August 17, 2026
Global IoT and connected-hardware news from around the world - silicon, infrastructure, edge intelligence, standards, and the business models behind long-lived products.
This week's IoT News Digest at a glance. Earth-by-night background: NASA via Wikimedia Commons.
This week's stories arrive at an uncomfortable intersection. Nation-state actors are targeting water infrastructure at scale across the US, a scan of the public internet finds thousands of industrial controllers directly reachable with no authentication, and a connected industrial gateway marketed for Industry 4.0 work ships a maximum-severity unauthenticated remote code execution vulnerability in the same week. The defensive response - a cybersecurity coalition launched at DEF CON with government backing - reveals how far behind under-resourced operators have fallen.
Running alongside the security stories, two sets of company numbers point the same direction. Semtech's decision to exit cellular modules three years after acquiring Sierra Wireless shows how IoT value chains get rationalized when consolidation expectations meet market reality. Nordic Semiconductor's quarter shows the other side of that trade: its fastest-growing line is the one carrying cloud lifecycle services, including compliance tooling for the CRA deadline now five weeks away.
Now on Amazon: Tangibles: How Software Turns Hardware into Platforms
The thesis behind this newsletter is now a book. Tangibles: How Software Turns Hardware into Platforms lays out how connected products move from one-time sales into evolving, service-backed platforms - the validation traps, digital interfaces, security moves, and recurring-revenue models this digest tracks each week.
Cross-Cutting Signals
Nation-state attacks on critical infrastructure are advancing faster than sector-specific defenses
Multiple US states reported coordinated cyberattacks on water systems in the same week that a DEF CON coalition launched managed detection and response for small utilities - confirming that attackers are already inside the window that defenders are only beginning to close.
Cellular IoT deployed without private APNs or VPN creates direct internet-to-control-system bridges
Of the internet-exposed PLCs Forescout found this week, more than 70 percent of US devices connect through cellular modems with no network isolation. The attack path requires no vulnerability - just a SIM card and an open port.
Value chain focus is reasserting itself in IoT after the consolidation wave
Semtech's exit from cellular modules three years after paying $1.2 billion for Sierra Wireless illustrates a broader pattern: companies that assembled broad IoT portfolios are now identifying which layers they actually want to own and shedding the rest.
Silicon vendors are attaching lifecycle services to the part, and the attached line grows fastest
Nordic's long-range segment, which carries its nRF Cloud services, grew 94% against 29% for its high-volume short-range business. The services being sold - vulnerability management, fleet observability, CRA reporting evidence - are the same operability duties the security stories in this issue show operators failing to meet on their own.
This Week at a Glance
Quick overview of what is shaping connected devices this week.
DEF CON and NRWA Launch Water Watch Center to Defend 91% of US Water Systems - The National Rural Water Association and DEF CON Franklin launched the Water Watch Center on August 10, bringing five managed detection and response providers to the 91% of the nation's 50,000 community water systems that serve fewer than 10,000 people. The launch followed coordinated nation-state attacks on water systems across at least 12 US states. A Senate bill would authorize $300 million annually for state revolving funds to support small utility cybersecurity.
Semtech Sells Sierra Wireless Cellular Module Business to Compal for $62 Million - Semtech announced on August 13 that it will sell substantially all assets of its cellular module business - the portion of Sierra Wireless acquired in 2023 for $1.2 billion - to Compal Electronics for $62 million in cash. CEO Hong Hou identified LoRa connectivity and data center as Semtech's focus areas, signaling that the cellular module portfolio no longer fits the strategy.
Siemens Patches Maximum-Severity Unauthenticated RCE in Simatic IoT2050 in August ICS Patch Tuesday - Siemens published 10 new ICS advisories on August 12, including a CVSS 10.0 missing-authentication vulnerability in Simatic IoT2050 Advanced devices that allows a remote, unauthenticated attacker to execute arbitrary code with elevated privileges. Schneider Electric and Phoenix Contact published parallel advisories for code execution, authentication bypass, and SQL injection flaws in their own ICS products.
4,407 Rockwell PLCs Found Internet-Exposed, 86% Running a 2017 Firmware Vulnerability - A Forescout Vedere Labs scan published August 7 found 4,407 internet-facing Rockwell Automation and Allen-Bradley PLCs globally, 2,844 of them in the United States. Of 22 devices in cities already struck by the July 2026 nation-state campaign, 19 ran firmware still vulnerable to CVE-2017-16740, a flaw with a patch available for nine years. Over 70% of US-exposed devices connect through cellular modems with no VPN or private APN protection.
