Cybersecurity Bulletin: Key Security Updates for Water & Wastewater Utilities

Cybersecurity,

August 27, 2026

Member Security Bulletin

Federal cybersecurity agencies and water sector partners continue to report increased cyber activity affecting critical infrastructure. Below are the most important updates for Utah water and wastewater utilities.

High Priority

Oracle Vulnerability Under Active Exploitation

A critical vulnerability affecting Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in is currently being actively exploited in the wild.

Recommended Actions
  • Determine whether your organization uses Oracle HTTP Server or Oracle WebLogic.
  • Apply available vendor security updates immediately if affected.
  • Monitor systems for unusual activity until patching has been completed.

China-Linked Threat Group Targeting Critical Infrastructure

The FBI, NSA, and U.S. Cyber National Mission Force released a joint cybersecurity advisory regarding ongoing activity from a China-linked threat group targeting U.S. critical infrastructure.

Recommended Actions
  • Review the advisory with your IT provider.
  • Verify multi-factor authentication is enabled for all remote access.
  • Review privileged accounts and administrative access.

Ongoing PLC Cyber Activity

Federal cybersecurity partners continue monitoring cyber activity targeting programmable logic controllers (PLCs) used throughout the water and wastewater sector.

Recommended Actions
  • Verify PLCs and industrial control system devices are not directly accessible from the public internet.
  • Review any cellular modem or remote access configurations.
  • Monitor control systems for unauthorized access or unexpected configuration changes.

Additional Updates

Kennedy Jenks Ransomware Incident

Kennedy Jenks has released additional information regarding the recent ransomware incident. Utilities currently working with Kennedy Jenks should remain aware of the situation and follow any guidance provided directly by the company.

Micro-Comm Ransomware Incident

WaterISAC reported that Micro-Comm Inc. has been identified as a potential ransomware victim. Utilities utilizing Micro-Comm products or services should monitor communications from the company for additional guidance.

EPA Releases Drinking Water Systemic Issues Checklist

EPA has released a new checklist to help drinking water agencies identify recurring operational issues before they impact service reliability. The resource may be useful during internal reviews and planning efforts.

New CISA ICS Advisories Available

CISA has published additional Industrial Control System security advisories affecting multiple vendors and products. Utilities should work with their IT and SCADA providers to determine whether any advisories apply to their environment.

Report Suspicious Activity

If your utility experiences suspicious cyber activity or a confirmed cyber incident, report it immediately using the resources below.

Utah Division of Drinking Water

24/7 Emergency Response Line

(801) 560-8456