Skip to content

CyberSecurity Institute

Security News Curated from across the world

Menu
Menu

IT/OT Security Weekly — September 6, 2026

Posted on September 6, 2026 by admini

September 6, 2026 · Weekly Edition

IT/OT Security

The week the summer’s water attacks got their post-mortems and Washington answered in two directions at once — a funded six-month pilot in Texas, and six free assessments quietly withdrawn. Forescout put a price on AI-assisted exploit development for a PLC: USD 535.74, eight and a half hours, and a bricked controller. Booz Allen ran eighteen frontier models at a full kill chain. CISA published seven ICS advisories across two releases, three of them Rockwell. CERT Polska’s account of a Polish combined heat and power plant shut down through a wind farm’s cellular router surfaced in two separate write-ups on the same day. And Centrii put a 92% probability on a major attack against UK battery storage by 2031.

This week at a glance

Two stories dominate, and they are the same story seen from opposite ends. At the front end, the post-mortems on the summer’s water attacks landed: a campaign that began on July 27, reached more than a hundred separate incidents across at least seven states, and worked by reaching internet-facing Allen-Bradley MicroLogix controllers over EtherNet/IP on TCP 44818 and simply changing their IP addresses and passwords — locking operators out rather than manipulating any process. Minnesota was the epicentre with more than thirty municipal systems hit on July 26 and 27; recovery meant opening controller cabinets, pulling backup batteries and performing hard factory resets, and the Minnesota Department of Health confirmed no water-quality impact and no boil-water advisories. Randy Rose of the Center for Internet Security gave the week its epitaph: “Sophistication wasn’t necessarily needed.” At the back end, Washington moved twice in the same week and in contradictory directions. Project Watershed 250 launched as a six-month, no-cost pilot in Texas — EPA and CISA with Texas Cyber Command, plus Microsoft, Reflection AI, Palo Alto Networks, Dragos, Forescout and Tenable, running red-team exercises and AI-assisted tooling against real utility networks. Days earlier, regional CISA staff were told the agency was retiring six free assessment offerings, among them Cyber Resilience Reviews and Ransomware Readiness Assessments, at an agency that has lost roughly a third of its workforce. A pilot reaches a few hundred utilities; a retired baseline assessment was available to all of them. Around that spine, the AI question got its first honest measurements. Forescout’s Amine Amri ported a 2021 Nucleus FTP overflow to a different WAGO controller with an LLM in the loop and documented the bill — USD 535.74 and eight hours thirty-two minutes for working remote code execution, then two functional ARM payloads in twelve minutes, then a bricked device on the implant attempt. Booz Allen tested eighteen US and Chinese frontier models and found one completing a full enterprise kill chain autonomously, roughly two-thirds gaining initial access without credentials — and every frontier API model scoring zero against real-world vulnerabilities. Elsewhere: CERT Polska’s reconstruction of the December 2025 shutdown of a Polish CHP plant, entered through an unpatched firewall at a wind farm and a cellular router into the grid operator’s private APN; Centrii’s Monte Carlo modelling of UK battery storage, where compromising about 400 units would black out 67 million people; and a seven-advisory CISA run covering RSLinx Classic, the Logix platform, OPC UA’s discovery server, the IXON VPN client, Ignition and the Pyramid Solutions NetStaX EtherNet/IP stack.

On our watch list

  • Whether the water campaign gets a formal attribution and a usable indicator set. Officials are investigating a possible Iranian connection and CISA advisory AA26-097A covers a broader Iran-affiliated campaign against Rockwell, Schneider Electric and Siemens devices. Watching for a named actor and, more usefully, indicators a small utility could actually hunt with.
  • What Project Watershed 250 produces in six months. Watching whether the red-team findings are published in aggregate, whether the AI component turns out to be scanning and triage or something that touches a live process network, and whether the model is designed to extend beyond Texas.
  • Whether anything replaces the six retired CISA assessments. Watching for a successor offering, a handoff to sector ISACs or state programmes, and any figure at all for how many organisations were using them — nobody has published one.
  • The missing detail on ICSA-26-244-05. Two Rockwell Logix advisories landed the same day with overlapping product families and very different levels of published detail. Watching for the full vulnerability and version data on the wider ControlLogix, CompactLogix, CompactLogix 5480, GuardLogix and Compact GuardLogix advisory.
  • How far the NetStaX stack reaches. Watching for downstream vendor advisories naming products that embed the Pyramid Solutions EtherNet/IP stack. A protocol-stack vulnerability is only as visible as the OEM disclosures that follow it.
  • Whether CERT Polska’s case produces changes at the carrier layer. Watching whether private APN client isolation becomes a default rather than an option, and whether European grid operators publish anything on cellular-connected remote-site architecture in response.
  • Whether anyone starts monitoring inverter damping behaviour. Centrii’s detection thesis rests on a signature no one currently watches for. Watching for a grid operator, optimiser or OEM to publish anything on distinguishing a hostile frequency response from a commercial one.
  • Booz Allen’s six-month prediction against the zero-score finding. Watching whether frontier models close the gap between enterprise test environments and real-world vulnerabilities, and whether any independent party reproduces the kill-chain result outside a vendor with a counter-AI product to sell.
  • NERC CIP-015-2 implementation planning. FERC approved it by letter order on August 10, extending internal network security monitoring to High and Medium Impact BES Cyber Systems with External Routable Connectivity plus EACMS, PACS, SCI and PCAs. Watching how registered entities scope Phase 1 ahead of the CIP-015-1 retirement, and how Order No. 919’s virtualization standards interact with it.
  • What the new Coast Guard office does first. Watching whether CG-MCP produces enforcement direction, guidance, or international standards work — and whether MTSA cyber requirements start generating findings at inspection across the roughly 360 US commercial ports in scope.
  • Post-quantum work reaching OT. The G7 call to action emphasises store-now-decrypt-later interception. Watching for anything that addresses authentication on twenty-year field assets — relays, RTUs, teleprotection — rather than transport encryption on IT systems.
  • Whether the OT security market consolidates around the Forrester placements. Two Leaders announced the same report the same day. Watching whether the Wave changes anything in procurement shortlists, or whether the Cognizant/CrowdStrike-style managed service becomes the delivery model that actually reaches mid-sized operators.

