Skip to content

CyberSecurity Institute

Security News Curated from across the world

Menu
Menu

IT/OT Security Weekly — August 23, 2026

Posted on August 23, 2026 by admini

August 23, 2026 · Weekly Edition

IT/OT Security

CISA, NSA, the FBI, the Department of Energy and the EPA issued a joint advisory this week on active targeting of internet-exposed Siemens S7 PLCs using AI-generated exploitation scripts dressed up as legitimate OT monitoring software — the summer’s water-sector campaign, generalised into a toolkit that anybody can now run. Around it, TrendAI counted 6,300 industrial and building-automation devices reachable from the internet within a kilometre of US data centres, and Clop’s PTC Windchill campaign began surfacing manufacturing and aerospace victims. Washington had a busy week too: the Quantum-GUARD Act for the grid, the Water Cyber Shield Act for utilities, a new National Security Science & Technology Strategy, and a CISA comment window on its own assessment programme. Underneath all of it sits the slow work — the NSA and ISASecure building a certification scheme for high-criticality OT components, NIST writing guidance for building-automation operators with no security staff, and CyberSheath finding that defence contractors’ self-reported scores are rising while their confidence in those scores falls off a cliff.

This week at a glance

The lead story is unambiguous. On August 19 the NSA, CISA, the FBI, the Department of Energy and the Environmental Protection Agency published joint cybersecurity advisory AA26-231A, warning that threat actors are actively targeting Siemens S7 Series programmable logic controllers — S7-200, S7-300, S7-400, S7-1200 and S7-1500, across most CPU variants and including safety controllers — using exploitation scripts generated with AI. The tradecraft is not exotic and that is precisely the point. The actors use commercial internet scanning services, Censys and ZoomEye, to find exposed controllers; they go after devices running outdated firmware, weak or default authentication, and known unpatched vulnerabilities; and the payload is a set of Python scripts built on the open-source snap7 and python-snap7 libraries that speak S7comm natively. Those scripts give read and write access to PLC memory, configuration data and ladder logic programs. Crucially, the tooling is packaged and named to look like legitimate operational-technology monitoring software — so a plant engineer glancing at a process list, or a network sensor matching on protocol behaviour alone, sees something that resembles the historian poller or the vendor diagnostic agent that is supposed to be there. The advisory’s own framing is the sentence worth quoting to your leadership: using AI to generate exploitation scripts “represents an evolution in threat actor capabilities, dramatically reducing the technical expertise and time required to develop working ICS exploitation scripts.”

Read that against the last two months and the shape of it changes. Through July, more than thirty Minnesota water utilities were disrupted by actors who reached PLCs directly, changed device passwords and altered IP addresses to knock controllers off the network; the campaign then widened through Michigan, South Dakota, Georgia, New Jersey and Alabama, with a pressure drop and boil-water advisory in Clayton County the worst physical consequence so far, and CyberAv3ngers the leading suspicion behind it. That campaign was a demonstration that exposed controllers can be found and touched at scale. AA26-231A is the sequel: the same exposure surface, now approached with a reusable, AI-assembled toolkit and a far wider sector list — energy, critical manufacturing, water and wastewater, chemical, food and agriculture, and commercial facilities, with the defence industrial base flagged as at risk. The agencies are careful to say the targeting is broader than Siemens and that the observed activity looks like persistent reconnaissance intended to pre-position rather than a run of high-impact attacks; WaterISAC put the same assessment to its members on August 20 and told them to push the advisory out to their integrators and remote-support vendors, because the third-party maintenance connection is exactly where an exposed S7 rack usually comes from. For an operator, the practical translation is short: enumerate every S7 CPU you own including the ones behind an integrator’s cellular modem, confirm which of them answer on TCP/102 from outside your boundary, and treat “we do not know” as a finding rather than a gap in the spreadsheet.

The patching advice in advisories like this one always collides with the maintenance window, and it is worth being honest about that. You are not going to reflash the firmware on a running S7-400 rack because an advisory landed on a Wednesday, and nobody serious expects you to. What you can do inside a normal week is entirely exposure work and none of it requires taking process down: kill the internet path, put the mode switch back to RUN and physically key it, remove or password-protect the web server and the PUT/GET communication setting on controllers that have them, rotate the credentials on the jump host and the cellular router in front of the rack, and get a packet capture that tells you who is actually talking S7comm to your controllers today. Save the firmware upgrades for the outage you have already scheduled, and write the exposure fixes into the change record as compensating controls so the auditor can see the sequencing. TrendAI’s research this week is the reminder that the exposed estate is bigger than the plant floor: 6,300 verified ICS and building-automation devices on 3,991 IP addresses within a kilometre of 1,063 US data centres, 81% of them BACnet controllers and Niagara framework instances managing cooling, UPS and power distribution — and facilities permitted from 2021 onward exposed at 13.1% against 4.9% for pre-2010 sites. Newer is worse, because remote manageability was the deployment priority. Meanwhile Clop’s exploitation of CVE-2026-12569 in PTC Windchill and FlexPLM is the enterprise-side version of the same lesson: nobody touched a controller, and the manufacturing, aerospace and automotive victims still lost their product-lifecycle data.

