once an attacker gains initial access through infotainment or diagnostic interfaces. The Siemens and Schneider Electric advisories published this week also carry indirect relevance for the sector, since both vendors’ engineering and licensing software are widely deployed across automotive assembly line automation, even though this week’s disclosed flaws require local or adjacent-network access rather than being remotely exploitable across the internet.

Medical Device CPS Security

CISA’s August 11 medical advisory batch took an unusual turn toward consumer wellness devices rather than hospital equipment. ICSMA-26-223-02 disclosed CVE-2026-18844 in the Pulsetto vagus nerve stimulator, a Bluetooth-connected wellness device marketed for stress and vagal tone management, scored 8.1 under CVSS v3.1. The device’s firmware accepts a set of undocumented commands over its Bluetooth Low Energy interface without any authentication or encryption, commands the companion mobile app never sends but which the device fully processes whenever powered on, potentially allowing a nearby attacker to disable the unit’s electrical safety mechanisms or alter its stimulation output. CISA noted that Pulsetto has not responded to the agency’s outreach, so no firmware fix is available, leaving network and physical proximity isolation as the only current mitigation.

The companion advisory, ICSMA-26-223-01, covered the Mira hormone monitor and its Android companion app, a consumer fertility-tracking device. The disclosure bundles several distinct issues: CVE-2026-67568 lets an attacker with internet access to the distributed Android APK read and write a user’s reproductive health profile, while CVE-2026-66875 allows an unauthenticated attacker within Bluetooth range to silently rebind the device to an attacker-controlled account and extract stored hormone measurements in cleartext. Additional findings included hardcoded API keys, third-party analytics SDKs transmitting user data off-device, and a lack of rate limiting on account-facing endpoints. Mira has shipped fixes in iOS v3.5.18, Android v4.5.18, and firmware v01.07.01.53, delivered automatically when the device syncs with an updated app, and CISA found no evidence of exploitation in the wild. Taken together, the two advisories reflect a continuing shift in CISA’s medical device disclosure program toward consumer-grade wearables carrying sensitive health data, devices that sit outside traditional hospital procurement and patching processes entirely.

Water & Wastewater Sector

The Iran-linked intrusion campaign against U.S. water and wastewater utilities, tracked since late July under the joint CISA-FBI advisory AA26-097A, widened again this week with confirmed incidents in New Jersey and Alabama. In New Jersey, the City of Cape May Sewer Department and the Borough of Woodbine Water Department both disclosed suspicious activity consistent with the campaign’s established pattern, with neither department reporting customer data access or significant service disruption. In Alabama, the Childersburg Water, Sewer, and Gas Board confirmed its computerized monitoring and control network had been targeted through a programmable logic controller, again with no significant operational impact reported. Every disclosure to date has followed the same shape: attackers reach an internet-exposed PLC, alter passwords or IP configuration to lock operators out of monitoring and control, and in some cases trigger brief pressure anomalies rather than sustained outages, with drinking water safety unaffected in all confirmed cases. The expansion to New Jersey and Alabama brings the number of states with confirmed activity beyond the twelve previously reported, reinforcing that the exposure driving this campaign, internet-facing Rockwell, Schneider, and Siemens controllers at small and mid-sized utilities, remains widespread and only partially remediated even as public awareness of the threat has grown.

Energy & Power Grid

No new energy-sector-specific incident emerged this week, but this week’s Siemens, Schneider Electric, and Phoenix Contact Patch Tuesday batch touches the sector indirectly, since all three vendors supply distribution automation, substation, and process control equipment used across power generation and grid operations. The Siemens License Server privilege escalation and path traversal flaws in particular affect engineering software that utilities use to manage licensing for control system design tools, underscoring how the attack surface facing energy operators extends well beyond field devices into the software supply chain that configures and maintains them.

