Thursday, July 23, 2026

CISA Updates Iranian PLC Attacks Advisory – 7-22-26

Yesterday, CISA announced that they had updated their Joint Cybersecurity Advisory on “Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure that had originally been published on April 7th, 2026. The new information included expanding the list of affected products to include systems from Schneider Electric and Siemens and includes updated indicators of compromise information (XML and JSON). 

I do not typically cover these Joint Cybersecurity Advisories, but the Technical Details section of the report included the following comment: 

“After the actors extracted device project files, the FBI and CISA identified the modification and deletion of project file logic, to include Add-On Instructions (AOIs) and data manipulation on HMI and SCADA displays (T1565). Additionally, the changes disabled critical shutdown and alarm logic, allowing systems to enter unsafe conditions without notifying operators of the anomalies.” 

As a former process chemist, that claim certainly caught my attention and raised the stakes considerably. 

The Joint Advisory references two supporting vendor advisories for products from Rockwell Automation and Siemens. Siemens updated that advisory today, adding S7-1200 PLC as targeted device based on the CISA advisory update as well as references to S7-1200 G1, S7-1200 G2, S7-1500 user manuals. They did not, however, remove the following comment: 

“At this point in time, we have not observed any exploitation of vulnerabilities (emphasis added) in Siemens industrial control system (ICS) products.” 

Neither CISA nor the vendors have identified a specific, correctable vulnerability involved in these attacks. 

No comments:

 
/* Use this with templates/template-twocol.html */