Policy moved on several fronts at once, and the through-line is fragmentation. Senators Coons and Rounds introduced the Quantum-GUARD Act, directing FERC to fold quantum risk into its grid reliability authority and DOE CESER to stand up a testbed for the practical problems of migrating deployed grid OT to post-quantum cryptography. Schiff and Klobuchar’s Water Cyber Shield Act arrived with $300 million a year and real EPA assessment and enforcement authority. The White House published its National Security Science & Technology Strategy, the first such document since 1995, with technological resilience and adversary-free supply chains among its four pillars. CISA opened a comment window, closing September 10, on extending the information collection behind its voluntary critical-infrastructure vulnerability assessments. And Fitch Ratings told water and healthcare providers what the credit market actually rewards: not prevention, but demonstrated resilience — incident response, operational continuity and enough margin to absorb the event. Against that pile of new mandates, the foundational set makes the counter-argument: the OT Cyber Coalition wants ISA/IEC 62443 recognised as the global OT standard and duplicative regimes retired; GAO found 117 cybersecurity regulations across 37 agencies with roughly 70% carrying overlapping reporting requirements; and the Coast Guard has clarified that an existing MTSA waiver buys you nothing under the maritime cyber rule — you still need the cybersecurity assessment before you can even ask. Add ISASecure and the NSA building the HCSA certification scheme for high-criticality OT components, NIST’s new tips-and-tactics for resource-constrained building-automation operators, the draft SP 1353 on using AI for CSF 2.0 analysis, SANS joining the OTCC on workforce, and CyberSheath’s finding that average defence-contractor SPRS scores hit a five-year high of +51 while confidence in their accuracy fell 24 points to 65% — and the week reads as an industry that knows exactly what it should be doing and cannot agree on who should make it do it.

Topic map of this week's IT/OT Security themes

This week’s topic map — joint advisory AA26-231A at the centre, linking the five authoring agencies to Siemens S7 controllers, AI-generated exploitation scripts, the snap7 libraries, tooling disguised as OT monitoring software, default credentials and the water, manufacturing and grid sectors it names; a second exposure cluster around TrendAI’s data-centre findings and Clop’s PTC Windchill campaign with CVE-2026-12569; a legislation cluster carrying the Quantum-GUARD Act, post-quantum cryptography, the Water Cyber Shield Act and the NSSTS strategy; a standards-and-certification cluster around ISA/IEC 62443, ISASecure’s HCSA scheme, NIST and CSF 2.0, and the MTSA cyber rule; and the defence-industrial-base thread through CMMC Level 2 — all tied together by the shared concepts of internet-exposed PLCs, OT asset inventory, network segmentation, sector regulation and the OT workforce gap.

View interactive topic map →

Article index

Weekly News

The Siemens S7 advisory

Five federal agencies warn that AI-generated Python tooling built on the open-source snap7 libraries, packaged to look like legitimate OT monitoring software, is being used against internet-exposed Siemens S7 controllers across six critical-infrastructure sectors.
Article Source Published
1. Defending Against an Active Threat to Siemens S7 Series PLCs (AA26-231A) CISA / NSA / FBI / DOE / EPA Aug 19, 2026
2. CISA, NSA, FBI warn of Siemens S7 PLC exploitation using AI-generated scripts Industrial Cyber Aug 20, 2026
3. US warns of AI-powered attacks on Siemens PLCs in critical infrastructure BleepingComputer Aug 19, 2026
4. Hackers Using AI to Target Siemens PLCs in Critical US Sectors SecurityWeek Aug 20, 2026
5. (TLP:CLEAR) Joint Cybersecurity Advisory — Active Targeting of Siemens S7 PLCs WaterISAC Aug 20, 2026

Exposure and active campaigns

Where the reachable estate actually is: thousands of building-automation and power controllers sitting a kilometre from hyperscale data centres, Clop working through a PTC Windchill zero-day into manufacturing and aerospace, and a ransomware market that keeps fragmenting.
Article Source Published
6. TrendAI finds newer US data centers more exposed to OT risks, with 6,300 ICS and BAS devices online Industrial Cyber Aug 18, 2026
7. The long tail of Clop’s PTC hack is just beginning to emerge CyberScoop Aug 19, 2026
8. Check Point ransomware report signals rising AI use, faster exploit weaponization Industrial Cyber Aug 17, 2026

