ICS / OT
CISA
2026-08-19
Active threat actors are using AI-generated scripts to target Siemens S7 Series PLCs; owners must patch, isolate, and harden these devices.
CISA, NSA, FBI, DOE, and EPA warn of an active cyber threat targeting Siemens S7 Series programmable logic controllers (PLCs) using AI-generated exploitation scripts. While the advisory focuses on Siemens, the broader PLC targeting landscape requires all ICS owners to apply relevant mitigations to reduce risk to their devices and systems.
AFFECTEDSiemens S7 Series PLCs
▸ DO Inventory all Siemens S7 Series PLCs, apply critical security patches, and ensure they are not accessible from the Internet.
#ics-ot#ai-generated#patch-available#mitigations
ICS / OT
CISA
2026-07-30
CISA warns of active cyber attacks targeting exposed PLCs in water and wastewater systems, causing operational disruptions and physical damage.
Threat actors are actively targeting programmable logic controllers (PLCs) in the Water and Wastewater Systems sector, modifying passwords to lock out operators and changing IP addresses to disconnect devices. This activity has led to boil water notices and sustained manual operations, affecting entities of all sizes, including those with mature cybersecurity processes.
AFFECTEDWater and Wastewater Systems Sector PLCs
▸ DO Remove publicly exposed PLCs and other OT from the internet immediately; implement remote access via VPN or gateway instead of direct connections; enable password protection and change default passwords; allowlist IPs for remote access.
#ics-ot#state-sponsored#mitigations#dib-sector