Water Sector
48 articles covering water OT/ICS security
CVSS 10.0: Unauthenticated Root Command Injection in Haiwell IoT Cloud HMI Gateway (CVE-2026-19188)
A maximum-severity OS command injection flaw in Haiwell's IoT Cloud HMI Gateway lets unauthenticated remote attackers execute arbitrary commands as root through a Socket.io ping-test feature. CISA advisory ICSA-26-225-02 details the flaw, its exposure across energy, water, and manufacturing deployments, and patch guidance.
Forescout Scan Finds 4,400+ Exposed Rockwell PLCs; 19 in Water-Attack Cities Vulnerable to 2017 Modbus Flaw
An August 3, 2026 internet-wide scan by Forescout Vedere Labs identified 4,407 internet-facing Rockwell/Allen-Bradley PLCs on port 44818, with 22 located in cities hit by the July water-sector campaign. Nineteen run MicroLogix 1400 firmware vulnerable to CVE-2017-16740, a nine-year-old Modbus TCP buffer overflow Rockwell patched in 2017 but many operators never applied.
Phoenix Contact PLCnext and mGuard Security: CISA Advisory Roundup and Hardening Guide
Phoenix Contact is among the top five ICS vendors by CISA ICS-CERT advisory volume in 2026. Vulnerabilities span the PLCnext runtime environment, mGuard security routers, and WP 6xxx web panel HMIs — covering authentication bypass, remote code execution, cross-site scripting, and weak cryptography. This guide consolidates the advisory landscape and provides OT-specific hardening steps for each product family.
CISA AA26-097A: Iranian-Affiliated Actors Escalate PLC Exploitation Across Water, Energy, and Municipal OT
A July 2026 update to CISA advisory AA26-097A expands the confirmed scope of Iranian-affiliated PLC exploitation to Schneider Electric Modicon M340 and Siemens S7-1200 controllers, adding to the initial Rockwell Allen-Bradley targeting disclosed in April. Active exploitation of internet-facing PLCs is now confirmed across water, energy, and government facility sectors.
CISA Alert: PLC Targeting Campaign Hits Water Utilities Across Seven US States
CISA's July 30, 2026 alert confirms a coordinated campaign targeting internet-exposed programmable logic controllers at water and wastewater utilities in at least seven states. Threat actors modified passwords to lock out operators and changed IP addresses to disconnect systems, causing boil-water notices and manual operations.
Modbus and DNP3 Under Attack: Protocol Security and Detection for OT Networks
Modbus and DNP3 are the dominant SCADA communication protocols in energy, water, and manufacturing — and both were designed with zero authentication. This guide covers the specific attack techniques these protocols enable, real-world exploitation patterns from incident reports, and how OT security teams can add detection without disrupting production.
OT Endpoint Security: Deploying EDR and XDR in Industrial Environments Without Disrupting Control Systems
Deploying endpoint detection and response tools on OT assets — PLCs, HMIs, engineering workstations, historians — requires a different approach than IT EDR rollouts. Aggressive scanning, real-time interception, and performance overhead that are acceptable on IT endpoints can destabilise industrial control systems. This guide covers agent versus agentless approaches, deployment sequencing, and what OT-specific EDR products actually monitor.
CyberAv3ngers Hits 30+ Minnesota Water Utilities: CISA AA26-097A Updated Advisory for PLC Operators
Iran-linked CyberAv3ngers struck more than 30 Minnesota water systems on July 26-27, 2026, exploiting Unitronics Vision Series default credentials and CVE-2021-22681 to take one plant offline. CISA updated advisory AA26-097A with new detection guidance for Rockwell Automation environments. Actionable steps for water and energy OT operators.
Private 5G and LTE in OT Environments: Attack Surface and Security Architecture for Industrial Cellular
Manufacturers, utilities, and logistics operators are deploying private 5G and LTE networks to enable wireless OT connectivity for AGVs, robotics, sensors, and field devices. This guide covers the security architecture differences from Wi-Fi, the attack surface specific to industrial cellular, and hardening guidance for private cellular deployments.
AVEVA System Platform SCADA Security: Attack Surface, Vulnerabilities, and Hardening Guide
AVEVA System Platform (formerly Wonderware) is one of the most widely deployed SCADA and HMI platforms in industrial environments. This guide covers its attack surface, known vulnerability classes, and hardening practices for security teams and OT engineers.
OT Patch Management in Practice: A Field Guide for Industrial Control System Operators
Patching industrial control systems is categorically different from IT patching. Production constraints, vendor dependency, and long asset lifecycles make standard patch cadences unworkable. This guide covers compensating controls, vendor coordination, and a realistic patching process for OT environments.