Legislation and sector policy

A busy week in Washington: quantum risk written into grid reliability authority, $300M a year and real enforcement powers proposed for the water sector, a new national science and technology strategy, a CISA comment window, and a ratings agency explaining what the credit market actually pays for.
Article Source Published
9. Senators introduce bipartisan Quantum-GUARD Act to boost US electric grid against quantum cyber threats Industrial Cyber Aug 19, 2026
10. Schiff, Klobuchar introduce Water Cyber Shield Act to boost water-utility cybersecurity Industrial Cyber Aug 17, 2026
11. NSSTS strategy targets cybersecurity, OT/ICS resilience and technology supply chains Industrial Cyber Aug 19, 2026
12. CISA seeks public comment on extending voluntary vulnerability assessments for critical infrastructure Industrial Cyber Aug 18, 2026
13. Fitch explains how water, healthcare organizations can keep strong credit ratings despite cyberattacks Cybersecurity Dive Aug 20, 2026

Standards and certification

The slower, more durable work: the NSA and ISASecure building a certification scheme for high-criticality OT components, and NIST writing for the two audiences it usually misses — building-automation operators with no security staff, and practitioners trying to use AI against a framework without hallucinating their own control set.
Article Source Published
14. ISASecure and NSA develop HCSA certification scheme for high-criticality OT components Industrial Cyber Aug 21, 2026
15. NIST offers resource-constrained BACS operators practical steps to address OT cybersecurity risks Industrial Cyber Aug 20, 2026
16. NIST SP 1353 details AI prompts and use cases for Cybersecurity Framework 2.0 Industrial Cyber Aug 21, 2026

OT programme practice and workforce

Capability, not policy: SANS joins the OT Cyber Coalition to push on workforce readiness, practitioners take stock of where AI has actually earned a place in OT security, and a formal-methods tool produces mathematical evidence for a satellite network’s resilience claims.
Article Source Published
17. SANS Institute joins OTCC to strengthen critical infrastructure cybersecurity workforce development Industrial Cyber Aug 21, 2026
18. From Hype to Operational Reality: What We Learned at AI in OT Cyber Industrial Cyber Aug 18, 2026
19. AI-Assisted Tool Helped Secure Satellite Communication System After 2022 Russian Hacking SecurityWeek Aug 20, 2026

The defence industrial base and CMMC

Self-reported scores are at a five-year high and contractors’ belief in them has collapsed — while certification arrives one supplier at a time. AA26-231A names the defence industrial base as at risk, which makes this thread an OT story rather than a paperwork one.
Article Source Published
20. CyberSheath report finds growing credibility gap in CMMC compliance as contractor confidence falls Industrial Cyber Aug 21, 2026
21. Lastwall earns CMMC Level 2 certification to strengthen protection of CUI and FCI Industrial Cyber Aug 21, 2026

Foundational Reading

Harmonising OT regulation

The counter-argument to a week of new mandates: one coalition wants ISA/IEC 62443 recognised as the single global OT standard, GAO has counted the duplication, and the Coast Guard has confirmed that an old waiver does not travel forward into a new rule.
Article Source Published
22. OTCC paper urges federal adoption of ISA/IEC 62443 to unify OT cybersecurity Industrial Cyber Jul 27, 2026
23. OTCC urges CISA to issue binding OT cybersecurity directive after water-utility attacks Industrial Cyber Aug 3, 2026
24. GAO warns duplicative federal cybersecurity regulations increasing compliance burdens Industrial Cyber Jul 28, 2026
25. US Coast Guard: Existing MTSA waivers do not exempt maritime operators from cybersecurity rules Industrial Cyber Jul 24, 2026

Recent field lessons worth re-reading

Two case studies that make this week’s advisory concrete: a novel cellular pivot that put Siemens PLCs into STOP mode at a Polish energy facility, and a refrigeration controller whose daily admin password is derivable from a publicly readable MAC address.
Article Source Published
26. Novel Private APN Pivot Let Hackers Sabotage Second Polish Energy Facility SecurityWeek Aug 10, 2026
27. Claroty Team82 exposes Copeland XWEB Pro vulnerabilities that could disrupt commercial refrigeration Industrial Cyber Aug 12, 2026

Detailed write-ups

1. AA26-231A: AI-generated exploitation scripts against Siemens S7 PLCs, dressed as monitoring software

CISA / NSA / FBI / DOE / EPA · Industrial Cyber · BleepingComputer · SecurityWeek · WaterISAC · August 19–20, 2026

The joint advisory published on August 19 by the NSA, CISA, the FBI, the Department of Energy and the Environmental Protection Agency describes an active campaign against Siemens S7 Series programmable logic controllers, and the specificity is what makes it useful. The scope is the whole family — S7-200, S7-300 and S7-400 across CPU variants, and S7-1200 and S7-1500 including safety controllers. The discovery method is commercial internet scanning: the actors query Censys and ZoomEye for exposed devices rather than sweeping address space themselves, which means your controller does not need to be interesting to be found, only reachable. The initial access conditions are the ones that have been on every OT checklist for a decade — outdated firmware, known unpatched vulnerabilities, and weak or default authentication. What is new is the tooling. The exploitation scripts are Python, generated with AI assistance, and built on snap7.dll and the python-snap7 wrapper — a mature open-source library that speaks S7comm properly, so the traffic on the wire looks like a well-formed engineering client rather than a fuzzer. That combination gives read and write access to PLC memory, configuration data and ladder logic programs. Which is to say: the ability to read your process, change your setpoints, and rewrite the logic that keeps the plant inside its safe envelope.

