MEFILES · Edition No. 23Today's edition · Archive · RSS
Seven files · One region · Zero illusions
Digital Front Monitor The full edition of August 6, 2026 →
Old Paper, New Week

The Advisory Being Shared as This Week’s Federal Response Was Written in April

CISA’s AA26-097A carries the strongest government attribution to Iranian-affiliated actors in the file. It was published in April 2026 and last updated 22 July — before the water intrusions it is being used to explain.

AA26-097A, “Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure,” was originally published in April 2026 and updated on 22 July. It predates the Minnesota intrusions of 26–27 July and the FBI/EPA alert of 30 July, yet it is circulating this week as the federal answer to them. Its substance is genuinely load-bearing: the July update adds detection guidance for malicious changes in reusable code modules in Rockwell Automation PLC programs and widens the manufacturer scope to Schneider Electric, Siemens and “possible other PLC manufacturers.” Named sectors are Water and Wastewater Systems, Energy, and Government Services and Facilities including local municipalities. The activity is dated to “at least March 2026.”

The most consequential line in the 22 July addition is a single field observation. At one US victim, the FBI observed the actors download a malicious project file to a targeted PLC using configuration software; analysis indicated the file retained ladder logic for downstream function but added logic overriding the instruction sets responsible for maintaining safe operating parameters. That is a safety-interlock override, on the record from a government agency rather than a vendor blog, and it is the only documented basis for treating water-sector intrusions as a risk to life rather than an availability problem. It is also worth stating plainly what has not been shown: nothing in the current wave of incidents has been demonstrated to have used that capability. Every confirmed case this window ends in manual operation, brief pressure loss, or lost visibility.

Assessment: This is the desk’s recurring failure mode, and it is not confined to government documents. SOCRadar’s Iran–Israel dashboard was returned by search as four days old while its own page says the map data was last updated in March 2026. Halcyon’s Iranian-tactics page carries no date at all. Trellix’s “Iranian Cyber Capability 2026” scopes itself to March. Rolling URLs on live-looking pages are being read as live incident data by newsrooms working fast. The test is simple and almost nobody applies it: find the publication date inside the document, not the one the search engine assigns it.