Joint Advisory AA26-231A · 19 August 2026 NSA · CISA · FBI · DOE · EPA Siemens S7 Series PLCs Defending Against an Active Threat

CISA · AA26-231A, 2026 “There is an active threat targeting Internet-exposed Siemens S7 Series PLCs.”

CYBERSECURITY MASTERMIND · HOT SEAT

Failures happen by chance. Attacks do not.

When a machine fails in the factory

Does it make a sound?

THE PREMISE

All three assume no adversary.

SOAn attacker reads that same list looking for what can be turned against you. A failure is an opportunity, and so is a setting the watchdog timer will never fault on.
THEREFOREUnnamed failure modes never make the chart.

Internet-exposed devices running S7comm

On the 19th of August 2026 the NSA, CISA, the FBI, the Department of Energy and the EPA signed AA26-231A. It names a product line and it names a method. It declines to name an actor.

The target, the PLC unit.Siemens S7 Series PLCs. Specifically targeting U.S. installations across critical infrastructure sectors.
The actor and the advantage.AI-augmented threat actors. Adversaries use AI-assisted scripting to dramatically lower the technical barrier, generating exploitation scripts disguised as legitimate monitoring tools, built on snap7.

The barrier that kept this rare was never access to the protocol.
It was that adversaries no longer need decades of ICS expertise to understand S7comm. That is the barrier the advisory says has come down.

THE STRUGGLE

As a cybersecurity consultant, you are invited into an OT assessment.

You hold the network diagram showing the exposed port through the DMZ.. If we are subject to a possible compromise, according to documentation we should update S7 firmware and TIA Portal/STEP 7 to current versions. The room nods. How should you respond?

THE LESSONAs a cybersecurity professional you discover the DMZ is exposed to the public Internet, through a misconfiguration or through a legacy integration an operator still needs.

Which port should we monitor, or block from the public Internet?

THE SHARED OBJECTIVE

Different sectors. Same objective: operational integrity.

THE ADVISORY · WHO IS IN RANGE

Each of these sectors is at risk as a target.

Critical Manufacturing
Energy
Water and Wastewater
Chemical
Food and Agriculture
Commercial Facilities
Defense Industrial Basealso at risk, not most targeted
THE VECTORInternet-exposed port 102. Attackers leverage scanning services, Censys and ZoomEye, to locate unpatched, Internet-exposed devices running S7comm.
THE REALITYActive, not theoretical. This is ongoing reconnaissance and capability development. Left unprotected, compromise leads to damage and downtime.

ReconnaissanceCapability development damage

THE DMZ · WHAT ANSWERS

Check for the listening port 102

ot-jump · reconstruction, not a live plant
analyst@ot-jump:~$ ip -br addr showeth0 UP 10.20.0.14/24 eth1 UP 203.0.113.9/28 wg0 DOWN
analyst@ot-jump:~$ nmap -Pn -p 102 --open 203.0.113.0/28Nmap scan report for 203.0.113.11 Host is up (0.0031s latency). PORT STATE SERVICE 102/tcp open iso-tsap Nmap done: 16 IP addresses (1 host up) scanned in 4.21s
analyst@ot-jump:~$ nmap -Pn -p 102 --script s7-info 203.0.113.11| s7-info: | Module: 6ES7 315-2EH14-0AB0 | Version: 3.2.6 | System Name: SIMATIC 300(1) |_ Module Type: CPU 315-2 PN/DP
THE ANSWERPort 102. The advisory does not ask for it to be watched. It asks for it to be blocked at the perimeter, entirely.

HOT SEAT
1 / 17

Press Spacebar or click Mouse to continueTap the screen to continue

← → or space · P pause · ctrl+M exhibit tap to advance · long press for video
PCDrama
Click to beginTap to play
CISA · AA26-231A · 2026 Audio lockedPress to unlockAudio unlocked