Security1 distinct publisher3 min readPublished
July's intrusions into US water utilities did not need an exploit. They needed a PLC on a cellular modem with nothing in front of it, and CISA's August 21 guidance is an inventory job.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
A PLC hanging off a cellular modem is a routable host with no perimeter in front of it, which is why this wave needed no exploit worth naming: reach the device, then use it the way it was built to be used [s1c3]. The damaging moves were administrative. Changing a controller's IP address and its password strips out the two things an engineer needs to reach it over the network, and in some cases the intruders also switched off shutdown processes and alarms [s1c4]. CISA's own account of the result is loss of monitoring and control functionality, with operational disruption at some sites [s1c11].
The August document is short on novelty, and that is its value. Enumerate what you expose, from outside, using Shodan, Censys or CISA's own Cyber Hygiene Vulnerability Scanning service against your registered ranges [s1c7]. Then count ports: three of the familiar IT kind and five industrial ones, eight named protocols in total, which is a list one competent person can walk without a procurement cycle [s1c8][s1c15]. An open Modbus or DNP3 port is not evidence of compromise, only evidence of reachability, which is the part that has to be investigated [s1c8]. Where the connection is genuinely needed, CISA's instruction is a centrally managed gateway, VPN or firewall in the path rather than a direct hop to a PLC, HMI or RTU [s1c9], with phishing-resistant MFA and unique credentials instead of shared defaults [s1c10].
Attribution is the thinnest part of the record. Iran is suspected of much of the activity, tied to the war involving the US and Israel, and officials have not formally attributed it [s1c6]. An operator cannot act on that. Exposure, unlike adversary identity, is countable this week, and the gap between the attack month and the guidance was at most 51 days [s1c14].
SecurityAffairs sets July inside the wider pattern of nation-state interest in critical infrastructure, citing reported Volt Typhoon pre-positioning in US networks and Russian-linked probing of European water and energy systems [s1c12]. The tradecraft on show does not fit that frame. Quiet pre-positioning is defined by years of not being noticed [s1c12]; changing passwords and killing alarms declares itself the first time a pump behaves oddly [s1c4]. Those are two problems that happen to sit on the same asset list, and only one of them shows up in a July incident summary.
The publisher's other point stands on its own: none of the recommended controls are new engineering, they are hygiene that has been on the list for years [s1c13]. What changed is the evidence. There is now a dated, government-described case of directly exposed PLCs being driven into unsafe conditions without the people running the equipment being told [s1c4][s1c11], which is the reason a scan of your own IP ranges is cheaper to run than to justify skipping.
Ranked by verification strength, evidence, and original report placement.
Over 100 internet-exposed systems in the US water and wastewater sector were hit by cyberattacks in July 2026.
CISA published exposure reduction guidance on August 21 walking organisations through how to find their own internet-facing weak points.
Most of the affected systems were programmable logic controllers that control pumps and valves; many were connected directly to cellular modems with no firewall or gateway between them and the internet.
Attackers remotely accessed exposed PLCs, changed device IP addresses and passwords, and in some cases disabled shutdown processes and alarms, creating what CISA called unsafe conditions without notifying the operators running the equipment.
CISA states that internet exposure reduction does not mean disabling necessary remote access: organisations should remove remote access when it is unnecessary and secure it when it is necessary.
CISA presents reconnaissance as an ongoing process and says organisations can use tools such as Shodan, Censys, or CISA's Cyber Hygiene Vulnerability Scanning service to check their own IP ranges from the outside.
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Primary agency guidance quoted, but a single publisher and no incident specifics
The technical core is strong for a one-source cluster: the article quotes CISA's guidance verbatim on cellular-modem exposure, on removing unnecessary versus securing necessary remote access, and on the gateway/HMI/RTU recommendation, and it reproduces CISA's own description of impact. What is missing is anything independently verifiable about the incident itself, no named utilities, no dates beyond 'July 2026', no indicators, and the attribution and the wider pre-positioning narrative are asserted rather than sourced.
Incident footprint and guidance release are dated; remediation uptake is unobserved
Two concrete, dated events anchor adoption: an attack wave touching more than 100 exposed systems in July 2026 and CISA's guidance release on August 21. Both establish that the exposure pattern is real and widespread in the sector. Nothing in the supplied material shows utilities running the inventory, closing ports, or standing up gateways, and no counts, surveys or follow-up advisories are cited, so uptake of the recommended controls is unmeasured and the score reflects the exposure evidence only.
Technical core is grounded; urgency and geopolitical framing run ahead of the evidence
Slightly overstated overall. The mitigation and impact claims sit on quoted CISA text and are not inflated, and the article is candid that none of this is novel engineering. The overshoot comes from framing layered on top: an informal Iran attribution presented as the likely cause, a Volt Typhoon and Russia pre-positioning narrative introduced with 'reportedly' and no citation, and closing imperatives ('run the scan today', 'an open invitation') that push urgency beyond what the supplied evidence about any individual reader's exposure can support.
Trade-press attention and author self-promotion; no vendor pitch, agency promotes its own guidance
Mild and visible incentives. The publisher is a security trade outlet whose readership rewards urgent, actionable ICS coverage, and the piece ends with the author's own social-follow promotion and an imperative call to act. The primary source is CISA describing the value of guidance it authored. Offsetting this, no commercial vendor, product or sponsorship appears, and the recommended tools include a free government scanning service alongside two widely used exposure search engines, so there is no evident sales funnel behind the advice.
Confident on the quoted guidance, weak on incident detail, attribution and uptake
Moderate. One publisher, but it quotes primary agency language for the load-bearing technical claims, and the derived arithmetic (a maximum 51-day gap between the attack window opening and the guidance) is checkable from the dates given. Confidence is held down by the absence of corroborating sources, the lack of any incident specifics beyond an aggregate count, an explicitly informal attribution, and no observable evidence of remediation.
security
CISA's Ebyte advisory carries no fixed version, because the vendor stopped answering1 distinct publisher
security
Johnson Controls console holds passwords in cleartext memory, and the fix line names two versions1 distinct publisher
security
Siemens IoT2050 gateways ship a Node-RED interface that asks nobody for a password1 distinct publisher
security
U.S. warning on Siemens S7 PLCs: AI-written scripts, borrowed scan data, read access first1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 27, 2026