Nordic Semiconductor Q2 Revenue Up 33% as Cloud Lifecycle Services Carry the Fastest Growth - Nordic reported $218.6 million in Q2 revenue on August 6, up 33.2%, with gross margin at 53%. Long-range revenue, which includes nRF Cloud services from the Memfault acquisition, grew 94% to $14.6 million while the much larger short-range business grew 29%. Industrial and healthcare revenue rose 45% to $86.1 million. The quarter added firmware vulnerability scanning built for EU Cyber Resilience Act compliance, and the report names higher lifecycle value per end-product as one of four growth drivers.
News In Detail
1. DEF CON and NRWA Launch Water Watch Center to Defend 91% of US Water Systems
A sector-specific MDR coalition for under-resourced water utilities arrives after coordinated nation-state attacks on systems across 12 states, backed by proposed $300M federal funding.
The National Rural Water Association and DEF CON Franklin launched the Water Watch Center on August 10 to provide cybersecurity services to small US water utilities. The program targets systems serving fewer than 10,000 people, which account for 91% of the country's roughly 50,000 community water systems. Five managed detection and response providers - Defendify, Legato Security, L1 Secure, Rapid7, and Sentinel Technologies - will share threat intelligence and deliver security services to participating utilities. The launch followed what NRWA described as a coordinated nation-state cyberattack on more than 30 community water systems in Minnesota, with similar activity reported across at least 12 additional states. Nearly 450 volunteer cybersecurity experts were paired with utilities in a pilot phase across seven states. A future partnership with Vanderbilt University will add AI-driven defensive agents through DARPA's CASTLE program research.
Senators Schiff and Klobuchar introduced concurrent legislation, the Water Cyber Shield Act, authorizing $300 million annually through the Drinking Water and Clean Water State Revolving Funds and granting EPA explicit cybersecurity authority over drinking water systems. The combination of a sector-specific MDR coalition and dedicated federal funding represents the model that the broader critical infrastructure cybersecurity framework has been pointing toward: direct operational security services to operators who cannot build or staff their own capability, funded at the infrastructure level rather than left to individual utility budgets.
Water systems are critical infrastructure in the same category as energy and transportation, but their security investment baseline has been far lower. A utility serving 4,000 customers has no security operations center, no incident response team, and often no dedicated IT staff. The Water Watch Center provides what those utilities cannot self-fund: continuous monitoring, threat detection, and incident response. The sector coalition model, where MDR providers share threat intelligence across all participating utilities, is more effective than individual utility contracting - attackers targeting water infrastructure in Minnesota today are likely targeting similar systems in other states tomorrow.
Signals to Watch
Whether the Water Cyber Shield Act passes and EPA uses the explicit cybersecurity authority to set minimum security standards for systems below the 10,000-customer threshold
How quickly the five MDR providers onboard utilities and whether the volunteer expert pairing program scales beyond the seven-state pilot
Whether other critical infrastructure sectors (energy distribution, municipal gas) adopt comparable sector-specific MDR coalition models following the water utility template
Key Links
2. Semtech Sells Sierra Wireless Cellular Module Business to Compal for $62 Million
Three years after a $1.2 billion acquisition, Semtech exits the cellular module business to concentrate on LoRa connectivity and data center - a clear signal of where it sees durable market position.
Semtech announced on August 13 a definitive agreement to sell substantially all assets and operations of its cellular module business to Compal Electronics for $62 million in cash, subject to regulatory approvals expected to close in Q4 of Semtech's 2027 fiscal year. The sale covers the cellular module portfolio, intellectual property, customer relationships, and personnel acquired as part of Semtech's $1.2 billion takeover of Sierra Wireless in January 2023. Semtech CEO Hong Hou stated the divestiture allows the company to concentrate resources on LoRa connectivity and data center operations, which he identified as areas of strongest growth prospects and market position. Compal, a Taiwanese contract manufacturer known for laptops and electronics, adds the cellular IoT module business to a manufacturing portfolio that spans consumer and industrial hardware.
The transaction makes the strategic calculus explicit. Semtech entered the cellular module business through the Sierra Wireless acquisition, inheriting a product portfolio, customer base, and brand that required continued investment to remain competitive against Quectel, u-blox, and Telit. Three years later, the cellular module business is sold for $62 million - a fraction of what Semtech paid for the broader Sierra Wireless portfolio. That gap reflects the ongoing margin pressure in cellular IoT modules, the capital required to certify new modules across regional carriers, and the operational complexity of a hardware business that sits in a different growth trajectory than LoRa infrastructure or data center silicon. Semtech's LoRa business, which serves 125 million connected devices and provides the physical layer for a global LPWAN network, carries a different competitive moat than a cellular module line competing on price with high-volume Asian manufacturers.