Two details deserve more attention than they will get. The first is the disguise. The advisory notes the tools are presented as legitimate OT monitoring software — which is a detection problem, not just a cheek. Most industrial environments have accumulated a layer of read-only pollers, vendor diagnostic agents and third-party historian connectors that nobody can fully enumerate, and a new process or a new S7comm client that names itself plausibly is exactly the kind of thing that survives a casual review. If your detection strategy for OT is “we would notice unusual protocol traffic,” this campaign is built to defeat it; if it is “we maintain an allow-list of which IP addresses may open an S7comm session to which CPU,” you are in far better shape. The second is the sector list: critical manufacturing, energy, water and wastewater, chemical, food and agriculture, and commercial facilities, with the defence industrial base named as at risk. The agencies also say plainly that the wider PLC-targeting activity is broader than Siemens — so if you run Rockwell, Schneider, Mitsubishi or Omron, the correct reading is not that you dodged it. Both SecurityWeek and BleepingComputer land on the same assessment as the agencies: this looks like persistent reconnaissance and pre-positioning, with no confirmed high-impact effects yet. Pre-positioning is not reassurance. It is the phase before the one you cannot respond to.

WaterISAC’s August 20 note to members adds the piece that most utilities will find hardest. It asks members not just to implement the defence-in-depth hardening themselves but to forward the advisory to any third-party service provider with remote access and ask them to confirm mitigation — because for a small water system, the exposed S7 rack is almost never something the utility put on the internet. It is the integrator’s cellular modem, installed for legitimate remote monitoring, that nobody has re-reviewed since commissioning. Practically, this week’s work is inventory and exposure rather than firmware. Build the list of every S7 CPU you own, including the ones on packaged skids and inside vendor-maintained systems; determine which respond on TCP/102 from outside your network boundary, and get them behind a gateway that enforces VPN plus MFA or off the path entirely; set the physical mode switch to RUN and key it; disable PUT/GET communication and the integrated web server where the application does not require them; rotate credentials on every remote-access appliance and cellular router in front of a controller; and put an allow-list of engineering-client addresses into your monitoring so that a well-behaved S7comm session from an unexpected source raises an alarm. Firmware upgrades go into the next scheduled outage, documented as such. The exposure work does not need one.

Sources: CISA / NSA / FBI / DOE / EPA · Industrial Cyber · BleepingComputer · SecurityWeek · WaterISAC

2. 6,300 exposed controllers next door to the data centres: TrendAI on the OT nobody owns

Industrial Cyber · August 18, 2026

TrendAI Research took a passive Shodan dataset, filtered 73,847 raw records down past honeypots and non-OT services, and counted 6,300 verified industrial and building-automation devices across 3,991 unique IP addresses within a one-kilometre radius of 1,063 US data centres. The composition is the interesting part: 3,664 BACnet controllers (58%) and 1,453 Fox/Niagara framework instances (23%), together 81% of the exposed environment, plus 143 multi-protocol gateways — 125 of them exposing Niagara and BACnet simultaneously — and a visible population of Vertiv/Liebert precision cooling, UPS and power-distribution equipment. Silicon Valley hyperscale campuses showed clusters of 171 or more exposed devices. The researchers are careful that a one-kilometre radius is a metropolitan exposure indicator, not proof that a given device belongs to a given facility, and that caveat is worth honouring. It does not change the finding, which is that the mechanical and electrical plant around modern compute is reachable from the internet in quantity.

The counter-intuitive result is the age curve. Facilities permitted from 2021 onward showed a 13.1% nearby-exposure rate against 4.9% for pre-2010 sites. Newer buildings are worse, and the reason is not neglect but priority: AI-era thermal loads have made cooling more complex and more actively managed, and the deployment pressure has been on rapid commissioning and remote manageability rather than on network hardening. A chiller plant that a vendor can dial into from anywhere is a chiller plant that anyone can find. For a plant or facilities engineer, the consequence is specific and physical rather than informational. An adversary reaching a BACnet controller or a Niagara station can shift temperature setpoints, suppress or falsify monitoring, lock operators out of the interface, manipulate power distribution, or trip a protective shutdown — and in a data centre, a protective shutdown is the outage. This is availability risk delivered through the building, not through the network the security team watches.

