MEFILES · Edition No. 13Today's edition · Archive · RSS
Seven files · One region · Zero illusions
Digital Front Monitor The full edition of July 27, 2026 →
Update, Not Incident

Six US Agencies Widen the Iranian PLC Advisory to Siemens and Schneider, Three Months On

The joint advisory AA26-097A was revised on 22 July to add detection guidance and two new PLC manufacturers. It documents a campaign that began in November 2023 — not a new intrusion this weekend.

CISA published a revised version of AA26-097A, “Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure,” on 22 July 2026. The original, issued on 7 April by the FBI, CISA, the NSA, the EPA, the Department of Energy and US Cyber Command’s Cyber National Mission Force, covered internet-exposed Rockwell Automation PLCs in US government facilities, water and wastewater systems and energy infrastructure. The July revision adds guidance on detecting malicious changes in reusable code modules inside Rockwell PLC programs and expands the manufacturer scope to include observed targeting of Schneider Electric, Siemens and potentially other branded controllers, stressing that direct internet access be restricted. The advisory attributes the activity to actors affiliated with the IRGC’s Cyber Electronic Command operating as “CyberAv3ngers,” also tracked as Hydro Kitten, Storm-0784, Bauxite and UNC5691, and dates the comparable earlier campaign against US PLCs and HMIs to November 2023.

The framing gap is visible in how the document travelled. WaterISAC told members that the agencies had “updated” the advisory, that the original dated from 7 April, and that the revision was circulated “to draw awareness to the new information which may require utility action if not done already.” Several trade outlets ran the same document as an Iranian escalation story over the weekend. Nothing in the material reviewed reports a fresh intrusion or disruptive effect inside the 24–27 July window. The escalation language traces back to April, when Burns & McDonnell’s 1898 & Co. called the original advisory “a significant escalation in Iranian offensive cyber capability against operational technology, consistent with anticipated retaliatory activity” — a characterisation from a firm that sells detection services built against this advisory.

Assessment: Two things are being conflated: the state’s threat picture widening, and the threat itself widening this week. Only the first is documented. A scope expansion from one PLC brand to three tells you where defenders have since looked, not necessarily where attackers have since gone — and the agencies say as much by publishing detection guidance rather than incident reporting. Treat the recirculation tempo as a signal about the news cycle around the Gulf confrontation, not about intrusion tempo. Readers should also note what this desk could not check inside the window: Predatory Sparrow activity, platform takedowns, Israeli directorate statements and current NetBlocks postings on Iranian connectivity. Unchecked is not absent.