Topic map of this week's IT/OT Security themes

This week’s topic map — the multi-state water PLC campaign at the centre, tying internet-exposed OT, Allen-Bradley MicroLogix controllers and EtherNet/IP to Minnesota, the FBI and CISA, and onward to Project Watershed 250 in Texas; an AI cluster running from Forescout’s Vedere Labs experiment and CVE-2021-31886 on WAGO controllers through Booz Allen’s frontier-model testing to the joint alert on Siemens S7 PLCs; the September 1 and 3 advisory batch around Rockwell Automation, RSLinx Classic, the Logix platform and Ignition; a grid and energy cluster linking Centrii, Rafael Narezzi and battery energy storage to IEC 62443 and NERC CIP-015-2, with Sandworm’s Polish CHP plant intrusion and Teltonika cellular routers alongside; and a sector-and-market thread through Dragos, Claroty, the Forrester Wave, MTSA maritime compliance and manufacturing recovery.

View interactive topic map →

Article index

Advisories and vulnerabilities

One patch-desk block, not seven stories. CISA’s September 1 and September 3 releases carried seven advisories that matter on a plant floor: three Rockwell Automation entries covering RSLinx Classic and two separate Logix denial-of-service cases, plus OPC UA’s discovery server, the IXON VPN client, Inductive Automation’s Ignition gateway and an EtherNet/IP protocol stack that ships inside other vendors’ products.
Article Source Published
1. Rockwell Automation RSLinx Classic (ICSA-26-244-01) CISA Sep 1, 2026
2. Rockwell Automation Logix Platform (ICSA-26-244-03) CISA Sep 1, 2026
3. Rockwell Automation ControlLogix, CompactLogix, GuardLogix, Compact GuardLogix (ICSA-26-244-05) CISA Sep 1, 2026
4. OPC Foundation OPC UA LocalDiscoveryServer (LDS) (ICSA-26-246-01) CISA Sep 3, 2026
5. IXON VPN Client (ICSA-26-246-02) CISA Sep 3, 2026
6. Inductive Automation Ignition (ICSA-26-246-06) CISA Sep 3, 2026
7. Pyramid Solutions NetStaX EtherNet/IP Stack (ICSA-26-246-07) CISA Sep 3, 2026

AI as attacker and defender

The week’s most useful research is also its most deflating: measured end to end, an LLM compresses the payload and adaptation work on a PLC exploit but not the discovery work, and it costs real money and real hours. Read Forescout’s own numbers as the primary account — the SecurityWeek piece is a write-up of the same experiment, published the same day, with the figures rounded.
Article Source Published
8. Can AI Create PLC Attacks? Yes, But It’s Not That Easy Yet Forescout Vedere Labs Sep 1, 2026
9. Experiment: Porting a PLC Exploit With AI Takes Hours and Hundreds of Dollars SecurityWeek Sep 1, 2026
10. Booz Allen: AI models approaching autonomous cyberattack capability as critical infrastructure response windows narrow Industrial Cyber Sep 4, 2026
11. AI-fueled attacks pose ‘active threat’ to water, other sectors, U.S. agencies warn CyberScoop Aug 19, 2026

Water and the state of critical-infrastructure defence

The Minnesota and multi-state water campaign and its post-mortems, the internet-exposure research that explains how those utilities were found, the federal-state-vendor pilot standing up in Texas, and CISA retiring six free assessments in the same week. That last tension — a funded pilot for a few, a withdrawn baseline for everyone — is the editorial spine of the section.
Article Source Published
12. Experts: Water Cyber Attacks Had Scale, Not Sophistication GovTech Aug 31, 2026
13. The Attack Wasn’t Sophisticated. That’s What Should Scare Every Water Utility BlastWave Sep 3, 2026
14. Inside the Minnesota Water Attacks: Exposed PLCs, a Guarded Chip Breach, and Washington’s AI Patching Plan Industrial Cyber Aug 10, 2026
15. Do you show up on Shodan? The risks of internet-exposed OT to local governments IBM X-Force Sep 2, 2026
16. US launches Project Watershed 250 to tackle water system cybersecurity vulnerabilities with AI, red-team exercises Industrial Cyber Sep 1, 2026
17. Forescout Partners with the White House and the State of Texas for Project Watershed 250 Forescout Sep 4, 2026
18. CISA scraps 6 free cybersecurity assessments for critical infrastructure operators Cybersecurity Dive Sep 1, 2026
19. CISA, FBI, partners release guidance to help service providers manage communications during IT, OT outages Industrial Cyber Sep 3, 2026

Grid, energy and physical consequence

Two write-ups of one Polish incident — Netresec’s headline gives no hint that it is an incident analysis — two angles on one battery-storage report, and the two regulatory instruments that will shape monitoring and cryptography on the grid for the next decade.
Article Source Published
20. Rethinking OT Boundaries: Sandworm’s Cellular Breach of a Polish Power Plant Zscaler Aug 31, 2026
21. OT Networks Still Need Monitoring Netresec Aug 31, 2026
22. Centrii’s GRIDLOCK report warns UK battery storage faces 92% probability of major cyberattack by 2031 Industrial Cyber Sep 3, 2026
23. A battery storage cyberattack would look exactly like a badly tuned controller Help Net Security Sep 2, 2026
24. FERC Approves NERC CIP-015-2: What It Means for Your INSM Program Dragos Aug 24, 2026
25. G7 urges governments, organizations to begin PQC transition, protect public key encryption from quantum threats Industrial Cyber Sep 4, 2026

