August 29, 2026
Five verified OT and industrial cybersecurity items relevant to security professionals, including guidance on exposure reduction, supply‑chain authority for grid equipment, emerging reconnaissance techniques against Siemens PLCs, telemetry gaps in OT, and urgent KEV additions.
AI-Generated Scripts Lower the Barrier for Siemens S7 PLC Reconnaissance
CISA advisory AA26-231A reports malicious actors are using AI‑generated Python scripts built around snap7.dll and python-snap7 to interact with Siemens S7comm on TCP port 102. The advisory concerns reconnaissance and capability development against Siemens S7-200, S7-300, S7-400, S7-1200, and S7-1500 PLCs, including F‑series safety controllers; it reports no confirmed process‑disruption incidents and recommends eliminating internet exposure, blocking port 102 at the perimeter, applying available updates, and monitoring S7comm traffic.
Source: Forkast
CISA Urges Exposure Management After Attacks on More Than 100 U.S. Water Systems
CISA cited cyberattacks against more than 100 internet‑exposed U.S. water and wastewater systems in July 2026 and issued exposure‑reduction guidance. The four‑step guidance emphasizes finding exposed assets and third‑party remote access, removing unnecessary exposure, hardening systems that must remain accessible with strong credentials, updates, monitoring and centrally managed remote access, performing routine reassessments, and specifically warns against directly connecting to PLCs, HMIs, or RTUs.
Source: SANS NewsBites
Executive Order Elevates Bulk-Power Equipment Supply-Chain Cybersecurity
A new executive order signed August 26 authorizes the U.S. Department of Energy to prohibit, condition, monitor, or require replacement of foreign‑produced bulk‑power equipment that presents unacceptable cybersecurity, reliability, resilience, or national‑security risk. The scope includes substation transformers, grid‑connected inverters, battery energy storage systems, generators, industrial control systems such as RTUs and PLCs, and protective relays, including relevant firmware, remote‑access capabilities, and lifecycle update mechanisms. It can also reach equipment already installed, and implementing rules are directed within 120 days.
Source: Baker Donelson
OT Telemetry Gaps Put the Spotlight on Earlier IT-to-OT Attack Detection
A commentary highlights that PLCs, RTUs, cameras, badge controllers, building‑management systems, and other operational assets often produce little usable security telemetry, retain logs locally, or do not feed standard analytics. It argues attackers moving from enterprise systems toward OT can leave defenders without sufficient evidence or forensic history and recommends deception mechanisms such as decoy credentials, engineering workstations, PLCs, and assets to create high‑fidelity alerts across the IT‑to‑OT attack path.
Source: Dark Reading
CISA Adds Ten Vulnerabilities to KEV, Including Several With Three-Day Mitigation Deadlines
CISA added ten vulnerabilities to its Known Exploited Vulnerabilities catalog since August 25, with five carrying three‑day mitigation deadlines for U.S. federal agencies. The urgent set includes flaws affecting Gitea, Citrix NetScaler ADC and Gateway, Microsoft SQL Server, ownCloud, and the Linux kernel, and the report underscores that asset discovery and validated remediation remain important for remote‑access and supporting infrastructure connected to OT environments where unpatched perimeter or management systems can offer an entry point.
Source: SANS NewsBites
Closing: Prioritize exposure reduction, asset discovery, and timely remediation across IT and OT environments.