Joint Advisory AA26-231A · 19 August 2026 NSA · CISA · FBI · DOE · EPA Siemens S7 Series PLCs Defending Against an Active Threat
CISA · AA26-231A, 2026 “There is an active threat targeting Internet-exposed Siemens S7 Series PLCs.”
CYBERSECURITY MASTERMIND · HOT SEAT
When a machine fails in the factory
Does it make a sound?
THE PREMISE
All three assume no adversary.
Internet-exposed devices running S7comm
On the 19th of August 2026 the NSA, CISA, the FBI, the Department of Energy and the EPA signed AA26-231A. It names a product line and it names a method. It declines to name an actor.
The barrier that kept this rare was never access to the protocol.
It was that adversaries no longer need decades of ICS expertise to understand S7comm. That is the barrier the advisory says has come down.
THE STRUGGLE
As a cybersecurity consultant, you are invited into an OT assessment.
You hold the network diagram showing the exposed port through the DMZ.. If we are subject to a possible compromise, according to documentation we should update S7 firmware and TIA Portal/STEP 7 to current versions. The room nods. How should you respond?
Which port should we monitor, or block from the public Internet?
THE SHARED OBJECTIVE
THE ADVISORY · WHO IS IN RANGE
Each of these sectors is at risk as a target.
ReconnaissanceCapability development damage
THE DMZ · WHAT ANSWERS
Check for the listening port 102
scan@node-7:~$ masscan 0.0.0.0/0 -p102 --rate 100000 --excludefile exclude.conf
rate 100.00-kpps · 0 probed · 0:00:00 elapsed
DISCOVERED · OPEN 102/TCPFive addresses answered on port 102. The third is this deck’s own DMZ address.
102/tcpopen198.51.100.12
102/tcpopen198.51.100.140
102/tcpopen203.0.113.11YOUR DMZ
102/tcpopen198.51.100.58
102/tcpopen198.51.100.201
scan@node-7:~$ nmap -Pn -p102 --script s7-info -oX loot.xml 203.0.113.11
1 host up · identity returned · written to loot.xml
HOW IT ANSWERED
Press Spacebar or click Mouse to continueTap the screen to continue