Sector risk, market and practice

Maritime governance and MTSA compliance, medical devices and pharma, food and agriculture, manufacturing threat and recovery, and an OT security market that produced two vendor announcements this week about the same Forrester Wave report.
Article Source Published
26. Coast Guard Establishes Office of Maritime Cybersecurity Policy SecurityWeek Sep 1, 2026
27. The Work that Never Makes the Highlight Reel: MTSA’s Routine Maintenance Requirement Dragos Sep 1, 2026
28. Designing for Disruption: MTSA’s Resilience Requirement Dragos Aug 18, 2026
29. Marlink expands OT security capabilities as connected maritime and industrial systems face growing cyber risks Industrial Cyber Sep 1, 2026
30. Boston Scientific Still Recovering From Cyberattack SecurityWeek Aug 31, 2026
31. Pharmaceutical sector urged to shift cyber resilience focus from systems to medicine value chains Industrial Cyber Sep 2, 2026
32. Food and Ag-ISAC warns AI, ransomware, nation-state threats intensifying cyber risks across food and agriculture Industrial Cyber Sep 3, 2026
33. F6 reports manufacturing emerges as top cyberattack target, as 80% of industrial firms face security staffing shortage Industrial Cyber Sep 4, 2026
34. From IT restoration to production restart: Why manufacturers continue to struggle with operational side of cyber recovery Industrial Cyber Sep 1, 2026
35. How Adversaries See Your Extended Operational Technology (xOT) Environment Dragos Aug 31, 2026
36. The Responsibility of Building What’s Next in xOT Cybersecurity Dragos Sep 1, 2026
37. Claroty Named a Leader and a Customer Favorite in OT Security by Leading Independent Research Firm Claroty Sep 1, 2026
38. Cognizant, CrowdStrike expand collaboration with OT cybersecurity service for converged IT and OT environments Industrial Cyber Sep 4, 2026

Detailed write-ups

1. Scale, not sophistication: the multi-state water PLC campaign gets its post-mortem

GovTech · Industrial Cyber · IBM X-Force · BlastWave · August 10 – September 3, 2026

The campaign against US water and wastewater systems began on July 27, spans at least seven states, and involves more than a hundred individual incidents. The method was not exotic. Attackers reached programmable logic controllers that answered directly from the internet and changed their IP addresses and passwords. That is the whole technique. No process was manipulated, no chemical dosing was touched, no safety interlock was defeated — the operators were simply locked out of their own controllers. Randy Rose, VP of Security Operations and Intelligence at the Center for Internet Security, gave the assessment that should frame every board conversation about this campaign: “Sophistication wasn’t necessarily needed.” The equipment reached was Rockwell Automation Allen-Bradley MicroLogix 1100 and 1400 series controllers, contacted over EtherNet/IP on TCP port 44818. Threat actors have still not been officially named; US officials are investigating a possible Iranian connection, and CISA advisory AA26-097A covers a broader Iran-affiliated campaign against Rockwell, Schneider Electric and Siemens devices. The FBI, EPA and CISA are all engaged.

Two different counts circulate, and they measure two different things. GovTech’s figure — more than a hundred incidents across at least seven states from July 27 — describes the whole campaign. The Minnesota figure, more than thirty municipal water systems struck on July 26 and 27, describes its epicentre, with similar intrusions in at least seven other states. Minnesota is where the operational detail is clearest. Some facilities reverted to manual operation, reading gauges and adjusting valves by hand. Recovery meant physically opening controller cabinets, removing backup batteries and performing hard factory resets — a procedure that requires a technician at each site, which is exactly the constraint a small utility does not have slack for. The Minnesota Department of Health confirmed no impact on water quality and issued no boil-water advisories. In parallel, the White House launched Gold Eagle on July 14, a public-private vulnerability clearinghouse using AI to coordinate scanning and remediation; Dennis Hackney’s column for Industrial Cyber makes the sharpest objection to it, arguing that an AI clearinghouse which accelerates patch delivery solves an IT problem rather than an OT one. Patch velocity is not the constraint when the controller has been reachable from the public internet for six years.

IBM X-Force’s David McMillen supplies the reconnaissance half of the story, and it is the part local government should read directly. Attackers do not need a target list; they need a search engine. As McMillen puts it, “an adversary can first search for a technology, protocol, product or service and identify its owner afterward.” The ports that matter are the ones already in the campaign: 44818 for EtherNet/IP, plus 2222, 102 and 502. X-Force names Rockwell Automation/Allen-Bradley, Schneider Electric, Siemens and Unitronics as the vendor estate visible this way, and sets the current campaign against its own precedents — Iranian-affiliated targeting of internet-connected PLCs across US critical infrastructure in April 2026, the January 2024 Texas water incidents at Muleshoe, Hale Center and Lockney, and the November 2023 CyberAv3ngers campaign against Unitronics devices that compromised more than 75 units. BlastWave’s commentary on the same events, which quotes Shaun Six of UTSI and its own solutions architect Joe Baxter, is vendor material rather than reporting, but it lands on the right conclusion: an attack that required no sophistication is more alarming than one that did, because nothing about the adversary needs to improve for it to happen again.

The practical work is unglamorous and finite. Enumerate every controller, HMI, historian and cellular gateway that holds a routable address, including carrier-assigned ranges behind any modem, and confirm from the outside — not from the asset register — which of them answer. Check ports 44818, 2222, 102 and 502 explicitly. Search the commercial scanning services for your own organisation’s name, netblocks and equipment banners, because that is the query the adversary ran. Where a controller must be reachable for a legitimate remote-support arrangement, put an access gateway with multi-factor authentication in front of it and log every session. And write down the recovery procedure now, while nobody is under pressure: which cabinet, which battery, which reset sequence, whose truck, how long. The utilities that took days to recover were not the ones with the worst security; they were the ones who had never rehearsed a factory reset on a controller they could no longer log into.

Sources: GovTech · Industrial Cyber · IBM X-Force · BlastWave

2. Project Watershed 250: a six-month pilot in Texas, at no cost to the utilities

Industrial Cyber · Forescout · September 1–4, 2026

Project Watershed 250 is a six-month pilot programme in Texas whose purpose is to find and fix cyber vulnerabilities in water systems before they are exploited. The federal participants are the EPA and CISA; the state participant is Texas Cyber Command; the private-sector participants are Microsoft, Reflection AI, Palo Alto Networks, Dragos, Forescout and Tenable. Participating utilities receive federal, state and private-sector cyber defences at no cost to them — which, for a sector where most systems serve fewer than ten thousand people and many have no dedicated security staff at all, is the design decision that determines whether anything happens. The programme has two components: red-team exercises run against utility networks, and AI-powered security tooling and threat intelligence deployed alongside them. National Cyber Director Sean Cairncross, Texas Cyber Command chief Timothy James “TJ” White and Governor Greg Abbott appear on the government side; Chris Barry of Microsoft US Public Sector, Dragos CEO Robert Lee, Tenable’s public-sector CTO Chris Day and Forescout’s VP of Government Affairs Alison King on the industry side. King framed the premise in the sentence the whole programme rests on: “Resource-constrained cannot mean defenseless.”

