CISA and six partner agencies updated AA26-097A on July 22, extending the vendor scope beyond Rockwell and adding detection guidance for tampered reusable code modules.
Perspective Coverage
12 publishers
- Builder
- Builder 29%
- Operator
- Operator 60%
- Investor
- Investor 11%
Reality
- Evidence60
- Adoption
- Insufficient
- Hype gap+30
- Incentives45
- Confidence58
A hand-built client walked TPKT, COTP and S7comm against a Snap7 server on port 102, negotiated a 480-byte PDU and pulled 16 bytes out of DB3 with function code 0x04. The layers below that byte are the same for a write.
Reality
- Evidence60
- Adoption
- Insufficient
- Hype gap−5
- Incentives42
- Confidence52
Joint advisory AA26-231A describes threat actors feeding internet-scan results into AI tools that emit working python-snap7 clients against Siemens S7 controllers. Siemens says the weakness is configuration, not a new vulnerability.
Reality
- Evidence58
- Adoption28
- Hype gap+12
- Incentives45
- Confidence55
Five US agencies told PLC owners that scanners are finding exposed Siemens S7 controllers. ZoomEye puts that surface at 173 assets by product fingerprint, or 161,764 by open port.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+5
- Incentives40
- Confidence55
A Siemens-specific follow-up to the July PLC warning describes internet-wide discovery paired with AI-generated Python tooling that reads and writes ladder logic.
Reality
- Evidence58
- Adoption35
- Hype gap+15
- Incentives40
- Confidence55