AI Workflow Tools in OT Environments: The Attack Surface Industrial Operators Are Building Without Noticing
n8n, Langflow, and Node-RED are being adopted in industrial environments for AI-driven process analytics, predictive maintenance, and historian integration. The NadMesh botnet now specifically targets these tools. This creates a new attack path from exposed AI workflow interfaces to OT data historians and, in poorly segmented environments, to SCADA systems.
OT Threat Hunting with Passive Network Monitoring: An ICS Practitioner Guide
OT threat hunting is fundamentally different from IT threat hunting — you can't run endpoint agents on PLCs, and active scanning can destabilise control systems. This guide covers passive network monitoring with Zeek and Suricata ICS decoders, OT-specific hunting hypotheses, and the protocol anomalies that separate legitimate traffic from attacker activity in industrial environments.
Nation-State Router Targeting at the OT Perimeter: Technical Response to CISA AA26-194A
CISA Advisory AA26-194A documents Russian FSB Center 16 exfiltrating router configurations from critical infrastructure globally via SNMP and Cisco Smart Install. For OT environments, perimeter routers hold additional sensitivity: they contain VPN configurations, routing to SCADA networks, and credentials that can enable lateral movement from IT into OT. This guide covers the OT-specific implications and hardening steps.
ICS Patch Tuesday July 2026: Siemens TIA Portal RCE, Schneider IGSS Critical, Rockwell 12 Advisories
July 2026 ICS Patch Tuesday brings a significant advisory load: Siemens releases 18 advisories including a critical TIA Portal remote code execution flaw, Schneider Electric addresses a critical IGSS SCADA vulnerability, and Rockwell Automation publishes 12 advisories covering FactoryTalk and Logix controllers. Prioritisation guidance for OT security teams.
IEC 62443 in Practice: Security Levels, Zone-Conduit Model, and Implementation for OT Practitioners
IEC 62443 is the international standard series for industrial automation and control system security. This practitioner guide covers the security level framework, the zone-conduit network architecture model, and what implementation actually looks like for OT security teams — from SL-1 baseline controls to SL-3 nation-state-resistant configurations.
FSB Center 16 Poland Grid Attack: OT Sector Analysis and Critical Infrastructure Implications
The UK and EU attribution of December 2025's Poland energy grid attack to FSB Center 16 — an operation that nearly caused a blackout for half a million people — has direct implications for OT security in European energy and water sectors. Analysis of the attack characteristics, attribution dispute, and what ICS operators should take from the formal sanctions.
MQTT Security in IIoT: Authentication, TLS, and Broker Hardening
MQTT is the dominant messaging protocol for Industrial IoT — used in energy monitoring, manufacturing telemetry, building automation, and smart grid applications. Its minimal design and widespread default configurations leave most deployments exposed to unauthenticated access, data interception, and command injection. This guide covers the attack surface and hardening approach.
Smart Grid and Advanced Metering Infrastructure (AMI) Cybersecurity: Attack Surface and Hardening in 2026
Advanced Metering Infrastructure connects tens of millions of smart meters to utility head-end systems via RF mesh and cellular networks. The attack surface — bidirectional communication, large device counts, heterogeneous firmware, and direct connection to distribution grid controls — is poorly understood outside specialist OT security teams.
U-Boot Vulnerabilities in Industrial Control Systems: Embedded Firmware Security in 2026
U-Boot is the dominant open-source bootloader for embedded Linux devices — including industrial routers, RTUs, PLCs, and SCADA components. Vulnerabilities in U-Boot's FIT image parsing and boot verification logic have direct implications for OT device firmware integrity and secure boot trust chains.
FrostyGoop: The ICS Malware That Weaponised Modbus TCP Against Energy Infrastructure
FrostyGoop (BUSTLEBERM) is the first publicly documented ICS-specific malware to directly communicate with industrial devices via Modbus TCP. Its January 2024 deployment against a Ukrainian district heating company — disrupting heat for 600 buildings in winter — demonstrates the operational impact of OT-native attack tools.
GhostLock CVE-2026-43499: Advisory for OT Environments Running Linux-Based Historian and SCADA Systems
The GhostLock Linux kernel vulnerability (CVE-2026-43499) enables local privilege escalation to root in approximately five seconds with 97% reliability. OT environments running Linux-based historian servers, OPC-UA gateways, and SCADA platforms are directly affected. Patching and mitigation guidance for industrial operators.
