Skip to main content

folkfox

Skip to main content
Skip to content
THREAT LANDSCAPE

Five Agencies, One Warning, and Not a Single Number

A fox does not bolt at the first rustle in the undergrowth. It waits, ears flat, to hear which way the noise is walking. Five agencies rustled the hedgerow this week, and everyone selling into ot cybersecurity heard a warning with nothing in it to weigh.

Quick answerFive US agencies warned on 19 August 2026 that threat actors pair AI-assisted scripting with an open source library to reach internet-exposed Siemens S7 PLCs. The advisory publishes no numbers, so ot cybersecurity teams must bring their own.
Section 01

What five agencies said, and what they left unmeasured#

0

quantified observations published in the five-agency advisory

CISA AA26-231A

On 19 August 2026 the NSA, CISA, FBI, DOE and EPA put five names to one document, advisory AA26-231A, titled Defending Against an Active Threat to Siemens S7 Series PLCs. Five authoring agencies is a serious signal on its own, and the sectors it names are the ones that hurt when they stop: Critical Manufacturing, Energy, Water and Wastewater, Chemical, Food and Agriculture, and Commercial Facilities. Anyone working in ot cybersecurity should read it twice, once for the threat and once for the silence.

The method is described with unusual precision. Threat actors are said to be pairing open source industrial automation libraries, snap7.dll and python-snap7, with AI-assisted scripting to build custom tools that mimic legitimate OT monitoring software. Reconnaissance runs through commercial scanning services, and the agencies name them: "Using Internet scanning services (e.g., Censys, ZoomEye) to identify Internet-exposed or insufficiently segmented Siemens S7 Series PLCs". The quarry is anything reachable and poorly segmented, which is a wider hedgerow than most operators enjoy admitting.

Intent is stated as an assessment rather than an observation. The authoring agencies assess the pattern is "likely intended as persistent reconnaissance in targeted sectors and facilities to develop capabilities and prepare to cause operational effects". Read that slowly, because it describes reconnaissance, capability development and pre-positioning. No plant is said to have stopped, no water system tampered with, no turbine touched. Every honest ot cybersecurity brief written this week has to hold that line, however tempting the taller headline looks.

No count, no hashes, no dates#

Here is the part the trade press skated past. The advisory carries no quantified observation of any kind: no incident count, no affected-facility count, no indicators of compromise, no hashes, no samples, no timeframe and no named actor. It also publishes no evidence that the scripts were written by AI. That claim rests entirely on government assessment, which is a perfectly legitimate thing for an agency to publish and a genuinely difficult thing for a buyer to budget against on Monday morning.

Be fair about the reasons. Agencies protect sources and methods, and a sanitised warning that arrives early beats a fully evidenced one that arrives after the damage. Even so, two of the mitigations name commercial ICS detection products by brand, which joint advisories seldom do, and those vendors will be quoting the document by Friday. A rival ot cybersecurity firm needs measured ground of its own to stand on, not a louder rendition of the same adjective. That is the same problem NIST handed security teams this morning, in a different register.

u/DrKabanov
Writing exploits for OT infra used to require deep expertise. Now AI makes it dramatically easier by just using publicly available information on these PLCs for initial access, credential access, denial of service, and other objectives.
r/cybersecurity, 20 August 2026View on Reddit

That post is the sector's mood in three sentences: plausible, urgent and unmeasured. Nobody has published a denominator. How many exploitation attempts, against how many devices, across what window, at what success rate, stays unanswered by everyone who holds the telemetry to answer it. Asking for that figure is not scepticism about the threat. It is the difference between a claim a customer can act on and a mood a customer can only absorb.

The disclosure surface CISA has to cover
ot cybersecurity: CISA industrial control system advisories published per year since 2010600400200020102011201220132014201520162017201820192020202120222023202420252026ICS advisories: 20ICS advisories: 69ICS advisories: 81ICS advisories: 85ICS advisories: 103ICS advisories: 143ICS advisories: 137ICS advisories: 174ICS advisories: 194ICS advisories: 204ICS advisories: 225ICS advisories: 370ICS advisories: 371ICS advisories: 371ICS advisories: 409ICS advisories: 481ICS advisories: 331
ICS advisories
Counted by folkfox from CISA's own published sitemap rather than quoted from a CISA statistic: 2026 runs only to 20 August, and the step from 2020 to 2021 is a CISA process change rather than a threat signal.

Set the alert against that disclosure surface and it looks less like a thunderclap and more like weather. The trail runs from 20 advisories in 2010 to 481 in 2025, and this year stands at 331 to 20 August, counted by binning CISA's own sitemap and cross-checked against its published advisory pager. Any ot cybersecurity vendor claiming a sudden inflection has to explain why 2021 stepped and 2013 crawled. Volume here measures what a regulator can process, which is a useful thing to know and a terrible thing to mistake for a threat count.