The programme is explicitly a response to the July 2026 attacks on more than thirty Minnesota water systems, and it inherits that campaign’s lesson about where the failure was. Red-teaming a utility that has an exposed MicroLogix on 44818 will find it in minutes, which is the point — the exercise is not there to discover novel tradecraft but to produce a finding with a state agency’s name attached to it, in a sector where an outside finding is often the only thing that unlocks a budget line. The AI component is the part to watch sceptically. Automated scanning and triage across a few hundred small utilities is a genuinely good fit for the technology; autonomous remediation on a live process network is not, and nothing published so far says which of the two is intended.

Forescout’s own release, three days later, is worth reading with its framing adjusted. Forescout is one of six named private-sector participants, not a bilateral partner of the federal government and the state, and the release itself names no specific White House office and no specific Texas agency — the Industrial Cyber piece is the one that identifies Texas Cyber Command, the EPA and CISA. What the release does usefully supply is the shape of the technical contribution: continuous monitoring, asset visibility, external attack-surface analysis, passive OT assessment, vulnerability prioritisation, segmentation and AI-enabled defence delivered through its Vistaro platform and a universal zero-trust network access architecture, with Barry Mainz as CEO and Mike Walsh leading Forescout Government Systems. The accompanying figures — more than 70 US federal entities served, use by over 85% of US federal executive departments, eight of the top ten Fortune 500 utilities, more than 180 product integrations — are vendor self-reported and should be read as positioning rather than as programme facts. For an operator outside Texas the practical question is narrower and answerable now: passive OT assessment and external attack-surface analysis are exactly the two services that produce a defensible baseline without touching a controller, and both are procurable today from several of the six.

Sources: Industrial Cyber · Forescout

3. CISA retires six free assessments in the same week it helps launch a pilot

Cybersecurity Dive · September 1, 2026

CISA is ending six free assessment offerings for critical-infrastructure operators: Cyber Resilience Reviews, Cyber Resilience Essentials surveys, Ransomware Readiness Assessments, Incident Management Reviews, External Dependencies Management Assessments and Cyber Infrastructure Surveys. Regional staff were told on August 25. The agency’s stated rationale is reducing redundancy and retiring what it describes as legacy questionnaire assessments; sources inside the agency cited workload concerns and disputes between CISA divisions as contributing factors. The context is an agency that has lost roughly a third of its workforce since the start of the second Trump administration, and that is currently operating with acting leadership across the relevant chain — Nick Andersen as acting director, Chris Butera as acting executive assistant director for the Cybersecurity Division, James Harrell as acting assistant director for Integrated Operations.

The criticism is pointed and comes from people who have run this machinery. Jeff Greene, formerly head of CISA’s Cybersecurity Division; Michael Daniel, president of the Cyber Threat Alliance and a former White House cybersecurity coordinator; and Tatyana Bolton, executive director of the OT Cyber Coalition, all pushed back. The objection they share is about timing rather than product design: “This is a deeply dangerous time to be scaling back direct assistance.” It is worth being precise about what is actually lost. These were questionnaire-driven, facilitator-led reviews, not penetration tests, and a large mature operator will not miss them. The organisations that will are the ones with no security programme to review — the small water system, the rural co-op, the county utility for which a free, structured, externally facilitated assessment was the only mechanism that ever produced a written list of gaps. CISA has not said how many organisations used the assessments, and the reporting does not quantify it.

Set this beside Project Watershed 250 and the shape of the policy becomes visible: intensive, funded, vendor-supported help for a few hundred utilities in one state, and the withdrawal of a low-cost baseline that was available to all of them. Those are not substitutes. If your organisation was on a waiting list for any of the six, the practical move is to find out what stage your request is at before the offering closes, and to identify the replacement path — a sector ISAC, a state programme, a regional CISA advisor relationship that survives the cut, or a commercial assessment mapped to the same control set. The output that mattered was never the questionnaire; it was having a document, produced by someone outside the organisation, that a general manager or a rate board would treat as evidence.

Sources: Cybersecurity Dive

4. A wind farm’s cellular router, a private APN, and a Polish CHP plant that stopped

Zscaler · Netresec · August 31, 2026

On December 29, 2025, a Polish combined heat and power plant lost a steam turbine and its process-water treatment system to a cyberattack, temporarily cutting municipal heat supply to around 50,000 residents. CERT Polska investigated and published its account in August 2026, with public disclosure on August 8; two separate write-ups appeared on August 31, and both describe the same incident. Zscaler supplies the chain, Netresec the forensics. The intrusion is attributed to Sandworm, also tracked as the Russian state-sponsored group Electrum, and CERT Polska describes coordinated simultaneous attacks against more than thirty other Polish renewable-energy and power-distribution sites.

The path in is the reason this incident belongs in every OT architecture review this quarter. It started at an internet-facing, unpatched firewall at a remote wind farm — Netresec identifies it as a FortiGate VPN appliance. From there the attackers took SSH access to a Teltonika cellular router, a RUTX50 5G unit, and tunnelled into the grid operator’s private APN. A private APN is widely treated as a trusted network; this one had no client isolation, so a scan of the entire private cellular IP range was possible from a single compromised site. That scan found a WAGO PLC still carrying default administrator credentials. The attackers then issued unauthorised stop commands to Siemens PLCs controlling the steam turbine, over Modbus and S7comm. Netresec adds the timeline that matters most: malicious activity was visible in the traffic as early as December 18, against destructive actions on December 29 — more than eleven days of dwell time in an environment where nobody was watching. The attackers put Siemens S7-1500 controllers into STOP mode, enabled PLC password protection to slow recovery, and altered the configuration of industrial serial device servers and network switches. No CVE is named in either account; nothing here required one.