Modbus Protocol Security: Attack Surface, Exploitation, and OT Network Hardening
Modbus is the most widely deployed industrial protocol in the world — and one of the least secure. This guide covers the Modbus attack surface, documented exploitation techniques used against OT environments, and practical hardening measures for energy, water, and manufacturing defenders.
OT Incident Response: The First 48 Hours
When a cyber incident hits an operational technology environment, the first 48 hours determine whether a brief outage becomes a prolonged shutdown. This playbook covers the critical decisions, sequencing, and OT-specific considerations that IR teams need to get right from the first alert.
Siemens S7comm Protocol: Attack Surface, Unauthenticated Access, and OT Network Detection
S7comm is Siemens' proprietary PLC communication protocol. Legacy S7comm lacks authentication and encryption, enabling unauthenticated read/write access to process data and PLC control commands. This guide covers the attack surface, documented exploit techniques, and detection approaches for OT defenders.
Securing OT Remote Access: VPN, ZTNA, and Jump Server Architecture for Industrial Networks
Remote access to operational technology environments expanded dramatically during 2020-2022 and was never fully locked down. This guide covers the specific risks of each remote access pattern — vendor VPNs, site VPNs, jump servers, and ZTNA — and the hardening steps that reduce the attack surface without breaking the maintenance workflows OT teams depend on.
PIPEDREAM and COSMICENERGY: The ICS Malware Frameworks Built for Grid Disruption
PIPEDREAM (disclosed April 2022) and COSMICENERGY (May 2023) are the two most sophisticated ICS-targeting malware frameworks to emerge since TRITON. Both target industrial protocols used in power and energy infrastructure. This analysis covers their architecture, capabilities, and what they mean for defenders.
DNP3 Protocol Security: Authentication, Attack Vectors, and Hardening for Energy and Water Utilities
DNP3 is the dominant SCADA communication protocol for energy and water utilities in North America. This guide covers its security architecture, known attack vectors, DNP3 Secure Authentication v5, and practical hardening for operational environments.
Ransomware in OT Environments: How Manufacturing and Energy Operators Are Being Hit in 2026
Ransomware groups are no longer stopping at IT systems. This sector briefing covers how operators in manufacturing, energy, and water treatment are being targeted in 2026 — the specific OT attack vectors, operational impact patterns, and the defensive controls that matter most.
ICS Patch Tuesday June 2026: Critical Vulnerabilities in Siemens, Honeywell, and Mitsubishi Electric Products
The June 2026 ICS Patch Tuesday cycle brings critical and high-severity advisories affecting Siemens industrial networks, Honeywell building and process control systems, and Mitsubishi Electric PLCs. OT security teams should prioritise triage and remediation planning for affected assets.
CISA Advisory: Automatic Tank Gauge Systems Under Active Attack — What OT Operators Need to Do Now
CISA, FBI, NSA, and five other US federal agencies issued a joint advisory in June 2026 warning of active malicious cyber activity targeting internet-exposed automatic tank gauge (ATG) systems across the energy, water, transportation, and critical infrastructure sectors. Attackers are exploiting authentication bypass and command execution flaws to modify pump controls and disable safety alerts.
OPC UA Security: Attack Surface Analysis and Hardening Recommendations for Industrial Environments
OPC Unified Architecture has become the dominant interoperability standard for industrial communication — and a consistent target in ICS-focused threat campaigns. This analysis covers the OPC UA threat model, documented vulnerability classes from recent CVEs, known exploitation by nation-state actors, and the hardening steps that reduce exposure without breaking operational continuity.
Advantech WebAccess/SCADA: Multiple High-Severity Vulnerabilities Enable Remote Code Execution
Advisories covering Advantech WebAccess/SCADA document path traversal, unrestricted file upload, and SQL injection vulnerabilities rated up to CVSS 8.8. WebAccess/SCADA is deployed across manufacturing, energy, and water treatment facilities globally. This analysis covers the vulnerability classes, exploitation paths, and immediate mitigations for OT operators.
Record 508 ICS Advisories in 2025: What the Vulnerability Surge Means for OT Defenders
Forescout's analysis of 2025 ICS security advisories identifies a record 508 advisories covering 2,155 vulnerabilities — with 82% rated high or critical. Field controllers, PLCs, and SCADA systems are the primary targets, and the growing share of advisories with no available patch creates an unresolvable exposure category that demands compensating controls.
CISA's Zero Trust Roadmap for OT: What the April 2026 Joint Guidance Means for Industrial Operators
CISA's April 2026 joint guidance 'Adapting Zero Trust Principles to Operational Technology' lays out a practical roadmap for applying zero trust in environments where the standard IT playbook doesn't work — legacy protocols, uptime requirements, and safety constraints included.