The remediation list is unglamorous and overlaps almost exactly with AA26-231A: discover every BAS, EPMS and cooling interface with internet reachability, eliminate the direct exposure, segment OT from IT through controlled conduits with defined protocols, enforce MFA on remote access, replace default credentials, and monitor for abnormal control traffic rather than trusting the graphical display. The line from the write-up that belongs on a slide: the firewall protecting the compute environment is insufficient if the chiller, generator or UPS controller remains reachable from the public internet. If your organisation draws its OT boundary around the process and leaves building services to facilities management, this research is the argument for redrawing it — and the practical starting point is asking who holds the credentials for the building management system, because it is very often a contractor and very often a shared account.

Sources: Industrial Cyber

3. Legislation week: quantum risk for the grid, $300M for water, and a new national S&T strategy

Industrial Cyber · August 17–19, 2026

Senators Chris Coons and Mike Rounds introduced the Quantum Grid Utility Assurance and Resilient Defense Act — Quantum-GUARD — on August 14. It directs FERC to evaluate quantum-related cybersecurity vulnerabilities within its existing grid reliability authority, and tasks DOE’s Office of Cybersecurity, Energy Security and Emergency Response with standing up a collaborative testing environment for the practical problems of post-quantum cryptography adoption, plus studies on quantum threats to the bulk electric system covering both IT and OT. That OT clause is the one that matters to anyone who owns substation equipment. NIST finalised its PQC standards in 2024; the hard part was never the algorithms but the installed base, and grid OT is the worst case — relays, RTUs and teleprotection gear with twenty-year service lives, cryptographic implementations baked into firmware, and no appetite for a field upgrade campaign without a very good reason. As QED-C’s Celia Merzbacher put it, securing monitoring and control communications with PQC is “widely recognized as one of the most feasible and highest-impact actions to secure grid operations.” A testbed is exactly the right first ask: nobody is going to migrate a protection scheme on the strength of a standards document.

The Water Cyber Shield Act, introduced by Senators Adam Schiff and Amy Klobuchar, carries the money and the teeth: $300 million a year through the Drinking Water and Clean Water State Revolving Funds, and explicit EPA authority to assess water systems, enforce corrective measures, set standards jointly with CISA and NIST, mandate risk assessments for large systems and extend incident reporting to state and locally owned facilities, with protection for sensitive utility data from public disclosure. Read alongside AA26-231A and WaterISAC’s advisory to members, the bill is a direct response to a sector that has been told what to do repeatedly and cannot fund it. Whether it survives committee with the enforcement authority intact is the thing to watch; the appropriation is easier to pass and less consequential than the assessment power.

Framing both is the White House’s National Security Science & Technology Strategy, released August 18 — the first such document since 1995, and a companion to the 2025 National Security Strategy. Its four pillars are focusing techno-strategic competition, building technological resilience, accelerating the pace of innovation, and protecting national security science and technology. For industrial operators the second and fourth are the load-bearing ones: keeping adversaries out of critical technology systems and supply chains, with an explicit line that resilience “cannot mean halting technological progress.” That is a strategy document, not a rule, and it will not change a single configuration. But it is the language federal programme offices will use for the next several years when they justify OT security funding, and if you are writing a grant application or a DOE proposal this autumn, its four pillars are the frame to write into. The week’s smaller item belongs here too: CISA has opened a comment window closing September 10 on extending the information collection behind its voluntary critical-infrastructure vulnerability assessments — 1,100 respondents a year, with three legacy questionnaires retired. If you have ever taken one of those assessments and found the questions poorly matched to an OT environment, this is the moment to say so.

Sources: Industrial Cyber (Quantum-GUARD) · Industrial Cyber (Water Cyber Shield Act) · Industrial Cyber (NSSTS) · Industrial Cyber (CISA assessments)

4. ISASecure and the NSA build a certification scheme for high-criticality OT components

Industrial Cyber · August 20–21, 2026

ISASecure is developing a new certification scheme, High Criticality Component Security Assurance (HCSA), in partnership with the National Security Agency. It derives from ISASecure’s existing Component Security Assurance certification and builds on ISA/IEC 62443-4-2 — the part of the standard that defines technical security requirements and security levels for individual OT components rather than for systems or processes. The NSA’s Operational Technology Assurance Partnership contributed six new technical security requirements to the scheme, and the agency intends to use HCSA as an approved mechanism for evaluating OT components for inclusion on the National Security Systems OT Product Compliant List. That is a procurement lever, and a significant one: a scheme that starts as a gate for components going into national security systems tends to become the specification everyone else’s procurement team copies, because it is the only externally validated answer to “is this controller any good.”