For product teams selecting cellular modules, the transition to a Compal-owned Sierra Wireless portfolio raises practical questions: which carrier certifications carry through the acquisition, how the support and firmware update commitment changes under new ownership, and whether Compal will continue the Sierra Wireless OTA and device management services or hand off those responsibilities to module customers. The divestiture also confirms a pattern: IoT portfolio consolidation moves that made sense in 2021-2023 are being reassessed as acquirers identify which layers of the value chain they genuinely own versus which they inherited and cannot competitively sustain.
Signals to Watch
How Compal positions the cellular module business alongside its contract manufacturing operations - whether it retains the Sierra Wireless brand and maintains OTA/device management services or reduces to a module-only offering
Whether Semtech's LoRa network infrastructure benefits from capital redeployed from the module business, specifically in gateway hardware and LoRa Cloud service development
How other IoT platform acquirers with mixed cellular and LPWAN portfolios respond to Semtech's explicit focus signal
Key Links
3. Siemens Patches Maximum-Severity Unauthenticated RCE in Simatic IoT2050 in August ICS Patch Tuesday
A CVSS 10.0 missing-authentication flaw in a device marketed as an Industry 4.0 gateway underlines that IoT-ready branding and patch discipline are separate requirements.
Siemens published 10 new ICS advisories on August 12 as part of the monthly Patch Tuesday cycle, including a maximum-severity vulnerability in Simatic IoT2050 Advanced devices. The flaw - a missing-authentication condition - allows a remote, unauthenticated attacker to execute arbitrary code on the underlying server with elevated privileges. Siemens separately patched a critical code execution vulnerability in Siveillance Video Management Servers and high-severity flaws across Solid Edge, Simcenter Nastran, Siemens License Server, Simcenter Femap, Parasolid, and Logo! Soft Comfort. Schneider Electric addressed code and command execution issues in NetBotz 5 and an authentication bypass in PowerChute Serial Shutdown. Phoenix Contact fixed SQL injection and denial-of-service conditions in PLCnext firmware. CISA published parallel advisories for vulnerabilities in Pulsetto, Mira, and Johnson Controls products.
The Simatic IoT2050 is a Siemens product line explicitly positioned for Industry 4.0 applications - an industrial gateway that runs Linux, connects OT systems to IT networks, and appears in factory edge deployments that require bridging between legacy control systems and cloud platforms. A CVSS 10.0 missing-authentication vulnerability in that specific product is not a fringe case: it is a maximum-severity flaw in hardware that operators select precisely because it sits at the IT-OT boundary. The patch cycle for industrial connected hardware runs differently from enterprise IT: devices may not have automated update mechanisms, may require maintenance windows that shut down production lines, and may run firmware that the operator did not configure and cannot easily access. Ten Siemens advisories in a single monthly cycle is a patch management load that strains the OT maintenance capacity of most industrial operators.
The Simatic IoT2050 vulnerability illustrates a problem that recurs across ICS Patch Tuesday cycles: the connected industrial hardware most central to IT-OT integration is also among the hardware most difficult to patch in production environments. A product team selecting a connected gateway for a factory edge application must ask not only what the gateway's connectivity features are, but what the vendor's patch release cadence is, whether the device supports verified OTA updates, and what the operator's patch application window looks like relative to the vendor's disclosure-to-patch timeline. Those operational questions belong in the procurement specification, not the post-deployment security audit.
Signals to Watch
Whether Siemens provides an automated OTA update path for the Simatic IoT2050 CVSS 10.0 patch or requires manual firmware application through site access
How CISA and sector-specific regulators respond to maximum-severity flaws in Industry 4.0 gateways, specifically whether a binding operational directive naming connected industrial gateways as a patch-priority category follows
Whether the August 2026 ICS Patch Tuesday volume drives procurement teams to add patch release cadence as an evaluation criterion for industrial connected hardware
Key Links
4. 4,407 Rockwell PLCs Found Internet-Exposed, 86% Running a 2017 Firmware Vulnerability
Cellular IoT deployed without VPN or private APN creates a direct internet-to-control-system path that no firewall protects, and nine-year-old unpatched firmware turns that path into a reliable exploit.