Section 02

How many are exposed, and what ot cybersecurity can actually count#

Exposure is the one thing in this story anybody can count, and somebody did. In a snapshot dated 30 July 2026, Censys counted 4,117 internet-exposed hosts fingerprinting as Siemens SIMATIC S7-1200, precisely the family the advisory names. That is the figure an ot cybersecurity brief should open with, because it is dated, sourced, reproducible and boring in the way good evidence is always boring.

Reachable from the open internet
Reachable from the open internetics security: internet-exposed industrial hosts by vendor in the Censys snapshot of 30 July 2026Rockwell: 4148Siemens S7-1200: 4117Schneider: 207260004000200004148Rockwell4117Siemens S7-12002072Schneider
Censys counted these hosts in a snapshot dated 30 July 2026, and the Schneider total is vendor-wide rather than PLC-scoped, so it is not strictly comparable with the other two bars.

The other two bars need their footnotes carried with them. The Rockwell count covers hosts that answer EtherNet/IP and identify themselves as Rockwell Automation or Allen-Bradley. The Schneider figure is vendor-wide, with no model or protocol filter applied, and Censys says plainly it should not be read as Schneider PLC exposure. An ics security claim built on that third bar without the footnote is the kind of thing a journalist unpicks in a single email, and the correction outlives the campaign that caused it.

Where the exposure sits, and who carries it#

The geography is stranger than the totals. Greece, Spain, Italy and Austria together account for 86.0% of the exposure in that snapshot, and in each of them the traffic sits mostly on the country's leading mobile carrier rather than a fixed-line or hosting provider. Industrial kit is reaching the public internet through SIM cards. For critical infrastructure security teams that redraws the map completely, because the asset is not in a rack you can walk to, it is on somebody else's mobile network, behind somebody else's support contract.

There is an earlier snapshot too, from 7 April 2026, counting 5,219 hosts globally that answer EtherNet/IP as Rockwell or Allen-Bradley, with Verizon Business alone accounting for 2,564 of them (49.1%) and AT&T Mobility a further 693 (13.3%). Resist the obvious move. Two points four months apart on one query is not a trend, and a fingerprinting change explains a swing that size as neatly as a clean-up campaign does. Plotting 5,219 against 4,148 as a decline sells a slope, not a scada security finding.

One more detail, and it is the strangest thing in the whole pack. That same Censys page carries a line reading: "The following paraphrases the CISA alert as supplied by the user for this report; it was not independently re-fetched from cisa.gov in this session." Those are an AI research pipeline's working notes, left in a published security page. Be precise about what it means. The scan counts are Censys's own instrumentation and they stand. The advisory summary on that page is second-hand by Censys's own admission, and the fair reading stops exactly there.

It matters because it is this week's argument in miniature: an alert about AI-assisted attack tooling, summarised by AI-assisted content, then quoted onward by firms who read the summary rather than the source. Every ot cybersecurity team in that chain had the option to fetch the original, and the few who did have something to say that the rest simply cannot. Provenance is turning into a product feature, which is why our SEO and GEO practice starts with what a page can prove.

Section 03

Does AI actually lower the bar?#

What a measured contest showed
What a measured contest showedot cybersecurity: DARPA AI Cyber Challenge vulnerability discovery and patch rates, 2024 versus 20252024 semifinal2025 finalFound: 37 to 86Found 37%86%Patched: 25 to 68Patched 25%68%
These are synthetic vulnerabilities found and patched by defensive tooling built by funded expert teams inside a contest, not a novice with a chatbot.

Take the AI claim apart gently, because there is real evidence in it. The closest thing to a controlled measurement anybody has is the DARPA AI Cyber Challenge. In the final scored round, teams identified 86% of the competition's synthetic vulnerabilities, up from 37% at the semifinals, and patched 68% of what they identified, up from 25%. Those are published, dated, repeatable numbers, and they belong in your deck with three words carried in the same breath: synthetic, defensive, funded.

The economics are the part worth borrowing. Average cost per competition task came to about $152, patches arrived in an average of 45 minutes, and the competing systems worked through more than 54 million lines of code. Cheap, quick and at scale is a different threat model from clever, and it is the one an ot cybersecurity roadmap should plan for. None of it, though, describes a stranger with a chatbot pointed at a live plant.

ot cybersecurity: a fox raising a hooded lantern to a row of industrial control dials
One dial answers the lantern and the rest of the panel stays dark, which is roughly how much of the picture anybody outside the agencies can see.