The practical value for an asset owner is that component certification is the one part of the 62443 family you can consume without running a programme. You do not have to be certified yourself to write “ISASecure CSA certified, or HCSA where applicable” into a purchase specification, and it shifts a category of work — secure development lifecycle, hardening defaults, credential handling, patchability — onto the vendor where it belongs. The two field lessons in this issue’s foundational set are the argument for it: a WAGO PFC200 shipping with default web-admin credentials, and a Copeland XWEB Pro deriving its daily administrator password from a publicly readable MAC address. Neither is an operator failure. Both are product failures that a component certification regime exists to catch before the device reaches a plant.

NIST covered the other end of the market the same week, publishing tips and tactics for building automation and control system operators who are explicitly resource-constrained — the school district, the hospital estate, the mid-size manufacturer whose BACS is maintained by one facilities engineer and a service contract. Given TrendAI’s exposure findings, that audience is precisely the one carrying the risk. And NIST’s draft SP 1353, out for comment until October 15, is a quick-start guide for using AI in CSF 2.0 work across three use cases: governance review, building a current-state profile from existing artefacts and interview notes, and drafting a target-state profile. It ships sample prompts, fictional source documents and cautions. For an OT team of two people asked to produce a framework profile for a board, that is a genuinely useful artefact — provided the output is treated as a first draft to be checked against the plant, not as an assessment. AI-generated exploitation scripts and AI-generated compliance profiles arrived in the same week; only one of them has a human in the loop by design.

Sources: Industrial Cyber (HCSA) · Industrial Cyber (NIST BACS) · Industrial Cyber (NIST SP 1353)

5. Clop’s PTC Windchill campaign reaches manufacturing, aerospace and automotive

CyberScoop · August 19, 2026

Clop exploited CVE-2026-12569, a critical unauthenticated remote code execution flaw in PTC’s Windchill and FlexPLM product lifecycle management platforms, as a zero-day in early June — before PTC disclosed it on June 17 and patched it the following day, and before CISA added it to the Known Exploited Vulnerabilities catalogue on June 25. Extortion emails began going out in mid-July, and the victim list is only now surfacing: Toast, Zebra, and reportedly GE, Philips and Shell, none of whom commented. The industries hit hardest are manufacturing, aerospace and automotive — organisations that run PTC for supply-chain automation and product lifecycle management, which is to say for the CAD models, bills of material, supplier data and engineering change records that describe how a product is built.

ReliaQuest’s analysis of the tooling is what elevates this above a routine mass-exploitation story. Clop deployed a custom web shell that researchers describe as a fully equipped extortion platform, purpose-built for Windchill: credential decryption, malware delivery, persistent access, lateral movement and data encryption, with the components mimicking standard Windchill functionality so that its activity blended into normal application behaviour. That is targeted engineering against one enterprise product, from a crew usually characterised as an opportunistic mass exploiter. The analyst framing quoted in the piece is worth keeping: Clop “remains a sleeping dragon, always looking and preparing to mass exploit vulnerabilities in software that holds sensitive data.”

For OT teams the relevance is the boundary question, and it is the same one Dragos’s ransomware data keeps posing. PLM is not a control system, and nothing here touched a PLC. But PLM is where the engineering intent lives, and it sits adjacent to the MES and the engineering workstations that do talk to the plant floor — frequently with service accounts, file shares and integration middleware crossing the boundary in both directions. Two questions to take from this: does your PLM environment have any authenticated path into the process network, and is your intellectual-property loss scenario exercised as seriously as your outage scenario? For a defence supplier the answer to the second question also determines whether this becomes a CUI incident, which links this story straight to the CMMC thread below.

Sources: CyberScoop

6. CMMC’s credibility gap: scores at a five-year high, confidence down 24 points

Industrial Cyber · August 21, 2026

CyberSheath’s 2026 State of the Defense Industrial Base report, drawn from a May survey of 302 defence contractors, produced a result that only looks contradictory at first glance. The average self-reported Supplier Performance Risk System score reached a five-year high of +51, up from +33 in 2025 against a maximum of 110. Over the same period, the share of contractors who described themselves as extremely or very confident in the accuracy of that score fell to 65%, from 89% a year earlier and 94% in 2024 — a 24-point drop. Scores are going up; belief in the scores is going down. Only 1% consider themselves completely prepared for CMMC certification, unchanged year over year. Average annual DFARS compliance budgets have risen to $155,000. Control adoption remains thin: multi-factor authentication at 63%, secure backup at 48%, data-leakage protection and vulnerability management at 44% each, endpoint detection at 40%.

The most plausible reading is that the assessment has got more honest rather than the posture worse. As contractors have worked toward third-party certification, they have learned what the assessors actually look for, and the gap between a self-attested score and a defensible one has become visible to them. That is uncomfortable but healthy, and it is also a warning: a self-score that was never audited is a liability under the False Claims Act, and the difference between +51 and a provable +51 is evidence. The demand signal in the survey is striking — 90% want government-mandated minimum cybersecurity standards across all federal contractors, 77% believe DFARS compliance meaningfully improves national security, and 74% simply want it made easier to implement. This is not a sector resisting regulation. It is a sector asking for one clear regime instead of several partial ones, which is the same argument the OTCC makes about 62443 and the same problem GAO measured across 117 regulations and 37 agencies.

