← BACK TO FEED
TAG

ics security6 articles

100+ Water Systems Hit in July Cyberattacks — CISA Finally Puts a Number On It

In July 2026, CISA identified cyberattacks targeting over 100 internet-exposed water and wastewater systems across at least 12 U.S. states, linked to Iranian threat actors who exploited programmable logic controllers (PLCs) connected directly to cellular modems. While the attacks caused no significant disruption, they have raised serious concerns about the vulnerability of critical infrastructure. In response, CISA has issued updated guidance urging organizations to reduce their internet attack surface by auditing exposed systems, enforcing strong authentication, applying security updates, and securing remote access through protected gateways.

27 Aug 2026

AI-Assisted Hacking Puts Siemens PLCs in US Critical Infrastructure Squarely in the Crosshairs

US government agencies, including the NSA, CISA, FBI, EPA, and DOE, have issued a joint advisory warning that unidentified hackers are using AI to develop exploitation scripts targeting Siemens PLCs across critical infrastructure sectors such as energy, water, and manufacturing. The attackers combine AI-generated tools with open-source industrial automation libraries to manipulate PLC memory, configuration data, and ladder logic, while also conducting persistent reconnaissance that suggests preparation for future disruptive attacks. Agencies are urging organizations to apply the latest patches, restrict internet exposure of PLCs, and implement strong access controls and ICS monitoring solutions.

21 Aug 2026

AI-Assisted PLC Attacks on Critical Infrastructure Are No Longer Hypothetical

Five US federal agencies have issued a joint alert warning that attackers are actively using AI-generated scripts and open-source industrial libraries to hack internet-exposed Siemens S7 Series programmable logic controllers (PLCs) across critical infrastructure sectors including water, energy, and manufacturing. Iran-affiliated actors are suspected to be behind the campaign, which has already disrupted water systems in at least 12 US states. Authorities warn that AI is lowering the technical barrier for such attacks and urge critical infrastructure operators to immediately patch systems, remove PLCs from internet exposure, and monitor for anomalous network behaviour.

20 Aug 2026

PLCs on the public internet are an open goal for attackers, says ex-NSA chief

Retired General and former NSA chief Paul Nakasone has warned that water system controllers should not be connected to the internet, following suspected Iranian cyberattacks on water facilities across at least 12 US states. Speaking at DEF CON, he highlighted the enormous attack surface posed by around 50,000 underfunded and understaffed water municipalities, calling for higher cybersecurity standards and a collaborative defence approach. While neither the FBI nor the Trump administration has officially attributed the attacks to Iran, security researchers and Nakasone himself consider Iranian involvement highly likely given the country's history and demonstrated capability in targeting such infrastructure.

8 Aug 2026

Iranian Hackers Suspected Behind Wave of Cyberattacks Hitting Minnesota Water Systems

Cyberattacks targeted over 30 water systems across Minnesota on Sunday and Monday, with authorities including the FBI investigating the source amid warnings that Iranian hackers have been actively targeting water and critical infrastructure systems. While some communities experienced brief disruptions, such as the city of Braham temporarily asking residents to conserve water, there were no reported impacts on water quality or service for residents. Investigators have noted similarities across the incidents in timing and technology targeted, but have not yet confirmed whether a single culprit was responsible or publicly attributed the attacks to Iran.

2 Aug 2026

AI-Directed Hackers Ransacked Mexican Government Databases — Then Got Stumped by a Login Screen

Between December 2025 and February 2026, a small, unknown hacking group carried out one of the first truly AI-directed cyberattack campaigns, using Claude Code to orchestrate attacks against at least nine Mexican government entities and stealing millions of sensitive records. However, when the attackers attempted to move from IT into operational technology (OT) systems at a Monterrey water utility, the AI-guided attack was stopped by a simple SCADA gateway login screen, failing to crack it despite multiple password-spraying attempts. The incident highlights both the growing power of AI in lowering the barrier for sophisticated cyberattacks and its current limitations — demonstrating that strong fundamental OT security controls, such as network segmentation and secure remote access, remain effective defences even against AI-driven threats.

20 May 2026