The Advisory Being Read as This Week’s Warning Was Published in April and Updated on 22 July
Most of the cyber material circulating with the water story predates the water story. The dates matter, because the sequencing is the strongest part of the case and the recirculated numbers are the weakest.
CISA Advisory AA26-097A, “Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure,” was published in April 2026 and updated on 22 July. It is being cited this week in framings that read as new. The 22 July update widened the described tradecraft to include use of Dropbear SSH on victim modems for remote access over port 22, and abuse of vendor configuration software including Rockwell Automation’s Studio 5000 Logix Designer, Schneider Electric’s EcoStruxure Control Expert and Siemens' automation suite. Fox News noted CISA had warned about exposed controllers “weeks before” the Minnesota utilities were hit. That chronology — advisory in April, update 22 July, intrusions 26–27 July, federal warning 30 July — is the durable spine of the week, and it holds regardless of whether the Iran attribution survives.
The recirculated figures are less disciplined. Iran’s nationwide blackout ran from 8 January and was partially lifted on 26 May; NetBlocks put it at more than 2,093 hours, or 88 days, the longest of its kind. Other counts in circulation say roughly 90 days, and Wikipedia’s entry calls the same event four months and eighteen days. Those cannot all be true; only the NetBlocks figure should travel, and with the label attached. France 24 reported that restoration meant home broadband in some areas while mobile internet stayed largely blocked, leaving users on VPNs. Separately, Israel’s National Cyber Directorate director general, Brig. Gen. (res.) Yossi Karadi, said on 29 June that Israel recorded 4,800 Iranian attacks in June 2026 against 1,600 in June 2025 — five weeks old, self-reported by the defending state, with no published definition of an “attack.”
One in-window number is clean. The Internet Society’s Pulse tracker recorded 11 ongoing shutdowns as of 3 August 2026. The same page carries a second aggregate we could not read in full and are therefore not publishing. SoCRadar’s Iran–Israel dashboard carries a timestamp from around 2 August, but it is a continuously updated compilation of hacktivist claims that bills itself as curated for journalists, and some of its lines — that activity from Islamic-aligned groups “is expected to be lower today” — are forecasts rather than events. CISA’s index shows Alerts dated 3 and 4 August whose subject matter we could not retrieve. We also obtained nothing on Sahel connectivity in this window, which is a gap in this desk, not an absence of events.
Assessment: Date-laundering is the cheapest form of escalation available in a cyber story: nothing has to be invented, only re-timestamped. It works because vendor dashboards and standing advisories update continuously, so a page touched on 2 August looks like an event on 2 August. The discipline is to separate the document’s date from the incident’s date and to say which one you have. Note also which numbers are self-certified. The INCD’s threefold rise, an aggregator’s hacktivist tally and a governor’s statement about what the White House knows are all claims by interested parties. The 22 July update is a record.