Manufacturing & Industrial

Dragos published its Q2 2026 industrial ransomware analysis on August 11, reporting 1,140 ransomware incidents against industrial organizations for the quarter, up 12 percent from 1,020 in Q1. Manufacturing absorbed the overwhelming majority at 747 incidents, or 65 percent of the total, followed by construction at 176, equipment manufacturing at 114, and food and beverage producers at 70. The report reinforces a theme that has held throughout 2026: ransomware crews rarely need direct access to control system networks to disrupt industrial production, since encrypting or exfiltrating data from IT systems like ERP platforms, virtualization infrastructure, and remote access gateways is often sufficient to halt manufacturing lines that depend on those systems for scheduling and coordination. Dragos also tracked a continuing shift in extortion tactics away from pure file encryption toward data theft alone, with Qilin logging the most industrial victim claims at 140, down from 198 in Q1, Akira rising to 129 from 100, and The Gentlemen climbing to 125 from 83.

Outside the ransomware numbers, North Carolina’s state-run ports authority disclosed a cyberattack on August 4 that disrupted IT systems and forced a transition to manual gate processing at the Port of Wilmington, Port of Morehead City, and the Charlotte Inland Port. The authority reported the intrusion contained by August 5 and began recovery, though full restoration continued into this week without a public timeline, and the U.S. Coast Guard confirmed it was monitoring the incident given the maritime facilities involved. No threat actor has claimed responsibility, and officials have not confirmed whether the incident involved ransomware, data theft, or a ransom demand, but the operational pattern, an IT-side outage cascading into manual physical operations at critical transportation infrastructure, mirrors the broader trend Dragos highlighted of IT disruption alone being sufficient to degrade industrial and logistics operations.

Threat Intelligence Highlights

The Gunra ransomware advisory is notable less for novel tradecraft than for what it confirms about the current ransomware economy: a Conti-derived toolkit, in active use for over a year, continuing to compromise victims through Fortinet vulnerabilities that have had vendor patches available since 2024 and early 2025 respectively. That gap between patch availability and real-world remediation remains the single most exploited condition across this week’s incidents, from Fortinet-facing Gunra intrusions to internet-exposed water sector PLCs that have gone unpatched or unsegmented for years. The consumer medical device disclosures also point to an emerging pattern worth watching, as BLE-connected wellness and fertility devices increasingly hold sensitive health data and physical actuation capability, yet are built and maintained by consumer electronics companies with none of the regulatory muscle memory that hospital device manufacturers have developed under FDA postmarket surveillance requirements.

Defensive Recommendations

Organizations running Johnson Controls C-CURE 9000 or Victor should prioritize the upgrade to 3.20 and 8.0 respectively, and in the interim block all inbound traffic to TCP port 8999 from untrusted network segments. Engineering teams using Siemens Parasolid, Solid Edge, Simcenter Nastran, Simcenter Femap, or Siemens License Server should apply this week’s Patch Tuesday updates, with particular urgency on the License Server’s sudoers misconfiguration given its path to full root compromise. Any organization still running unpatched Fortinet FortiOS or FortiProxy instances should treat CVE-2024-55591 and CVE-2025-24472 as immediate priorities regardless of sector, given their continued active exploitation by Gunra affiliates against healthcare and government targets specifically.

Water and wastewater utilities in New Jersey, Alabama, and every other state should assume internet-facing Rockwell, Schneider, or Siemens PLCs remain an active target and should audit for direct internet exposure immediately, particularly on cellular-connected remote pump and lift stations, following the mitigation guidance in AA26-097A. Healthcare organizations and consumers using the Pulsetto vagus nerve stimulator should minimize the device’s Bluetooth exposure and avoid use near untrusted networks given the absence of a vendor patch, while Mira hormone monitor users should update to the latest app and firmware versions to close the account-rebinding and data-exposure flaws. Manufacturing and logistics operators should treat IT and OT segmentation as a production continuity control rather than a compliance checkbox, given Dragos’s finding that IT-only disruption is frequently sufficient to halt industrial operations without any control system compromise at all.

Sources Referenced

Government Advisories & Directives

Threat Intelligence & Incident Analysis

Web Search Discoveries