Security1 distinct publisher3 min readUpdated
CISA and six partner agencies updated AA26-097A on July 22, extending the vendor scope beyond Rockwell and adding detection guidance for tampered reusable code modules.
The Watch · Security desk
Compiled by The WatchSomething wrong?How this is made
The seven agencies behind advisory AA26-097A revised it on July 22, 2026, adding guidance on detecting malicious changes in reusable code modules used inside Rockwell Automation PLC programs and expanding the manufacturer scope to include observed targeting of Schneider Electric, Siemens, and potentially other branded PLCs [1][2][3]. The advisory first went out on April 7, 2026 with TTPs and indicators for ongoing exploitation of internet-connected operational technology devices by Iranian-affiliated APT actors [4], which means any asset owner who built an April response plan around a single vendor's product line now has a scoping error to fix, 106 days later [13].
The authoring agencies are the FBI, CISA, NSA, EPA, the Department of Energy, US Cyber Command's Cyber National Mission Force, and the Treasury [1]. Their warning covers PLCs manufactured by Rockwell Automation/Allen-Bradley, Schneider Electric, Siemens, and potentially other manufactured PLCs across multiple US critical infrastructure sectors [5]. The named sectors are Government Services and Facilities, including local municipalities, Water and Wastewater Systems, and Energy [8].
The observed effects are worth reading closely, because they are not ransomware-shaped. Organizations experienced disruptions through malicious interactions with PLC project files and through manipulation of the data shown on HMI and SCADA displays [6]. In a few cases, the activity caused operational disruption and financial loss [7]. Manipulating what an operator sees on a screen is a different detection problem from encrypting a file server, and it is the reason the new guidance on reusable code modules matters more than its low-key placement in an update note suggests: a plant can pass an inventory check, a firmware check, and a network check while the logic running on the controller has been altered.
The agencies assess that a group of Iranian-affiliated APT actors is conducting this activity to cause disruptive effects within the United States [9]. They have previously reported similar PLC-targeting activity by CyberAv3ngers, also called the Shahid Kaveh Group, a threat actor affiliated with the IRGC's Cyber Electronic Command [10]. In a comparable campaign beginning in November 2023, those actors targeted US-based PLCs and HMIs and compromised at least 75 devices, focusing on Unitronics PLC devices with an integrated HMI used across sectors including water and wastewater [11]. The same group is tracked in industry reporting as Hydro Kitten, Storm-0784, APT Iran, Bauxite, Mr. Soul, Soldiers of Solomon, and UNC5691 [12].
Operationally, the July update is not a re-read of the same document. It ships a fresh IOC package as STIX XML and JSON dated July 22, kept separate from the historical April 7 indicators [14], so hunts that ran once in April against the original set need to run again against the new one. The advisory asks organizations to urgently review the TTPs and IOCs for indications of current or historical activity and to apply the mitigations [15], and it emphasizes restricting direct internet access to these devices [3]. If an affected internet-accessible device turns up, the agencies say additional technical measures may be needed to evaluate compromise risk, and they direct owners to engage incident response plans and contact both the agencies and the applicable vendors through existing support channels [16].
What to watch: whether the scope widens a third time, given that the agencies already allow for "potentially other" brands [5]; whether Schneider Electric and Siemens publish matching customer guidance for their own product families; and whether the reusable-code-module detection advice gets extended beyond Rockwell programs, since the technique is not vendor-specific in principle [3].
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
The authoring agencies updated the advisory on July 22, 2026, to add new guidance on detecting malicious changes in reusable code modules leveraged within Rockwell Automation PLC programs.
The agencies warn of ongoing cyber exploitation of internet-connected OT devices including PLCs manufactured by Rockwell Automation/Allen-Bradley, Schneider Electric, Siemens, and potentially other manufactured PLCs, across multiple US critical infrastructure sectors.
The authoring agencies assess that a group of Iranian-affiliated APT actors is conducting this activity to cause disruptive effects within the United States.
Advisory AA26-097A was authored by the FBI, CISA, NSA, EPA, Department of Energy, US Cyber Command - Cyber National Mission Force (CNMF), and the Department of the Treasury.
The July 22, 2026 update also expands the manufacturer scope to include observed targeting of Schneider Electric, Siemens, and potentially other branded/manufactured PLCs, emphasizing the importance of restricting direct internet access and providing best practice resources for secure deployment.
The advisory was originally published on April 7, 2026, to provide tactics, techniques, and procedures and indicators of compromise related to ongoing cyber exploitation of internet-connected operational technology devices by Iranian-affiliated APT actors.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Primary joint-agency advisory with machine-readable IOCs, but single-source
The cluster rests on the authoritative primary document: a seven-agency joint advisory that cites direct FBI observation, engagements with victim organizations since at least March 2026, a specific victim technical detail (a project file that overrode safe-operating-parameter instructions), a historical device count for the 2023 campaign, and downloadable STIX XML/JSON IOC packages that defenders can independently validate against telemetry. Evidence is deducted for being uncorroborated by any second publisher, for withholding the scale of the 2026 activity, and for the supplied source body being truncated before the Mitigations and full TTP detail.
Real-world exploitation documented; defender uptake of guidance unmeasured
Adoption is scored on documented real-world occurrence rather than product uptake: the agencies report victim-confirmed PLC disruption across Government Services and Facilities, Water and Wastewater Systems, and Energy since at least March 2026, plus a prior campaign with at least 75 compromised Unitronics devices, and the advisory itself is now a published, versioned artifact with distributable IOCs. The score is held mid-range because no source discloses how many organizations were affected in 2026, how many have hunted for the IOCs, or how widely the mitigations have been implemented.
Slightly understated: hedged official language, thin external coverage
The advisory's language is urgent but disciplined — impact is qualified as affecting 'a few cases', attribution is framed as an agency assessment, and the vendor scope expansion is stated as observed targeting rather than confirmed mass compromise. The cluster headline tracks the document faithfully. Against that, the material risk (safety-parameter overrides on internet-exposed PLCs in water, municipal, and energy environments, plus tampering hidden inside reusable code modules) is carried by a single primary publisher with no amplifying or corroborating coverage, so the story reads as somewhat under-told relative to its evidence rather than overstated.
Government mission incentive to warn; no commercial stake
The sole publisher is the issuing government agency, which has a statutory mission incentive to drive urgent defensive action and to demonstrate interagency response, and it names three commercial PLC vendors without including any vendor reply. There is no pricing, product, or revenue interest behind the publication, and the release of independently verifiable STIX IOCs and a hedged impact statement cut against any incentive to exaggerate, so distortion pressure is assessed as low.
High source authority, low source diversity
Confidence is anchored by the fact that the cluster's single source is the authoritative primary document rather than secondhand reporting, and every canonical claim maps directly to explicit advisory text. It is capped below high because there is exactly one publisher, no independent verification of the attribution assessment or the impact characterization, no vendor confirmation, and the supplied body is cut off before the Mitigations section that the recommendations point to.
build
AI-written snap7 scripts move the scarce resource in OT attacks from skill to exposure2 distinct publishers
security
Gunra Goes Franchise: Conti's Leaked Code Now Ships With a Builder and an Affiliate Panel2 distinct publishers
product
After Arup, a face on a video call is not a credential1 distinct publisher
security
Akira advisory update: $244m taken, one SonicWall CVE, three controls to audit now1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.