Forescout's Vedere Labs conducted a Shodan-based exposure scan on August 3, published by the Cloud Security Alliance on August 7, finding 4,407 internet-facing Rockwell Automation and Allen-Bradley PLCs worldwide, with 2,844 of them in the United States. In 22 of those devices located in cities already hit by the July 2026 nation-state campaign, 19 - 86% - ran firmware still vulnerable to CVE-2017-16740, a 2017 flaw for which Rockwell has published a patch for nine years. More than 70% of US-exposed controllers connect through cellular modems deployed without private access point names or VPN protection, creating a direct internet-to-PLC path with no intermediate network controls. A second flaw, CVE-2021-22681 in Logix controllers, has no available vendor patch and requires architectural workarounds rather than a firmware update.
The cellular connectivity finding is the more operationally significant detail. A PLC connected to the internet through a cellular modem without a private APN or VPN is effectively an internet-connected device with a control system on the other end. The cellular modem was selected for convenience - it avoids wiring a remote pump station to a fixed network - but the security configuration that would isolate that connection (a private APN, SIM-locked to operator infrastructure, or a site-to-site VPN terminating inside the OT network) was either not specified, not implemented, or removed in the field. The result is that the cellular connectivity intended to reduce physical infrastructure cost creates the network exposure that makes the nine-year-old firmware vulnerability exploitable from anywhere in the world.
CVE-2017-16740 having a patch that 86% of exposed devices have not applied is the firmware governance problem that the water infrastructure sector shares with most of industrial IoT. Patching a PLC at a remote water pump station requires a maintenance visit, a planned outage, verification that the patch does not affect process control logic, and documentation. In a utility with no dedicated IT staff and no formal firmware management process, that sequence does not happen on a nine-year-old advisory - or often at all. The combination of accessible network path and unpatched firmware is what makes internet-exposed PLCs a reliable target for nation-state actors conducting reconnaissance or pre-positioning for operational disruption.
Signals to Watch
Whether cellular module vendors (Quectel, u-blox, Telit, Sierra Wireless) begin requiring private APN or VPN configuration documentation as a condition of OT market certifications, or whether sector regulators mandate it
How Rockwell Automation responds to the exposure scan data - specifically whether it publishes updated deployment guidance for cellular-connected PLCs and sets a patch application deadline for the nine-year-old CVE
Whether the US EPA or CISA use the exposure scan findings to issue sector-specific ICS advisories targeting Allen-Bradley controllers in water and wastewater applications
Key Links
Forescout - ICS Cybersecurity in 2026: Vulnerabilities and Path Forward
Industrial Cyber - Forescout flags spike in high-severity OT/ICS flaws
5. Nordic Semiconductor Q2 Revenue Up 33% as Cloud Lifecycle Services Carry the Fastest Growth
A wireless silicon vendor now names lifecycle value per end-product as a growth driver, and its numbers show where the compounding actually happens.
Nordic Semiconductor reported second-quarter revenue of $218.6 million on August 6, up 33.2% from $164.1 million a year earlier, with gross margin at 53% and reported EBITDA of $34 million. First-half revenue reached $411 million, up 28.8%. The segment detail is where the story sits. Short-range wireless - Bluetooth Low Energy, Thread, Zigbee, Matter - remains the volume engine at $199.8 million and 91% of revenue, growing 29%. Long-range, at $14.6 million and 7% of revenue, grew 94%, and Nordic attributes that to both broader cellular product sales and rising nRF Cloud services revenue following its 2025 acquisition of Memfault. Industrial and healthcare customers contributed $86.1 million, up 45% year on year and 19% from the prior quarter, now 39% of revenue against 57% for consumer. Guidance for Q3 is $220 million to $240 million with gross margin held above 50%.
The report lists four growth drivers, and the fourth is the one worth reading closely: higher lifecycle value per end-product. Nordic describes nRF Cloud as the mechanism - customers maintain and update products across their operational life through vulnerability management, fleet observability, battery health monitoring, and regulatory compliance support. The quarter added remote battery health monitoring, fuel gauging, and firmware vulnerability scanning built specifically to help device makers meet EU Cyber Resilience Act obligations, whose reporting duties for actively exploited vulnerabilities begin September 11. A chip vendor is now selling the compliance evidence its customers will be legally required to produce, attached to silicon those customers already designed in.
