Build1 distinct publisher3 min readPublished
CISA counted more than 100 internet-exposed water and wastewater systems targeted in July. The typical example is a controller wired straight to a cellular modem, a path that leaves no proxy log and often no inventory entry.
The Engineer · Build desk

Compiled by The EngineerSomething wrong?How this is made
Wire a PLC to a cellular modem and the device takes its address from a carrier, not from anything you administer. The write-up names that as the core problem: configurations that allow direct reachability to PLCs without passing through corporate IT networks [6]. A normal enterprise detection stack sits on the wrong side of that single hop. The traffic never crosses the proxy, so the proxy has nothing to show [7]. The identity provider sees a login only when a VPN or gateway brokered it, which this design skips by construction [8]. PLCs run no agent, so EDR simply isn't in play, leaving engineering workstations and jump hosts as the nearest supporting evidence [9]. And depending on NAT and how the carrier allocates addresses, the asset may never appear in a standard inventory [5].
What the count means depends on which rung of the write-up's own triage ladder it sits on. There are three: attempt observed, authentication success confirmed, subsequent compromise confirmed [10][11][13]. July's activity sits on the bottom rung, because nothing public confirms that authentication or manipulation succeeded on any individual system [13][21]. Reaching the second rung requires successful unauthorised logins evidenced in device or gateway logs [10]. The same document lists absent OT network monitoring and remote access logging as a contributing weakness [12]. The evidence that would upgrade the finding is missing for the same reason the exposure exists [22]. Read the zero-confirmed-compromises tally as a property of the logging, not as proof nothing happened.
That caps what you can borrow. No credentials, vulnerabilities, protocols, commands or configuration change procedures have been published [14], so there is no indicator to load and no specific CVE to chase. What transfers is the shape: a controller with a carrier-routable address and a live management interface, in a place your asset database does not describe.
The remediation list is short and expensive. Consolidate access behind secure gateways, jump hosts or VPNs [15], then change default passwords and add updates, MFA, allowlisting and least privilege, plus external attack surface discovery and continuous OT traffic monitoring [16]. Read that as a staffing plan rather than a project. The modem is there because a two-person utility needed to change a setpoint at 02:00 without driving to the plant. Pull the modem without replacing that capability and the operational risk simply relocates instead of going away, which is why the shortcut keeps getting rebuilt after every advisory.
Provenance matters for how hard you lean on this. The summary credits SecurityWeek's report of CISA's observation, rates the item High, and points at CISA's internet exposure reduction guidance as the related resource [20]. No critical operational disruption, water outage or water quality effect has been reported [3]. The one measurement in this story that was taken from the same vantage point as the attacker is an external scan of your own carrier address space, which is why it appears on the mitigation list rather than in the incident report [16].
Ranked by verification strength, evidence, and original report placement.
In July 2026, CISA observed malicious activity targeting over 100 internet-exposed systems in the water and wastewater sector.
Typical examples of the targeted systems were PLCs connected directly to cellular modems; threat actors targeted remote management features.
No critical operational disruptions have been confirmed, and no widespread water outages or water quality effects have been reported.
Depending on NAT or telecommunication provider configurations, external exposure may not appear in standard asset inventories.
The core issue involves configurations that allow direct reachability to PLCs without passing through corporate IT networks.
If OT devices connect directly to cellular networks, corporate proxies will not capture those logs.
Distinct publishers with included, body-backed reporting in this cluster.
dev.to
1 article · August 27, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
security
CISA finally counts the water intrusions: 100-plus exposed systems behind cellular modems2 distinct publishers
security
CISA orders Ray patched as RondoDox folds cluster software into a 174-exploit arsenal1 distinct publisher
security
CISA's water-sector answer is an inventory: 100-plus exposed systems, most of them PLCs1 distinct publisher
build
AI-written snap7 scripts move the scarce resource in OT attacks from skill to exposure2 distinct publishers
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Government-sourced count, no technical substantiation
The load-bearing facts trace to a CISA observation relayed through SecurityWeek and re-written by a single community publisher, so the count of 100-plus targeted systems and the cellular-modem exposure pattern are attributed but not independently verifiable here. The same source states that credentials, vulnerabilities, protocols, commands and exploitation conditions are not public, and that success on individual systems is unconfirmed, so there are no indicators, device logs, or case detail to check. Evidence quality is adequate for the exposure-pattern claim and weak for anything about actor capability or outcome.
Real targeting counted at scale, impact unconfirmed
There is a concrete real-world occurrence rather than a hypothetical: a named authority counted more than 100 exposed systems under attack in a single month in one sector, and the exposure pattern is described as typical rather than exceptional. What is absent is any confirmed consequence: no successful login proven per system, no confirmed logic or configuration change, no process or water quality impact. Real-world presence is therefore established at the attempt and exposure level only.
Mostly disciplined, with an unearned attribution and a High rating above confirmed impact
The write-up is unusually careful for a threat item: it labels the activity attempt-observed, repeats that no disruption was confirmed, and says the technical specifics are not public. Two elements still run ahead of the evidence. The High severity rating sits above anything confirmed in the material, and the Iran-linked attribution appears only as a metadata line for the broader activity with no evidence, naming authority, or stated connection to the 100-plus systems, while the headline framing invites readers to join the two. The gap is small and positive, not systemic overstatement.
Aggregated advisory content, no visible commercial stake
The single publisher is a developer community post that credits SecurityWeek as the original source and points to CISA's own exposure reduction guidance; no vendor product, sponsor, funding round, or proprietary detection service is promoted, and the recommended controls are generic hygiene rather than a named tool. The residual incentive is attention-based: threat write-ups reward severity framing and recognisable actor names, which fits the unsupported Iran-linked line and the High rating. No disclosure of the author's affiliation is supplied, so this is scored on visible content only.
Single publisher, coherent chain, unverifiable specifics
Confidence is limited primarily by source count: one supplied item, itself a secondary rewrite of a SecurityWeek report on a CISA observation, with no corroborating publisher in the cluster. Within that limit the item is internally coherent and self-limiting about what it does not know, and the structural claims about telemetry gaps and confirmation requirements follow logically from the described architecture rather than depending on undisclosed facts. The count, the attribution, and any per-system outcome remain unverifiable from the supplied material.