Skip to content
COOEY
ADVISORIES
2 advisories

CISA cyber & ICS and DC3 (DoD Cyber Crime Center / DCISE) threat products relevant to the DIB — each read by dex into a categorized card: the gist, why it matters, who's affected, and what to do.

ICS / OT CISA 2026-08-19

Defending Against an Active Threat to Siemens S7 Series PLCs ↗

Active threat actors are using AI-generated scripts to target Siemens S7 Series PLCs; owners must patch, isolate, and harden these devices.

CISA, NSA, FBI, DOE, and EPA warn of an active cyber threat targeting Siemens S7 Series programmable logic controllers (PLCs) using AI-generated exploitation scripts. While the advisory focuses on Siemens, the broader PLC targeting landscape requires all ICS owners to apply relevant mitigations to reduce risk to their devices and systems.

AFFECTEDSiemens S7 Series PLCs

▸ DO  Inventory all Siemens S7 Series PLCs, apply critical security patches, and ensure they are not accessible from the Internet.

#ics-ot#ai-generated#patch-available#mitigations
ICS / OT CISA 2026-07-30

CISA Urges Water and Wastewater Systems Sector to Protect OT Against Activity Targeting PLCs ↗

CISA warns of active cyber attacks targeting exposed PLCs in water and wastewater systems, causing operational disruptions and physical damage.

Threat actors are actively targeting programmable logic controllers (PLCs) in the Water and Wastewater Systems sector, modifying passwords to lock out operators and changing IP addresses to disconnect devices. This activity has led to boil water notices and sustained manual operations, affecting entities of all sizes, including those with mature cybersecurity processes.

AFFECTEDWater and Wastewater Systems Sector PLCs

▸ DO  Remove publicly exposed PLCs and other OT from the internet immediately; implement remote access via VPN or gateway instead of direct connections; enable password protection and change default passwords; allowlist IPs for remote access.

#ics-ot#state-sponsored#mitigations#dib-sector