Multiple high-confidence government advisories confirm active, cross-sector targeting of industrial control systems and their perimeters. Siemens S7-200/300/400/1200/1500 PLCs are currently being targeted with AI-assisted tooling to probe and manipulate S7comm, elevating immediate operational risk—especially for Water/Wastewater—if devices are exposed or poorly segmented. CISA Advisory
A destructive December 2025 energy-sector incident in Poland leveraged a misconfigured private APN to access OT; the follow-up report highlights a repeatable, high-risk pathway from cellular gateways into turbines and process-water systems—underscoring the need to harden private APN designs and isolate cellular-connected OT. Supporting Report
Iranian-affiliated actors have actively exploited internet-exposed PLCs and vendor engineering tools across U.S. infrastructure (ports 44818/2222/102/502), with techniques to alter logic, disable alarms, and manipulate HMI data, creating realistic pathways to unsafe states if basic access control and segmentation are absent. CISA Advisory
Ransomware operators (Gunra/Conti-derivative) are exploiting vulnerable VPN gateways (e.g., FortiGate) and valid accounts for full domain compromise and data theft before encryption—raising OT spillover risk where identity and remote access also service ICS jump paths. CISA Advisory
New and actively exploited identity and CI/CD weaknesses (Keycloak account takeover; TeamCity and Gitea KEV entries) amplify supply-chain and identity-perimeter risk that can indirectly impact OT environments through tampered artifacts and compromised SSO. View Article CISA KEV
OT gateways and EVSE remain high-value: Siemens SIMATIC IoT2050 Advanced has a critical unauthenticated Node‑RED RCE path; recent CISA bulletins detail unauthenticated RCE and unsafe update flaws in EV chargers with credible service disruption impact—prioritize isolation, patching, and OCPP hardening. ICS Advisory CISA Bulletin
Immediate risk to Water/Wastewater and industrial operations where TCP/102 is reachable or protections disabled.
OT access achieved through cellular APN path; turbine and process‑water system disruption confirmed.
Read/write access via exposed PLC protocols and engineering tools; risk of alarm disablement and unsafe states.
Full domain compromise with exfiltration; high spillover potential to ICS jump paths if segmentation is weak.
Unauthenticated code execution on industrial gateways; isolate OT DMZ and harden/patch Node‑RED.
Targeting across U.S. sectors; block TCP/102; enable protection levels.
Misconfigured APN enabled OT access and disruption.
Unauthenticated RCE on industrial gateway; patch V4.3.4.1+.
Double‑extortion; IT–OT pivot risk via identity/jump paths.
Hooks abuse to run shell commands; audit pipelines.
Active exploitation; apply Oracle CPU; hunt for shells.
Unauthenticated password reset; immediate patching required.
Harden routers; block WAN admin; egress filtering.
SNMP/SMI misuse; disable SMI, migrate to SNMPv3 authPriv.
Patch ZCS, revoke app passwords & 2FA scratch codes.
Zero‑days delivered malware via meetings; patch & verify installers.
No actionable OT threat intelligence; monitor only for context.
Low OT relevance (e.g., WhatsApp features, audio fingerprinting reports).
No direct OT/ICS linkage (e.g., Emacs fonts, Carbone zip‑bomb).