Two papers are doing the rounds and both are preprints, which changes how you are allowed to cite them. APIOT, posted 4 May 2026, reports a 90.0% mission success rate on a full attack and remediation cycle across 290 experiment runs, five frontier models, three network topologies and two impairment levels. It runs on a Zephyr RTOS lab testbed over Modbus and CoAP, not the S7comm protocol this advisory concerns, and states no peer review. Interesting, adjacent, and not evidence about Siemens controllers.

MALF, posted 3 October 2025, gets closer to the metal, fuzzing Modbus/TCP, S7Comm and Ethernet/IP with a test case pass rate of 88 to 92%. Deployed in an industrial attack and defence range built for power plants, it found critical vulnerabilities including three zero-day flaws, one of them confirmed and registered by CNVD. A registered zero-day is a genuine result. It is also a preprint, produced by a research team with a testbed, not by an opportunist prowling a mobile network for credentials.

The answer that still holds in March#

So what does an honest ot cybersecurity answer sound like? Roughly this. AI measurably improves vulnerability discovery and patching in controlled settings, run by people who know what they are doing, at costs low enough to change the arithmetic of scale. Whether it does the same for a stranger scanning for exposed S7 devices has not been published by anyone, yet. That sentence survives a hostile question in a budget meeting, and it survives the same question again in March, which is more than most ot cybersecurity claims manage.

Section 04

What the trend lines say, including the one that disagrees#

Pull back to the trend lines and the picture splits into five instruments pointed at five different things. Advisory volume measures disclosure. Incident counts measure what became public. Ransomware group counts measure criminal supply. Surveys measure what practitioners will admit. Vendor telemetry measures what a product blocked. Only one of them points down, and any ot cybersecurity deck that quietly leaves that one out is a deck waiting to be embarrassed by a sharp prospect.

Waterfall Security's 2026 OT Cyber Threat Report goes first because it states its inclusion criteria. Cyber incidents causing physical impacts in heavy industry and critical infrastructure dropped by 25% in 2025, falling from 76 publicly recorded cases in 2024 to 57, against 68 in 2023. Waterfall also reports that 65% of public incident reports in 2025 lacked the detail to conclude how the attack impaired physical operations, and calls its own dataset a conservative estimate that certainly under-reports activity. Nation-state and hacktivist attacks doubled year on year, with 5 of the 14 clearly linked to the invasion of Ukraine.

Using AI to generate exploitation scripts represents an evolution in threat actor capabilities, dramatically reducing the technical expertise and time required to develop working ICS exploitation scripts and malicious tools.
Advisory AA26-231A, five authoring agencies

That is the sentence a quarter of the market will build a campaign on, and it is an assessment rather than a measurement. Both things are true at once, and holding both is the entire craft. A vendor who repeats it without the caveat is one curious journalist away from a bad week. A vendor who dismisses it because the evidence is not public is one incident away from a far worse one.

Dragos tracked 119 ransomware groups aiming at industrial organisations in 2025, up from 80 in 2024, with 3,300 organisations affected. Average ransomware dwell time in OT environments ran to 42 days industry-wide, against an average of 5 days among its own customers with comprehensive OT visibility, which is a customer comparison rather than a market rate. Its blog puts 25% of advisories with no patch or mitigation, 3% of vulnerabilities needing immediate action and 4% actively exploited, while the press release says 26% and 2%, so cite the blog, note the variance, and never pick whichever number flatters the pitch. We wrote about the gap between disclosure and exploitation when the same pattern showed up in IT.

SANS surveyed 330 professionals for its 2025 state of ICS and OT security paper: 22% reported a cybersecurity incident in the past year, 40% of those caused operational disruption, close to 20% took more than a month to remediate, and just 14% felt fully prepared for emerging threats. ENISA examined 4 875 incidents for its 2025 threat landscape and put operational technology threats at 18.2% of them. Different instruments, same direction of travel, and a decent spine for any critical infrastructure security narrative.

Kaspersky points down because it counts commodity malware blocked on Windows machines in industrial estates, while every other row counts incidents, groups or disclosures.
SourceWhat it measuresStated sample
CISA AA26-231AAssessed threat activityNo sample stated
Censys, 30 July 2026Internet-exposed hosts4,117 Siemens S7-1200 hosts
Waterfall 2026Incidents with physical impact57 public cases in 2025
Dragos 2026Ransomware groups hitting industry119 groups, 3,300 affected
SANS 2025Practitioner self-report330 professionals
ENISA ETL 2025Incident share by category4 875 incidents
Kaspersky Q1 2026Malware blocked on Windows ICS hostsTelemetry, sample not disclosed

Then there is Kaspersky ICS CERT, which points the other way and deserves quoting anyway. The share of ICS computers on which malicious objects were blocked has fallen for five straight quarters: 21.9%, 20.5%, 20.1%, 19.7%, and 19.6% in the first quarter of 2026. It is vendor telemetry with no disclosed sample size, and it counts commodity malware stopped on Windows machines in industrial estates, not targeted access to a controller. Set it beside the others without that sentence and it reads as a contradiction. Keep the sentence and it becomes the most persuasive slide you own.