The counterpoint arriving the same week is Lastwall earning CMMC Level 2 certification — 110 controls aligned to NIST SP 800-171, verified by an accredited third-party assessment organisation, covering the handling of Controlled Unclassified Information and Federal Contract Information. Lastwall works in identity security and quantum-resilient authentication and has supported US defence environments since 2017 with FedRAMP Moderate authorisation. Certification is achievable; it is just achieved one supplier at a time. For manufacturers in the defence supply chain, the OT dimension is easy to miss and important: AA26-231A explicitly names the defence industrial base as at risk, CUI increasingly lives in engineering and production systems rather than only in the front office, and a shop-floor network with an internet-reachable controller on it is inside the assessment boundary whether or not anyone drew it that way. Scope your CMMC enclave before an assessor scopes it for you.

Sources: Industrial Cyber (CyberSheath) · Industrial Cyber (Lastwall)

Calls to action

  • Inventory every Siemens S7 CPU you own, including the ones you do not maintain. S7-200, S7-300, S7-400, S7-1200, S7-1500 and the safety variants. Walk the packaged skids, the vendor-maintained systems and the integrator cellular modems — that is where the exposed rack usually is, not on your own address space.
  • Establish which controllers answer on TCP/102 from outside your boundary, today. Scan your own ranges and your carrier-assigned ranges, and check Censys and ZoomEye for your own assets the way the adversary does. Anything reachable goes behind a gateway enforcing VPN plus MFA, or off the path entirely.
  • Do the exposure work now and the firmware at the next outage. Mode switch to RUN and keyed, PUT/GET communication disabled, integrated web server off unless the application needs it, credentials rotated on every remote-access appliance and router in front of a controller. Record these as compensating controls against the advisory and schedule the firmware upgrade explicitly — do not let the maintenance window become the reason nothing happens.
  • Allow-list your engineering clients rather than trusting protocol behaviour. AA26-231A’s tooling is built on snap7 and speaks well-formed S7comm while presenting itself as OT monitoring software. Define which source addresses may open an S7comm session to which CPU, and alarm on everything else.
  • Pull building services inside your OT boundary. BACnet controllers and Niagara stations managing cooling, UPS and power distribution are 81% of TrendAI’s exposed data-centre population. Find out who holds the BMS credentials — it is usually a contractor, usually a shared account — and get those interfaces off the internet.
  • Check whether your PLM environment has an authenticated path to the process network. Clop reached manufacturing, aerospace and automotive victims through PTC Windchill and FlexPLM without touching a controller. Patch CVE-2026-12569 if you have not, and audit the service accounts and integration middleware crossing between PLM, MES and the plant.
  • Forward the advisory to your integrators and remote-support vendors and require a written response. WaterISAC’s specific ask, and the right one for any sector: the remote-access relationship is the exposure, and the contract is the only lever you have over it.
  • Write component certification into your next purchase specification. ISASecure CSA today and HCSA as it lands. Default credentials on a WAGO PFC200 and MAC-derived passwords on a Copeland XWEB Pro are vendor defects that procurement language can filter out before they reach a plant.
  • Scope your CMMC enclave before an assessor does. If you supply the defence industrial base, CUI now lives in engineering and production systems, and AA26-231A names the DIB explicitly. A self-score you cannot evidence is a False Claims Act exposure, not a compliance state.
  • Comment on the CISA assessment collection before September 10. If the questions in a voluntary vulnerability assessment have never fitted your OT environment, this is the window in which saying so costs you nothing.