Netresec’s conclusion is the title of its post, and the evidence supports it plainly. CERT Polska’s own investigators wrote that “due to the lack of logs, our investigation relied on the development and testing of hypotheses” — eleven days of adversary activity reconstructed by inference because the network recorded nothing. The ICS ports Netresec recommends monitoring are specific and short enough to act on this week: TCP 102, 502, 2404, 5094, 20000, 44818 and 47808. It also ties the case to the NSA/CISA/FBI/DOE/EPA joint advisory of August 19 on the active threat to Siemens S7 series PLCs, which makes the Polish case a worked example rather than an isolated event. Three questions follow directly. Does your private APN isolate clients from one another, or does every remote site see every other one? Which cellular routers, firewalls and remote-access appliances at unstaffed remote sites are on a patch cadence, and who owns it — you, or the renewables developer who commissioned the site? And if an adversary spent eleven days on your process network, what record would exist afterwards?

Sources: Zscaler · Netresec

5. Battery storage: a 92% probability, and a hostile swing that looks like a badly tuned controller

Industrial Cyber · Help Net Security · September 2–3, 2026

Centrii’s GRIDLOCK report, presented by CEO and co-founder Rafael Narezzi, models the cyber risk to grid-scale battery energy storage using a Monte Carlo simulation of 10,000 iterations across three security postures. Under the current posture it puts the probability of a major attack on UK battery storage by 2031 at 92%; under mandatory IEC 62443 certification that falls to 61%. The physical scenario behind the headline is what makes the number legible. Compromising 29% of UK national BESS capacity — roughly 400 units — would be enough to trigger a national blackout affecting 67 million people. The Texas comparator is starker in ratio: 5.4% of the ERCOT battery fleet, about 1,500 units, would affect 30 million people. Damage estimates run to £2bn–£10bn for the UK and USD 12bn–65bn for Texas, against prevention spending of £400m–£1bn in Great Britain and USD 800m–2.8bn in ERCOT to reach IEC 62443 Security Level 2 — a return of five to eighty times. The precedents cited are real events, not scenarios: wind-turbine manipulation in Poland in December 2025, and the April 2025 Spain and Portugal outage in which 2.5 GW was lost in twenty seconds.

The companion interview, published a day earlier, is the same research turned toward detection, and it is the more operationally useful half. Narezzi’s framing is that Britain’s system is engineered to withstand a sudden loss of 1,320 MW without breaching statutory frequency limits, that Low Frequency Demand Disconnection triggers at 48.8 Hz, and that the grid can hold around 49.2 Hz for up to sixty seconds. Those numbers define the attack envelope. They also explain his smaller-scale figure, which deserves more attention than the blackout headline: 11 to 21 compromised 2 MW units are enough to destabilise a regional grid, against 400 to 1,500 for a national event. Regional destabilisation is within reach of an adversary who compromises one optimiser’s portfolio.

The detection problem is the genuinely hard part, and Narezzi states it exactly: “A hostile swing and a revenue-driven one look identical on the wire.” A battery that responds aggressively to a frequency excursion may be arbitraging, or it may be attacking; the command traffic looks the same. The distinguishing signature he offers is behavioural rather than protocol-level — inverter output that amplifies oscillations rather than damping them, a “reverse governor” response that no legitimate commercial strategy produces. The forensic obstacle is structural: the evidence needed to tell the two apart sits with the optimisers and OEM cloud platforms that dispatch these assets, not with the grid operators who would have to make the call. Neither piece names specific inverter or BMS manufacturers. For an operator, the actionable items are contractual as much as technical: establish now, in writing, what dispatch and inverter telemetry your optimiser and OEM retain, for how long, and how quickly you can obtain it after an anomaly. Then ask whether anyone in your organisation is monitoring for damping response at all, or only for availability and revenue.

Sources: Industrial Cyber · Help Net Security

6. USD 535.74 and eight hours: what it actually costs to port a PLC exploit with an LLM

Forescout Vedere Labs · SecurityWeek · September 1, 2026

Amine Amri of Forescout Research — Vedere Labs set out to answer a question the industry has been arguing about without data: can an AI model take an existing PLC exploit and port it to a different device, and what does that cost? The vulnerability chosen was CVE-2021-31886, a pre-authentication buffer overflow in the Nucleus RTOS FTP server stack. The source exploit targeted a WAGO 750-852 controller; the target was a WAGO 750-831 running firmware V01.04.16 — same vendor, different hardware, different memory layout. The models were Claude Sonnet 4.6 with a 200k context window and Claude Opus 4.6 with a 1M window, driven through Claude Code with terminal access and Ghidra for disassembly. This is a well-resourced setup operated by someone who already knew what he was doing.

The numbers are the contribution. The final remote-code-execution development stage consumed USD 535.74 in API tokens across a session totalling 8 hours 32 minutes spread over several days, with 2.6k input and 1.3 million output tokens. Once working RCE existed, the character of the work changed sharply: the model produced two functional ARM shellcode payloads in twelve minutes, one an ICMP echo-request payload and the other a UDP beacon transmitting the string “PWNED”. Then the researcher pushed further, attempting to extend the exploit into a command-and-control implant, and bricked the target device. Forescout’s own verdict is the one to quote to anyone claiming a step change: “One could argue that the researcher could have achieved the initial RCE port without AI in less time and at lower cost while also keeping the PLC alive.” SecurityWeek’s write-up of the same experiment, published the same day, rounds these to “over $500” and “more than 8 hours”; the precise figures above are Forescout’s.

The defensive reading is specific, and it is not reassurance. What the model was good at was the mechanical, well-specified, heavily-documented work — generating architecture-correct shellcode for a known payload objective, twelve minutes for two working payloads. What it was bad at, expensive at, and ultimately destructive at was everything requiring judgement about an unfamiliar embedded target: understanding a different memory layout, adapting an exploit primitive, knowing when to stop before the device dies. For OT defenders this maps to a concrete expectation. Assume the payload and adaptation stages get cheaper and faster from here. Do not assume the discovery stage does. That means the exposure and access controls that stop an attacker from reaching a controller in the first place retain their full value, while any defence premised on the difficulty of writing a working payload for your particular architecture is on a shortening clock. The other detail worth carrying into a risk conversation is the bricked controller: an adversary experimenting with AI-assisted exploitation against production equipment is likely to destroy some of it, which is a safety consideration rather than an availability one.

