Monthly Threat Brief: July 2026

July2026

July 2026 Threat Brief: When Cyber Incidents Become Operational Incidents

For several organizations in July, a cyber incident did not stay behind a screen.

Water utilities lost control of PLCs. Manufacturing lines stopped. Remote-access appliances provided paths into corporate environments. Credentials that had been sitting forgotten for years suddenly became useful to attackers.

The common thread is not one vulnerability or threat actor. It is how quickly weaknesses in IT, identity, remote access, and OT can translate into consequences for the operation itself.

Our July 2026 Monthly Threat Brief examines the incidents behind that shift and the lessons security and operational teams should take from them.

Water Utilities Were Forced Back to Manual Control

One of July's most significant developments began on July 26, when attackers exploited internet-exposed Rockwell PLCs at water utilities across seven states.

Roughly 36 utilities in Minnesota were affected in a single weekend. Attackers locked operators out of their own PLCs, and some facilities experienced pressure loss or flooding before personnel moved to manual control and restored service.

The incidents put a very practical issue in focus: direct internet exposure in OT can create a path from cyber access to physical disruption.

Removing PLCs from direct internet exposure, segmenting OT networks, replacing default or reused credentials, and rehearsing manual operations are not theoretical best practices when losing control of a device can affect the process it manages.

PLC Targeting Is Expanding Beyond a Single Vendor

The water utility incidents were not the only OT activity worth watching.

CISA also updated its advisory on Iranian PLC targeting to include Siemens and Schneider platforms alongside Rockwell. At one victim organization, actors reportedly disabled safety shutdown logic without being detected.

Together, the developments show attackers pursuing more than network access or data theft. Pressure loss, forced manual operation, unauthorized control-logic changes, and interference with safety functions are increasingly part of the threat model for operational environments.

Ransomware Can Stop More Than the Office Network

Coca-Cola's Fairlife operations provided another example of the connection between cyber incidents and physical operations.

A ransomware attack attributed to Anubis halted U.S. production at four Fairlife plants. The group also claimed to have stolen a terabyte of data, but the operational impact is just as important: production stopped.

Manufacturing remains a major ransomware target precisely because disruption does not necessarily stay within traditional IT. When business systems and production environments depend on one another, an IT compromise can quickly affect what happens on the factory floor.

That makes segmentation, offline copies of critical MES and SCADA configurations, manual-production procedures, and continuity planning part of ransomware preparedness too.

The Remote-Access Layer Keeps Opening the Door

SonicWall, Check Point, Cisco, and Fortinet all disclosed exploited vulnerabilities affecting edge or remote-access technology during the month.

In several cases, those weaknesses fed directly into ransomware activity.

These systems deserve attention not simply because they are vulnerable, but because of where they sit. VPNs, SD-WAN appliances, firewalls, and management platforms are exposed by design and often provide privileged paths deeper into an environment.

For those devices, patching speed and access controls need to reflect that position. July's activity reinforces the value of tracking known exploitation, accelerating remediation for exposed systems, disabling unused remote-access services, and verifying that fixes were actually successful.

Four-Year-Old Access Was Still Good Enough

Not every incident required exploiting vulnerable software.

An extortion crew used a four-year-old Salesforce API token originally issued to a vendor to access customer data belonging to nearly 200 companies. Separately, Cisco disclosed exploitation of a Firewall Management Center flaw involving embedded static credentials.

Both highlight a less visible form of exposure: access that exists long after anyone is actively thinking about it.

Third-party integrations, API tokens, OAuth grants, service accounts, and other long-lived credentials accumulate over time. If they are not inventoried, expired, and revoked when relationships or requirements change, yesterday's integration can become tomorrow's entry point.

July's Incidents Put the Consequences in Plain View

The individual incidents are different, but the pattern is increasingly difficult to ignore.

A compromised PLC can become a pressure problem. Ransomware in enterprise systems can become a production shutdown. An exposed VPN can become a path to domain compromise. A forgotten API token can expose data across hundreds of organizations.

For security teams, understanding whether something is vulnerable is only part of the job. The harder and increasingly important question is what happens to the organization if that weakness is actually used.

That means knowing which systems are exposed, which access paths still exist, how IT connects to operations, what can affect physical processes, and how the organization will continue operating when prevention does not work.

The full July 2026 Monthly Threat Brief covers these incidents in greater detail, along with the emerging threat surface, operational exposure, strategic takeaways, and practical actions organizations can take now.

July 2026 Monthly Threat Brief