For product teams, the design-win list shows what is being bought. Polar chose the nRF5340 for its Loop fitness bands; Minew selected Nordic parts for Bluetooth beacons used in indoor positioning; further wins spanned connected health and smart agriculture. Each of those is a one-time component decision that Nordic is converting into a multi-year service relationship, because the cloud layer keeps earning after the part ships. The structural lesson runs in both directions. A supplier that attaches lifecycle services to a component raises switching costs and earns revenue across the deployment's life rather than at the design win. A buyer that accepts those services accepts a dependency, and should ask what happens to fleet observability and CRA reporting if the relationship ends. Nordic declined to break out cloud services revenue separately, citing competitive sensitivity, which leaves the size of that recurring base unverifiable from outside.
Signals to Watch
Whether Nordic begins disclosing nRF Cloud services revenue separately, which would signal the recurring base has grown large enough to be a valuation argument rather than a competitive secret
Whether CRA-driven compliance tooling becomes a standard attach for wireless silicon vendors, with Silicon Labs, NXP, Espressif, and Infineon shipping comparable firmware vulnerability scanning ahead of the September 11 reporting deadline
Whether the industrial and healthcare mix keeps climbing past 39% of revenue, and whether long-range growth holds near double digits once the Memfault contribution laps its first full year
Key Links
Nordic Semiconductor - Quarterly reports and investor relations
Nordic Semiconductor - Full device observability and OTA via nRF Cloud powered by Memfault
From TheRoad
Previous issue: IoT News Digest #2632 - Issue 2632 covered Silicon Labs launching the BG2B Bluetooth 6 SoC with 1.1 uA sleep current, sub-meter Channel Sounding ranging, and PSA Level 3 security; the LoRa Alliance publishing TS014, TS018, and TR016 to automate device provisioning across 125 million LoRaWAN devices; Sabesp, Vivo, and IDEMIA building a three-layer security architecture for Brazil's largest water IoT initiative; Viakoo announcing Device Configuration Manager for automated OT/IoT configuration drift detection at Black Hat 2026; and Intelematics connecting its one millionth vehicle to the Australian emergency call platform across six OEM brands.
Deep dive and case submissions: Tangibles case study submission page - share real-world examples of connected products, smart infrastructure, and service-backed hardware.
Tangibles book progress: The Rockwell PLC exposure data and the Water Watch Center launch together illustrate the argument the book makes in the security and validation chapters. Operators deployed cellular-connected PLCs to reduce the cost of connecting remote sites - a reasonable hardware decision that skipped the security specification step the book identifies as part of validation. The cellular modem became the deployment shortcut that erased the network perimeter. Nine years later, 86% of exposed devices still run the original firmware. That is not a patch management failure alone; it is a lifecycle governance failure. The book argues that products designed without a defined firmware update path do not have a lifecycle - they have a deployment date and an unknown end state. The Water Watch Center represents what happens when that lifecycle gap accumulates at sector scale: the only viable response is an externally funded defense coalition, because individual utility operators cannot self-fund the capability.
The Semtech divestiture maps directly onto the business model chapter's argument about value chain clarity. Semtech acquired Sierra Wireless to build an end-to-end IoT connectivity position spanning LoRa, cellular, and cloud. Three years later, the cellular module business - competing on margin with high-volume Asian manufacturers - goes to Compal for $62 million. The LoRa infrastructure business, where Semtech has a genuine network effect and 125 million device deployments, stays. The book frames this as the recurring question for connected-hardware companies: at which layer of the stack do you have a durable competitive position, and at which layers are you paying to be present without a structural advantage? Semtech's answer is now explicit.
How to Use This Digest
Review your cellular-connected device deployments for private APN or VPN configuration. Any cellular modem connecting to an OT system or industrial controller without network isolation is reachable from the public internet regardless of what the device firmware does. Add network isolation verification to your deployment acceptance checklist before the next site goes live.
Treat patch release cadence as a procurement criterion for connected industrial hardware. The August Patch Tuesday cycle produced a CVSS 10.0 flaw in a device marketed for IT-OT integration. Ask vendors for their average time from vulnerability discovery to patch release, whether the device supports verified OTA updates, and what the expected maintenance window is for applying security updates in production - before signing the purchase order.
Bring one story per week into cross functional discussions between product, hardware, security, and operations to test how platform and policy shifts affect your portfolio and contracts.
Audit what your silicon supplier now sells above the part. Nordic's quarter shows vulnerability scanning, fleet observability, and CRA reporting evidence arriving as vendor services attached to the component. Before your next design review, establish which of those duties your team intended to build in-house, what the supplier would charge to carry them instead, and what your exit looks like if you take the service and later change parts. Buying the compliance layer from the chip vendor is a defensible choice; making it by default, without pricing the dependency, is not.








