Blog

Reading the Two Summer 2026 PLC Joint Advisories Together: Understanding What AA26-097A and the Siemens S7 Advisory Each Cover

Two joint advisories landed within months of each other, both about internet-exposed programmable logic controllers (PLCs). AA26-097A, updated in July 2026, covers Iranian-affiliated actors who exfiltrated project files, overrode safety instruction sets while leaving downstream logic running, and manipulated HMI and SCADA displays. The August 2026 Siemens S7 advisory covers unattributed actors using AI-generated scripts and open source automation libraries to conduct reconnaissance across every S7 family in service. Both warn about the same attack surface.
The diagram below maps them across five categories: attribution, actor activity, scope, detection, and mitigation. Reading any single category shows where the two advisories agree and where they diverge. Attribution moves from a named actor to none at all. Actor activity moves from confirmed manipulation to reconnaissance and pre-positioning. Mitigation moves from recovery actions to preventive hardening. The middle holds what both say, showing that these two advisories overlap in several areas despite their many differences.
Compare by
A is AA26-097A, Iranian-affiliated PLC exploitation. B is the Siemens S7 series advisory, August 2026.
Attribution
A names an actor. B does not. Both name the same enabler: internet exposure plus weak authentication.
Only in A · 3
Iranian-affiliated APT, IRGC CEC lineage
Similar activity to the 2023 CyberAv3ngers campaign
Escalation tracked since at least March 2026
In both · 3
Both warn of active, ongoing targeting
Internet exposure plus weak auth is the enabler
Neither reports a new CVE in the products
Only in B · 3
No attribution provided
Described only as threat actors
No nation-state or group naming
Actor activity
A documents confirmed impact. B documents reconnaissance and pre-positioning. The overlap is write access to controller logic.
Only in A · 4
Confirmed logic manipulation and operator blinding
Project files exfiltrated first, then modified and returned
Safety instruction sets overridden while downstream logic ran on
Project file logic modified and deleted, including AOIs
In both · 3
Write access to logic and data blocks
Ladder logic integrity is the stated concern
Mode and program changes are the traffic to watch
Only in B · 4
Recon and capability development, no impact shared at this time
Leveraging open source industrial automation libraries
AI-generated scripts used to build toolingFirst advisory where AI is a central finding, not a peripheral detail
Tools mimic legitimate OT monitoring solutions
Scope
Siemens S7 and TCP 102 are the common ground. A widens by vendor, B widens by controller family.
Only in A · 3
Rockwell and Schneider alongside Siemens
CompactLogix, Micro850, Modicon M340, S7-1200
Ports 44818, 2222, 502, plus Dropbear SSH on modems
In both · 3
Siemens S7 and TCP 102 in both
Energy plus water and wastewater named in both
NSA, CISA, FBI, DOE, and EPA co-author both
Only in B · 3
All S7 families, S7-200 through S7-1500
Includes F-series safety controllers
Six sectors plus the Defense Industrial Base
Detection
A gives you indicators to search. B gives you behaviors to hunt.
Only in A · 3
21 attacker IPs with first and last seen dates
September 2025 to July 2026 windows for log queries
STIX XML and JSON for SIEM and firewall import
In both · 3
MITRE ATT&CK v19 technique mapping
Verify running logic against known good
Log connections from engineering hosts
Only in B · 3
Five behavioral hunt categories, plus D3FEND
S7comm anomalies, recon patterns, tool artifacts
Off-hours activity, unexpected source countries
Mitigation
A tells you how to recover. B tells you how not to need to.
Only in A · 3
Recovery oriented, four ordered steps
Offline baseline predating the compromise window
Diff AOIs, validate the file, flip to RUN, reimage assets
In both · 3
Baseline hygiene both demand
Patch, remove default creds, require MFA
Restrict programming, hold integrators to it
Only in B · 3
Prevention oriented, seven steps
Inventory, patch, isolate, access, monitor, harden
Gold copy compare only, no restore path
Counts are the distinct points in each region of this comparison, not a measure of either advisory’s length. Both advisories are co-authored by NSA, CISA, FBI, DOE, and EPA. Dotted terms carry a definition on hover or keyboard focus.