Iranian APT Groups Escalate Attacks on Internet-Exposed PLCs: Water, Energy and Government Under Threat
Since March 2026, Iranian-affiliated APT actors have been conducting disruptive attacks on internet-exposed programmable logic controllers across US critical infrastructure — particularly water/wastewater, energy, and government services. A joint advisory from CISA, FBI, NSA and US Cyber Command details the campaign and recommended mitigations.
CISA CI Fortify: What the New OT Isolation Guidance Means for Operational Technology Operators
CISA's CI Fortify initiative moves beyond standard patching guidance to address a harder problem: how critical infrastructure OT environments maintain operational continuity when internet, cloud, and telecom connectivity is severed during a geopolitical cyber crisis.
IEC 62443: The OT Security Standard Your Procurement Team Needs to Understand
IEC 62443 is the international standard series for industrial cybersecurity. This explainer covers the structure of the standard, what Security Levels mean in practice, the zones and conduits model, and how to reference 62443 in vendor contracts to actually improve your security posture.
OT Threat Landscape 2026: New Dragos Groups, Shrinking Exploit Windows, and the Visibility Crisis
Dragos's 2026 OT cybersecurity year-in-review identifies 26 threat groups specifically targeting operational technology -- including three newly tracked groups -- as exploit timelines compress to 24 days and fewer than one in ten OT networks have active monitoring. A practical analysis for OT security practitioners.
Default Credentials, Internet-Exposed PLCs, and the Unsophisticated Actor Problem
CISA's April 2026 joint advisory warns of Iranian-affiliated actors targeting internet-facing PLCs with basic techniques. The Poland energy attack demonstrated the real-world consequences. This analysis covers the threat, affected protocols, and what operators must do now.
Water Sector Cyber Threats 2026 -- From Oldsmar to Nation-State Pre-Positioning
Water and wastewater systems face a growing and diverse cyber threat -- from opportunistic attacks exploiting internet-exposed HMIs to sophisticated nation-state pre-positioning campaigns. This briefing covers the current threat landscape, attack vectors, and sector-specific defensive priorities.
NIS2 OT Compliance: What the 2026 Enforcement Wave Means for Industrial Operators
EU member states are now issuing the first formal NIS2 enforcement actions against operators of essential services. Industrial operators — energy utilities, water authorities, manufacturing firms, and transport operators — face binding cybersecurity obligations, supply chain security requirements, and 24-hour incident reporting duties that the prior NIS1 regime did not meaningfully enforce. What actually changed and what OT teams need to do.
CISA Advisory: ABB AC500 PLC Remote Code Execution in Manufacturing and Process Control
CISA has issued an advisory covering a critical remote code execution vulnerability in ABB's AC500 PLC series, one of the most widely deployed programmable logic controller families in European manufacturing, paper and pulp, food processing, and water infrastructure. The flaw affects the Modbus TCP server component and requires no authentication to exploit.
Claroty 2026 State of XIoT Security: OT Vulnerability Disclosures Hit New High
Claroty's annual State of XIoT Security report documents record-high vulnerability disclosures across operational technology, IoT, and connected medical devices. OT vulnerabilities now account for the majority of disclosed flaws, with critical infrastructure sectors facing compounded exposure from legacy device lifecycles and the accelerating advisory pace.
Volt Typhoon Pre-Positioning in US and UK OT Networks
China-nexus threat actor Volt Typhoon has systematically infiltrated operational technology networks across US and UK critical infrastructure sectors, establishing persistent footholds in energy, water, and communications systems for potential future disruption.
OT Network Segmentation: Purdue Model, DMZ Design, and Historian Isolation
A practical guide to network segmentation in OT environments, covering the Purdue Reference Model, industrial DMZ architecture, data historian isolation, and the tradeoffs between operational access and security posture.
Modbus and DNP3: Inherent Security Weaknesses in Legacy Industrial Protocols
Modbus and DNP3 were designed for reliability and interoperability, not security. An analysis of the structural security weaknesses in both protocols -- unauthenticated commands, lack of encryption, spoofing, and replay attacks -- and the compensating controls available to practitioners.
The OT Asset Inventory Problem: Visibility Gaps, Passive Discovery, and Unmanaged Devices
Most industrial operators cannot accurately enumerate the devices on their OT networks. This visibility gap is the foundational barrier to OT security -- you cannot protect what you cannot see. A practical look at passive discovery tools, the limits of vendor inventories, and strategies for building actionable asset visibility.