Sources: Forescout Vedere Labs · SecurityWeek

7. Booz Allen tests eighteen frontier models — and finds them scoring zero where it counts

Industrial Cyber · CyberScoop · August 19 – September 4, 2026

Booz Allen Hamilton published “The Offensive Frontier: AI as the Attacker” on September 4, reporting on tests of eighteen US and Chinese frontier models against offensive tasks. The headline finding is that one model, Anthropic’s Claude Mythos, autonomously completed a full cyber kill chain in enterprise testing, gaining administrative access using stolen credentials, and that roughly two-thirds of the eighteen reliably gained initial network access without credentials. Booz Allen expects most of the tested models to reach full autonomous kill-chain capability within six months, and argues that the response windows available to critical-infrastructure defenders in energy, communications, financial services, water and healthcare narrow accordingly. Its framing sentence is the useful one: “The unit of risk is no longer the individual model but the system as a whole.” The report calls for enforceable, sector-specific readiness deadlines for critical infrastructure.

Two qualifications belong next to that headline. The first is a finding inside the report that cuts against it: every frontier API model tested scored zero against actual real-world vulnerabilities. Enterprise test environments are built to be solvable; production OT is not, and the gap between those two results is the entire practical question. The second is commercial. The figure that counter-AI playbooks reduced autonomous attacker success by more than 95% describes Booz Allen’s own playbooks, and the report accompanies Vellox Labs Guile, its counter-AI defence tool. That does not make the measurement wrong; it does mean the number is a vendor’s claim about a vendor’s product, and should be read as one.

The field evidence sits alongside it and is more concrete. On August 19 the NSA, CISA, the FBI, the Energy Department and the EPA issued a joint alert on Siemens S7 series programmable logic controllers, reporting attackers using AI-generated exploitation scripts disguised as legitimate monitoring tools across water, food, energy, chemical, manufacturing and commercial facilities. That is the pattern to plan against, and note what it is: AI used to mass-produce and disguise tooling for known targets, not AI discovering novel flaws in a controller. Michael Garcia of Monument Policy Advocacy, a former CISA official, and Brian Proctor, CEO of Frenos, both commented on the alert. Taken with Forescout’s cost measurement, a consistent picture emerges across three independent sources this week: the volume, speed and disguise of attack tooling are improving quickly; the ability to find genuinely new ways into industrial equipment is not, yet. Plan detection and exposure reduction for the first, and do not let the second become an argument for delay.

Sources: Industrial Cyber · CyberScoop

8. The patch desk: seven ICS advisories across two releases, and one numbering trap

CISA · September 1 and 3, 2026

CISA issued two ICS advisory batches this week, on September 1 and September 3. Seven of them belong on a plant-floor patch desk, and three are Rockwell Automation. ICSA-26-244-01, RSLinx Classic, carries four denial-of-service flaws: CVE-2026-9621, an integer overflow (CWE-190) rated 8.6 on CVSS v3.1 and 9.2 on v4.0; CVE-2026-9622, an integer underflow (CWE-191) at the same scores; CVE-2026-9624, also CWE-191, at 7.5 and 8.7; and CVE-2026-9625, a buffer overflow (CWE-120), at 7.5 and 8.7. Versions 4.50 and earlier are affected, and Rockwell’s advisory gives 4.60 as the corrected release. A single crafted CIP packet crashes the service, and it must then be restarted by hand — which on a site where RSLinx is the data path between the control network and everything above it means the operator loses visibility until someone walks to the machine.

ICSA-26-244-03, the Logix Platform advisory, is the one carrying a CVE, and it is easy to confuse with its same-day neighbour. CVE-2026-9637 is a memory-boundary flaw (CWE-119) rated 7.5 on CVSS v3.1 and 8.7 on v4.0. It affects ControlLogix 5580, CompactLogix 5380, GuardLogix 5580 and Compact GuardLogix 5380 at V33 and earlier, V34.011–V34.014, V35.011–V35.013 and V36.011–V36.012, with fixes in V34.015, V35.014, V36.013 and V37.011. Defective input validation during Common Industrial Protocol message handling lets a crafted network message induce a major non-recoverable fault, which requires a physical power cycle to clear. Separately and on the same day, ICSA-26-244-05 covers a wider Rockwell product list — ControlLogix, CompactLogix including the 5480, GuardLogix and Compact GuardLogix — and describes a crafted-data denial of service across those families. The two advisories are distinct despite the overlapping product names, and CVE-2026-9637 belongs to the Logix Platform advisory, not to this one. If your change record cites a single Rockwell Logix advisory this week, check which.

The September 3 batch spreads wider than Rockwell. ICSA-26-246-01 covers CVE-2026-77477 in OPC Foundation UA LocalDiscoveryServer installers before 1.04.420; it is not remotely exploitable, requires an attacker able to launch an elevated installer and interact with the keyboard, and has no known public exploitation — update to 1.04.420 or later and move on. ICSA-26-246-02 is more urgent: CVE-2026-75925 in the IXON VPN Client, a CRLF-injection flaw rated 9.6 on CVSS v3.1, affecting versions before 1.4.7, where unauthenticated attackers can modify configuration files used by privileged processes and potentially reach root or SYSTEM. Remote-access clients installed on engineering laptops are exactly the software nobody inventories; find yours. ICSA-26-246-06 covers CVE-2026-77393 in Inductive Automation Ignition, CVSS v3 8.8, a permissions-default problem (CWE-269/276) in which the Gateway’s “Create Project Role(s)” setting shipped blank, so any authenticated user able to execute gateway scripts could create projects; 8.1.53 and earlier are affected, the 8.3 line is unaffected, and 8.1.54 restricts project creation to Designer sessions. And ICSA-26-246-07 is the highest-scoring of the set: CVE-2026-78012 in the Pyramid Solutions NetStaX EtherNet/IP stack, a stack-based buffer overflow (CWE-121) at 9.8 on CVSS v3.1 and 9.3 on v4.0, vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, in versions before 5.6.1, where a large Class 3 explicit-message request can exceed the application-side receive buffer without generating any error or warning.