On our watch list

  • Whether AA26-231A moves from reconnaissance to effects. The agencies assess this as pre-positioning with no confirmed high-impact attacks. Watching for the first incident where an AI-generated S7 script is tied to an actual process disruption, and for indicators or a named actor being added to the advisory.
  • Attribution. No actor is named. Watching whether the S7 activity is formally connected to CyberAv3ngers and the summer water campaign, or turns out to be a separate and broader population of operators using the same commodity toolkit.
  • The non-Siemens follow-on. The advisory says PLC targeting is broader than Siemens. Watching for a companion advisory covering Rockwell, Schneider, Mitsubishi or Omron, and for equivalent AI-assembled toolkits against EtherNet/IP and Modbus.
  • Whether snap7-based tooling shows up in commodity crimeware. The libraries are open source and the scripts are generated, not hand-written. Watching for this capability appearing in ransomware affiliate kits rather than staying with state-aligned reconnaissance.
  • The Water Cyber Shield Act’s enforcement clause. The $300M authorisation is the easy part. Watching whether EPA’s assessment and corrective-action authority survives committee, and whether it is reconciled with the OTCC’s call for a binding CISA directive instead.
  • Quantum-GUARD and the DOE CESER testbed. Watching whether the bill advances, and more usefully whether the testbed produces real migration guidance for relays, RTUs and teleprotection rather than a paper on algorithm selection.
  • HCSA’s publication timeline and its pull-through. Watching when the scheme opens for certification, which vendors go first, and whether non-federal buyers start citing it in specifications the way they cite CSA.
  • Regulatory harmonisation after GAO. 117 regulations, 37 agencies, roughly 70% overlapping reporting. Watching whether ONCD’s implementation plans actually retire anything, and what CIRCIA’s finalisation this autumn adds to the pile.
  • The Clop victim list. Mid-July extortion emails are only now producing named victims. Watching how many turn out to be defence-supply-chain manufacturers, and whether any of the exfiltrated PLM data is classified as CUI.
  • Data-centre building automation as a named critical dependency. Watching whether TrendAI’s exposure data prompts a CISA advisory on BACnet and Niagara, and whether hyperscale operators start publishing OT segmentation commitments alongside their uptime figures.

IT/OT Security

A weekly intelligence bulletin from Security Radar LLC.
Curated by Paul Davis · paul.davis@security-radar.com

© 2026 Security Radar LLC. All rights reserved.

Article titles and summaries are excerpted for review and commentary; all linked articles remain the copyright of their respective publishers and authors.

*|LIST:ADDRESS|*

View this email in your browser · Unsubscribe

Recent Posts

  • AI & Machine Learning Security — August 23, 2026 — Interactive Topic Map
  • Agentic NetOps — August 23, 2026
  • Agentic NetOps — August 23, 2026 — Interactive Topic Map
  • Security Operations Weekly — August 23, 2026
  • Security Operations Weekly — August 23, 2026 — Interactive Topic Map

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • November 2025
  • April 2024
  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • April 2023
  • March 2023
  • February 2022
  • January 2022
  • December 2021
  • September 2020
  • October 2019
  • August 2019
  • July 2019
  • December 2018
  • April 2018
  • December 2016
  • September 2016
  • August 2016
  • July 2016
  • April 2015
  • March 2015
  • August 2014
  • March 2014
  • August 2013
  • July 2013
  • June 2013
  • May 2013
  • April 2013
  • March 2013
  • February 2013
  • January 2013
  • October 2012
  • September 2012
  • August 2012
  • February 2012
  • October 2011
  • August 2011
  • June 2011
  • May 2011
  • April 2011
  • February 2011
  • January 2011
  • December 2010
  • November 2010
  • October 2010
  • August 2010
  • July 2010
  • June 2010
  • May 2010
  • April 2010
  • March 2010
  • February 2010
  • January 2010
  • December 2009
  • November 2009
  • October 2009
  • September 2009
  • June 2009
  • May 2009
  • March 2009
  • February 2009
  • January 2009
  • December 2008
  • November 2008
  • October 2008
  • September 2008
  • August 2008
  • July 2008
  • June 2008
  • May 2008
  • April 2008
  • March 2008
  • February 2008
  • January 2008
  • December 2007
  • November 2007
  • October 2007
  • September 2007
  • August 2007
  • July 2007
  • June 2007
  • May 2007
  • April 2007
  • March 2007
  • February 2007
  • January 2007
  • December 2006
  • November 2006
  • October 2006
  • September 2006
  • August 2006
  • July 2006
  • June 2006
  • May 2006
  • April 2006
  • March 2006
  • February 2006
  • January 2006
  • December 2005
  • November 2005
  • October 2005
  • September 2005
  • August 2005
  • July 2005
  • June 2005
  • May 2005
  • April 2005
  • March 2005
  • February 2005
  • January 2005
  • December 2004
  • November 2004
  • October 2004
  • September 2004
  • August 2004
  • July 2004
  • June 2004
  • May 2004
  • April 2004
  • March 2004
  • February 2004
  • January 2004
  • December 2003
  • November 2003
  • October 2003
  • September 2003

Categories

  • AI-ML
  • AI-Ops
  • Augment / Virtual Reality
  • Blogging
  • Cloud
  • Competitive
  • DR/Crisis Response/Crisis Management
  • Editorial
  • Financial
  • IT/OT Security
  • Make You Smile
  • Malware
  • Mobility
  • Motor Industry
  • News
  • OTT Video
  • Pending Review
  • Personal
  • Product
  • Regulations
  • Secure
  • Security Industry News
  • Security Operations
  • Statistics
  • Threat Intel
  • Trends
  • Uncategorized
  • Warnings
  • WebSite News
  • Zero Trust

Meta

  • Log in
  • Entries feed
  • Comments feed
  • WordPress.org
© 2026 CyberSecurity Institute | Powered by Superbs Personal Blog theme