MEFILES · Edition No. 17Today's edition · Archive · RSS
Seven files · One region · Zero illusions
Digital Front Monitor The full edition of July 31, 2026 →
Eight Days Old

The Advisory Being Shared as Thursday News Was Updated on the Twenty-Second of July

Joint advisory AA26-097A widened the target list to Siemens and Schneider and documented stolen PLC project files. It landed four days before the Minnesota utilities were hit.

AA26-097A was first published in early April 2026 and updated on 22 July by the FBI, CISA, NSA, EPA, the Department of Energy and US Cyber Command. The update did three substantive things. It expanded confirmed vendor scope beyond Rockwell Automation and Allen-Bradley to Schneider Electric’s BMX P34 and Modicon M340 and Siemens' S7-1200. It documented for the first time confirmed exfiltration of PLC project files, carried out using the vendors' own engineering software — Rockwell Studio 5000 Logix Designer, Schneider EcoStruxure Control Expert and Siemens TIA Portal — run from leased third-party infrastructure. And it added detection guidance for tampering with Add-On Instructions, the reusable code modules inside PLC programs. The advisory records manipulation of HMI and SCADA displays causing operational disruption and financial loss, with added logic overriding instruction sets that had maintained safe operating parameters. CISA’s headline mitigation remains the simplest one: disconnect controllers from the public internet.

Infosecurity Magazine published on the advisory on 30 July and it is circulating as news of that day. TechCrunch covered it on 23 July, as did SecurityWeek and TechTimes. The genuinely new federal item on 30 July was the separate FBI, EPA and CISA warning to wastewater operators, not the advisory behind it. The number worth carrying is the interval: Tenable and The Register both place four days between the 22 July update and the 26 July intrusion in Minnesota. Underneath sits CVE-2021-22681, an authentication bypass in Rockwell Logix controllers rated 9.8, disclosed in February 2021, with no vendor patch, added to CISA’s Known Exploited Vulnerabilities catalogue only in March 2026. For historical scale, the 2023–24 Unitronics campaign compromised 75 controllers.

Assessment: Search-engine freshness signals are misdating a great deal of this week’s cyber reading, and the advisory is the clearest case: a federal document eight days old is being read as a same-day response to Minnesota, which inverts the sequence and flatters the warning. Two figures travelling through this story should not be charted yet. The 5,200 internet-exposed Rockwell controllers globally and 3,900 in the United States are attributed to Censys via a secondary write-up, and Tenable’s estimate that roughly 60 affiliated pro-Iranian groups have absorbed CyberAv3ngers techniques is likewise reaching readers second-hand. Neither primary publication has been read. A vendor inference repeated three times is still a vendor inference.