Two of these deserve a note beyond the patch list. The NetStaX finding is a protocol-stack vulnerability in licensed OEM software, which means the affected inventory is not “devices from Pyramid Solutions” but every device from every vendor that embedded this stack — and your asset register almost certainly does not record that. Ask your EtherNet/IP device vendors directly whether they ship it, and treat a slow answer as a finding in its own right. The RSLinx and Logix advisories share a pattern worth naming: all of them are denial of service reachable by a crafted CIP message, and none of them requires credentials. Any environment where an untrusted network segment can send CIP traffic to a controller or to an RSLinx host is one crafted packet away from a manual restart or a physical power cycle. That is an architecture finding, and it will still be true after these particular CVEs are patched.

Sources: CISA (RSLinx Classic) · CISA (Logix Platform) · CISA (ControlLogix / CompactLogix / GuardLogix) · CISA (OPC UA LDS) · CISA (IXON VPN Client) · CISA (Inductive Automation Ignition) · CISA (Pyramid Solutions NetStaX)

9. Sector round-up: a new Coast Guard office, ransomware in food and agriculture, and one Forrester Wave announced twice

SecurityWeek · Industrial Cyber · Dragos · Claroty · August 18 – September 4, 2026

The US Coast Guard has established an Office of Maritime Cybersecurity Policy, designated CG-MCP, under the Director of Inspections and Compliance. Its mandate is to act as the central authority for cybersecurity policy governing the Marine Transportation System, to serve as the primary liaison with industry and government, and to develop domestic policy, contribute to international standards and direct compliance strategy. The scope is roughly 360 commercial sea and river ports in the United States, and Rear Adm. Robert C. Compher, Assistant Commandant for Prevention Policy, is the named official. The office follows a February 2025 GAO report that identified shortcomings in the Coast Guard’s cyber approach to the MTS. It arrives alongside two Dragos pieces on what MTSA compliance actually asks of an operator: the routine-maintenance requirements at 33 CFR 101.650(e)(3)(i) through (v) — patch Known Exploited Vulnerabilities or document compensating controls, run a process for publicly submitted vulnerabilities, share threat and vulnerability information, eliminate direct internet exposure of OT, and restrict OT internet connectivity — and the parallel resilience requirement. The line from the first of those is the one to put in a compliance file: “‘We are working on a plan to patch’ is not a compensating control.”

The Food and Ag-ISAC, with the IT-ISAC, published “State of the Threat: Food and Agriculture Sector Cyber Trends”, and its numbers are the clearest sector trend line published this week: 227 ransomware incidents in food and agriculture through July 2026, up 62% from 140 in the same period of 2025, against an all-sector total of 4,272 successful attacks, up 22.7% year on year. Qilin leads the groups active against the sector with 47 incidents, followed by The Gentlemen at 31 and Akira at 14. The report tracks more than 330 adversaries, records ClickFix social engineering up 108% in the first half of 2026, and notes CVE disclosures on pace for roughly 66,000 in 2026, 46.3% above projection. It also names China, Russia — including the FSB Center 16-linked cluster tracked as Berserk Bear, Energetic Bear, Crouching Yeti and Dragonfly — Iran and North Korea as nation-state actors of concern to the sector. On the incident side, Boston Scientific is still recovering from an intrusion detected on August 25 in its on-premises IT systems and disclosed the following day. The global network outage disrupted manufacturing, customer order processing and shipping; implanted cardiac rhythm management devices were unaffected, though remote activations for some cardiac monitors were disrupted. CrowdStrike was engaged, no group has claimed responsibility, no financial figures have been disclosed, and partial shipments were expected to resume in the week beginning August 31. It is the familiar shape of a manufacturing incident: the control system stayed healthy and the company still could not ship.

On the market side, two vendor posts this week announce the same document. The Forrester Wave for Operational Technology Security Solutions, Q3 2026, published September 1, named both Dragos and Claroty as Leaders; Dragos reports the highest possible score in eight criteria, Claroty in nine, and neither post mentions the other. The Dragos post is worth flagging for a second reason: its on-page headline reads as thought leadership about the future of xOT cybersecurity, but it is a placement announcement written by a product marketing lead. Read both as positioning, and go to the Wave itself if you are running a selection. Around them, Cognizant and CrowdStrike expanded a partnership dating from 2025 into Cognizant Cybersecurity for Operational Technology, built on CrowdStrike Falcon for XIoT, with Vishal Salvi of Cognizant and Daniel Bernard of CrowdStrike fronting it; Marlink expanded its own OT security capabilities for connected maritime and industrial systems; and F6, a Moscow-based cybersecurity firm, reported that manufacturing is the top cyberattack target for 2026 and that 80% of companies including critical information infrastructure facilities face a shortage of qualified information security staff, with vacancies taking months to fill and a 24/7 team taking twelve to eighteen months to build from scratch. F6 publishes no sample size or geography for that figure, so treat it as the firm’s claim rather than a sector statistic — the staffing constraint it describes is real enough in Western plants too, but this is not the evidence for it.

Sources: SecurityWeek (Coast Guard) · Dragos (MTSA maintenance) · Dragos (MTSA resilience) · Industrial Cyber (Food and Ag-ISAC) · SecurityWeek (Boston Scientific) · Dragos (Forrester Wave) · Claroty (Forrester Wave) · Industrial Cyber (Cognizant/CrowdStrike) · Industrial Cyber (Marlink) · Industrial Cyber (F6)

