First edition of our weekly review. The idea is simple: every Friday, what mattered over the last seven days, read with the eyes of a risk owner rather than an analyst. No CVE list for its own sake. For each story, what it changes for a Canadian organization, and the question to ask on Monday morning.
This week has one thread running through it: the incidents that counted did not primarily steal data. They stopped operations. A company that can no longer ship, a power facility that no longer produces, a hospital whose doors no longer respond. Then, in the second part, three less spectacular facts that should nonetheless change how you manage patching, industrial exposure and data.
Part 1: operations down
Boston Scientific can no longer take or ship orders
On August 25, Boston Scientific detected a cyberattack that caused a network outage and cut access to several systems and business applications, including those used to process and ship customer orders. The company reported it to the SEC, activated its incident response and brought in outside experts. At the time of writing, it gives no timeline for full restoration, no attack type, no origin and no indication of whether data was taken. No group has claimed responsibility.
The scale sets the stakes: 59,000 employees, 13 manufacturing sites, a presence in 127 countries, more than $20 billion in 2025 sales. And the products are not consumer goods: stents, catheters, pacemakers. Behind every pending order there is an operating room somewhere counting on a delivery.
What it changes: the most useful question is not "what data was taken", it is "how long can we run without this system, and who knows the answer". A business continuity plan written for the scenario where ransomware encrypts the servers does not necessarily answer the scenario where the order-taking application is unavailable while everything else works. If your RTOs are defined per system rather than per business process, this is the week to reread them.
A UK power facility offline for four days
The Telegraph revealed on August 22 that a small electricity generation facility in the UK was taken offline for four days by Iran-linked hackers. The facility is marginal for the grid, "less than a rounding error" according to a government source, and that is exactly what makes the case instructive: the goal was not to plunge a country into darkness, but to demonstrate that it can be done. In parallel, dozens of wastewater treatment plants across twelve US states have been targeted since late July, with flooding and pressure loss reported.
What it changes: for Canadian municipalities, utilities and manufacturers, the adversary's proof of concept now exists. A risk assessment of an OT asset can no longer rest on "nobody cares about a small facility". Small facilities are precisely the ones you pick to practice on.
Winnipeg: a hospital without its doors and ventilation
The Health Sciences Centre in Winnipeg reported on August 10 a ransomware incident that hit its building management systems: door access control, central monitoring of heating and ventilation, a closed security office and ID cards that could not be issued or updated. Patient care was not interrupted, ventilation kept running in local mode, and the investigation into possible data access continues. Recovery was still under way last week.
What it changes: this is the Canadian version of the same message. The perimeter of a cyber incident includes physical systems, often managed by a different department than IT, with different vendors and different maintenance contracts. If your risk map stops at servers and workstations, it misses what the attacker found.
Cl0p and PTC Windchill: your product IP was in a web application
This week the Cl0p group named more than forty organizations, including Shell, Philips, Fiserv and Zebra, as victims of a campaign against PTC's Windchill and FlexPLM product lifecycle management platforms, exploited through CVE-2026-12569, an unauthenticated remote code execution flaw already listed in the KEV catalog in June. The published data runs from 1 GB to several terabytes per organization: engineering documents, blueprints, diagrams, backups. The analysis published on August 24 describes a bespoke web shell able to map the data vaults and decrypt every credential stored in the Windchill keystore.
What it changes: a PLM system holds what you would find hardest to replace, and it is exposed to the internet because your suppliers and plants need to reach it. The question for your external attack surface inventory: which business platforms are reachable from the internet, and who, by name, owns each one?
Part 2: three facts that change how you manage
Citrix NetScaler, exploited eight weeks after the patch
CVE-2026-8452 was patched by Citrix on June 30. The advisory described it as a memory overflow leading to denial of service. On August 14, watchTowr researchers published an analysis and exploit code showing it actually allows unauthenticated remote code execution on appliances configured as a gateway (SSL VPN, ICA Proxy) or as an AAA virtual server. In the following days, two firms observed attackers dropping web shells and running discovery commands. On August 26, CISA added the flaw to the KEV catalog with a remediation deadline of August 29 for federal agencies.
What it changes: a vendor's severity rating is an opinion at a point in time; your exposure is a fact. A patch "available" for eight weeks protects nothing until it is applied on your edge devices, and those devices are the preferred entry point of ransomware groups. Two governance rules follow: a maximum remediation window for anything internet-facing, independent of the vendor's initial rating, and a review of that rating the moment exploit code becomes public.
AI-written exploits against Siemens PLCs
On August 19, the NSA, CISA, FBI, Department of Energy and EPA issued a joint advisory (AA26-231A): actors are using artificial intelligence to generate Python exploitation scripts against internet-exposed Siemens S7 programmable logic controllers, building on public industrial automation libraries. They locate targets with scanning services such as Censys and ZoomEye, then deploy tools disguised as monitoring software. Targeted sectors: critical manufacturing, energy, water and wastewater, chemicals, food and agriculture. The agencies are blunt: "this is not a theoretical risk, it is an active threat".
What it changes: AI does not create new holes in your controllers. It removes the skill barrier that used to protect the old ones. An exposed PLC with a default password was a target for a few specialists; it becomes a target for anyone. The advisory's first recommended action is the same as episode 1 of our AI security series: the inventory. You cannot protect what you do not know you have.
Nova Scotia Power cannot explain why thirty years of data was never deleted
Before the regulator on August 18, a Nova Scotia Power executive acknowledged that the company does not know why a digital copy of almost three decades of customer data, created in 2021, was never deleted. Policy calls for automatic deletion cycles of no more than 90 days. The file was still there in March 2025 when actors the company believes are based in Russia took it: addresses, phone numbers, banking information and social insurance numbers of hundreds of thousands of customers. A telling detail: the company had stopped collecting SINs in 2018, but its legacy system could not delete them, and a full purge was only decided in 2024. The 2021 copy, never updated, therefore still held numbers the organization believed were gone.
What it changes: retention is a security control, not a compliance formality. Every record kept beyond its purpose is a record you will one day have to notify. Quebec's Law 25 requires personal information to be destroyed once its purpose is served; this incident shows what a destruction policy is worth when nobody verifies it. The question for Monday: who in your organization can prove that copies, exports and backups of personal data are actually destroyed on schedule?
The week's three questions for an executive committee
- For each of our five most critical business processes, how long can we run without the system behind it, and is that number written down anywhere?
- What is our maximum remediation window for an internet-facing device, and did we meet it this month for Citrix, Zimbra and our industrial controllers?
- Who can demonstrate, with evidence, that our personal data is destroyed when it is supposed to be?
If those three questions have no documented answer, the executive committee memo in ten questions is a good starting point, and our free cyber risk score places you in ten minutes across the resilience, data and third-party domains. To track these exposures continuously rather than once a year, that is the job of the EASM and CTI modules of the FortaRisks platform.
Sources: BleepingComputer, Boston Scientific · Security Affairs, UK power facility and water attacks · CBC, Health Sciences Centre · SecurityWeek, Cl0p and PTC Windchill · Help Net Security, Citrix NetScaler · CISA, advisory AA26-231A · Canadian Underwriter, Nova Scotia Power