MEFILES · Edition No. 15Today's edition · Archive · RSS
Seven files · One region · Zero illusions
Digital Front Monitor The full edition of July 29, 2026 →
A Comparison, Not a Finding

The Advisory Everyone Is Citing Was Updated Four Days Before Minnesota Was Touched

CISA’s AA26-097A, refreshed on July 22, names specific Rockwell, Schneider and Siemens controllers. No one has said whether any of the Minnesota utilities ran them — which is the difference between a pattern and a link.

The advisory being pulled into this week’s coverage is not new. AA26-097A was published on April 7, 2026 to document tactics and indicators tied to what the authoring agencies describe as ongoing exploitation of internet-connected OT devices by Iranian-affiliated APT actors. The July 22 update added guidance on detecting malicious changes in reusable code modules inside Rockwell Automation PLC programs and widened the manufacturer scope to include observed targeting of Schneider Electric, Siemens and potentially other branded controllers. WaterISAC’s member note names models: Rockwell CompactLogix and Micro850, Schneider BMX P34 and Modicon M340, Siemens S7-1200. The update also adds MITRE technique T1041, describing use of vendor configuration software on leased infrastructure to steal project files, plus fresh July indicators for log review. WaterISAC’s instruction to utilities and integrators is blunt: remove PLCs from direct internet exposure behind a secure gateway and firewall.

The reported technique is the use of the vendors' own engineering software — Studio 5000, EcoStruxure Control Expert, TIA Portal — to reach controllers over the internet; that account, including the claim that operators were shown falsified sensor readings, comes from a secondary aggregator and should be read off the CISA PDF before it is repeated. One durable detail: Rockwell has confirmed that CVE-2021-22681 cannot be fully resolved by patch, because the weakness lies in how the cryptographic key authenticating Studio 5000 to Logix controller communications is protected. Against that, a researcher quoted by Cybernews in April said threat groups have made “hundreds of unverified claims of compromised OT devices worldwide, including in North America” with no corresponding public disclosures, and that posting control-system screenshots without access is routine. Minnesota inverts that shape entirely.

Assessment: The recirculation is the story here. An advisory updated on July 22 is being read as evidence about an event that began on July 26, and the two connect only through the word “characteristics” in a state spokesperson’s email. AA26-097A is manufacturer-scoped, not incident-scoped; it tells you which controllers are exposed, not who touched Braham. The threshold to watch is narrow and concrete: a city or MNIT naming a Rockwell, Schneider or Siemens device on the affected systems. Absent that, the honest frame is comparison. Note too that the unpatchable-by-design element pushes the remedy toward architecture and procurement budgets in towns of a few thousand people — which is a municipal finance story wearing a geopolitical costume.