Calls to action

  • Scan for your own controllers on 44818, 2222, 102 and 502 this week. More than a hundred water-sector incidents since July 27 came from PLCs answering directly from the internet. Scan your own netblocks and the carrier-assigned ranges behind every cellular modem, and search the commercial scanning services for your organisation’s name and equipment banners — that is the query the adversary ran first.
  • Patch the September 1 and 3 advisories where they land. RSLinx Classic 4.50 and earlier to 4.60; the Logix platform to V34.015, V35.014, V36.013 or V37.011 depending on your line; IXON VPN Client to 1.4.7; Ignition 8.1.53 and earlier to 8.1.54; OPC UA LocalDiscoveryServer to 1.04.420; NetStaX-based devices to 5.6.1. Check which Rockwell Logix advisory your change record actually cites — two were published the same day with overlapping product families.
  • Ask your EtherNet/IP device vendors whether they embed the Pyramid Solutions NetStaX stack. CVE-2026-78012 is a 9.8 stack overflow in licensed OEM software, so the affected inventory is not one vendor’s product line. Your asset register does not record embedded stacks; only the vendor can answer, and a slow answer is itself a finding.
  • Rehearse a controller lockout recovery, on paper, before you need it. Minnesota utilities recovered by opening cabinets, pulling backup batteries and performing hard factory resets. Write down which cabinet, which battery, which reset sequence, who drives there and how long the plant runs manually in the meantime.
  • Check whether your private APN isolates clients. The Polish CHP plant was reached because one compromised wind-farm site could scan the grid operator’s entire private cellular range. Ask your carrier directly for client isolation on the APN, and treat “it’s a private network” as an assumption to test rather than a control.
  • Put the remote sites nobody staffs on a patch cadence with a named owner. The intrusion started at an unpatched internet-facing firewall at a wind farm and moved through a cellular router. Firewalls, VPN appliances and cellular gateways at unstaffed generation and pumping sites are the most consistently productive class in the industry, and ownership is usually ambiguous between operator and developer.
  • Start monitoring the seven ICS ports Netresec names. TCP 102, 502, 2404, 5094, 20000, 44818 and 47808. Eleven days of adversary activity in Poland were reconstructed by hypothesis because no logs existed. If nothing on your process network records these, that is the cheapest gap on this page to close.
  • Find out where your CISA assessment request stands before the offering closes. Cyber Resilience Reviews, Ransomware Readiness Assessments and four others are being retired. If you were queued for one, get the status now and identify the replacement — sector ISAC, state programme, surviving regional advisor relationship, or a commercial assessment mapped to the same control set.
  • Get your battery-storage telemetry rights in writing. The evidence needed to tell a hostile frequency response from a revenue-driven one sits with your optimiser and OEM cloud platform, not with you. Establish contractually what dispatch and inverter data they retain, for how long, and how fast you can obtain it after an anomaly.
  • Run the tabletop where the control system is healthy and you still cannot ship. Boston Scientific’s intrusion hit on-premises IT and stopped manufacturing, order processing and shipping. Establish which lines run degraded, for how long, on what paper process, and who may release product without the electronic quality record.
  • Rewrite “we are working on a plan to patch” out of your compliance file. If you are MTSA-regulated, 33 CFR 101.650(e)(3) requires KEV patching or documented compensating controls, a process for publicly submitted vulnerabilities, information sharing, and the elimination of direct internet exposure of OT. Documented compensating controls means written, specific and in place.
  • Plan for cheaper payloads, not cheaper discovery. Forescout’s experiment cost USD 535.74 and eight and a half hours to port one exploit, then produced two working payloads in twelve minutes. Weight your programme toward exposure reduction and detection, and retire any control whose value rests on an attacker finding it hard to write shellcode for your architecture.

IT/OT Security

A weekly intelligence bulletin from Security Radar LLC.
Curated by Paul Davis · paul.davis@security-radar.com

© 2026 Security Radar LLC. All rights reserved.

Article titles and summaries are excerpted for review and commentary; all linked articles remain the copyright of their respective publishers and authors.

*|LIST:ADDRESS|*

View this email in your browser · Unsubscribe

Recent Posts

  • AI Ops Weekly — September 6, 2026
  • AI Ops Weekly — September 6, 2026 — Interactive Topic Map
  • AI & Machine Learning Security — September 6, 2026

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • November 2025
  • April 2024
  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • April 2023
  • March 2023
  • February 2022
  • January 2022
  • December 2021
  • September 2020
  • October 2019
  • August 2019
  • July 2019
  • December 2018
  • April 2018
  • December 2016
  • September 2016
  • August 2016
  • July 2016
  • April 2015
  • March 2015
  • August 2014
  • March 2014
  • August 2013
  • July 2013
  • June 2013
  • May 2013
  • April 2013
  • March 2013
  • February 2013
  • January 2013
  • October 2012
  • September 2012
  • August 2012
  • February 2012
  • October 2011
  • August 2011
  • June 2011
  • May 2011
  • April 2011
  • February 2011
  • January 2011
  • December 2010
  • November 2010
  • October 2010
  • August 2010
  • July 2010
  • June 2010
  • May 2010
  • April 2010
  • March 2010
  • February 2010
  • January 2010
  • December 2009
  • November 2009
  • October 2009
  • September 2009
  • June 2009
  • May 2009
  • March 2009
  • February 2009
  • January 2009
  • December 2008
  • November 2008
  • October 2008
  • September 2008
  • August 2008
  • July 2008
  • June 2008
  • May 2008
  • April 2008
  • March 2008
  • February 2008
  • January 2008
  • December 2007
  • November 2007
  • October 2007
  • September 2007
  • August 2007
  • July 2007
  • June 2007
  • May 2007
  • April 2007
  • March 2007
  • February 2007
  • January 2007
  • December 2006
  • November 2006
  • October 2006
  • September 2006
  • August 2006
  • July 2006
  • June 2006
  • May 2006
  • April 2006
  • March 2006
  • February 2006
  • January 2006
  • December 2005
  • November 2005
  • October 2005
  • September 2005
  • August 2005
  • July 2005
  • June 2005
  • May 2005
  • April 2005
  • March 2005
  • February 2005
  • January 2005
  • December 2004
  • November 2004
  • October 2004
  • September 2004
  • August 2004
  • July 2004
  • June 2004
  • May 2004
  • April 2004
  • March 2004
  • February 2004
  • January 2004
  • December 2003
  • November 2003
  • October 2003
  • September 2003

Categories

  • AI-ML
  • AI-Ops
  • Augment / Virtual Reality
  • Blogging
  • Cloud
  • Competitive
  • DR/Crisis Response/Crisis Management
  • Editorial
  • Financial
  • IT/OT Security
  • Make You Smile
  • Malware
  • Mobility
  • Motor Industry
  • News
  • OTT Video
  • Pending Review
  • Personal
  • Product
  • Regulations
  • Secure
  • Security Industry News
  • Security Operations
  • Statistics
  • Threat Intel
  • Trends
  • Uncategorized
  • Warnings
  • WebSite News
  • Zero Trust

Meta

  • Log in
  • Entries feed
  • Comments feed
  • WordPress.org
© 2026 CyberSecurity Institute | Powered by Superbs Personal Blog theme