One cost anchor, carefully labelled. The Cyber Monitoring Centre estimates the Jaguar Land Rover incident caused a UK financial impact of £1.9 billion and affected over 5,000 UK organisations, with vehicle production suspended for roughly five weeks. The centre calls that scenario-based analysis rather than confirmed operational data, and the compromise was an IT one with manufacturing consequences, not a PLC attack. Our own read on the quarter when nobody touched the turbine found the same shape.

IBM's X-Force index puts manufacturing at 27.7% of observed incidents for a fifth year running, with vulnerability exploitation the leading cause at 40%, while its 2026 breach-cost study found 62% of AI-driven attacks aimed at critical infrastructure sectors and energy breaches averaging $5.2 million, across 602 organisations surveyed between March 2025 and February 2026. Stack those beside the ot cybersecurity story the advisory tells and the shape is consistent, even though not one of them measures the thing the advisory actually describes.

Section 05

Marketing a security product into a numberless alert#

Monday arrives, the biggest story in your category is an alert with no numbers in it, and three competitors have already published the word unprecedented. Here is the ot cybersecurity move that actually works, and it is not louder: turn up with a measurement where everybody else brought an adjective.

Absence is the opportunity. When a federal document quantifies nothing, the first firm to publish a dated, sourced, reproducible figure becomes the citation everyone else borrows. Not the loudest firm, the most checkable one. That is also how AI answer engines choose now: they lift the passage carrying a number, a date and a link, and leave the adjectives in the undergrowth. Our content marketing work lives on exactly that difference.

Count something yourself. Anyone can bin CISA's published advisory URLs by year, as we did for the chart above, and any vendor with a scanner can count exposed devices across its own customers' address space and publish the total with the date attached. A single honest number a competitor does not hold outperforms a page of fluent scada security prose that any of them could have written, and it costs less than the campaign it replaces.

Watch the failure modes, because every one of them is unforced. Do not let a sales deck turn reconnaissance into an attack. Do not let a designer join two Censys snapshots into a downward slope. Do not quote a preprint without the word preprint, and never quote the DARPA figures without saying the vulnerabilities were synthetic. Each shortcut buys a week of attention and costs a year of trust, and in ot cybersecurity the buyers all talk to each other constantly.

The person you are writing for is an engineering or security lead who has to ask for money on Monday with no incident of their own to point at. Give them a sentence they can repeat in a budget meeting without being asked for a source, and you have done more for the pipeline than any campaign about resilience ever managed. That is cybersecurity marketing done properly, and a sharper brand position is what makes it repeatable rather than lucky. The same discipline saved the story when nobody exploited a single flaw.

The advisory will be superseded, the exposure counts will move, and the AI question will eventually be answered by somebody holding telemetry rather than an assessment. Until then, the ot cybersecurity firms worth hiring are the ones that publish what they measured, name what they did not, and trust the reader to tell the difference. That is a slower prowl than the market wants, and it is the one that still has a den in the morning.

Questions

Frequently asked questions#

What is ot security?

OT security, short for operational technology security, protects the hardware and software that run physical processes: programmable logic controllers, sensors, drives and the networks joining them. It differs from IT security because the priority is safety and continuous operation rather than confidentiality, and a patch window can mean stopping production.

Did the advisory say any plants were actually attacked?

No. AA26-231A describes reconnaissance, capability development and pre-positioning, and says operational effects could follow. It reports no successful disruption at any facility, no incident count and no affected-facility count, so any claim that plants were taken offline goes well beyond what the five authoring agencies published.

How many Siemens PLCs are exposed to the internet?

Censys counted 4,117 internet-exposed hosts fingerprinting as Siemens SIMATIC S7-1200 in a snapshot dated 30 July 2026. Censys is explicit that this describes exposure only and does not confirm that any specific host is a victim of the activity CISA describes, which is the caveat every ot cybersecurity brief should carry with the number.

Is there real evidence that AI lowers the barrier to writing exploits?

There is measured evidence in controlled settings. In the DARPA final, teams found 86% of synthetic vulnerabilities, up from 37%, and patched 68%, up from 25%, at an average task cost near $152. That was defensive tooling built by funded expert teams, not a novice with a chatbot, and the advisory itself publishes no evidence of AI authorship.

What is the difference between ot cybersecurity and ics security?

They overlap heavily. The wider term, ot cybersecurity, covers all operational technology, including building systems, safety instrumented systems and industrial networks. The narrower one, ics security, covers industrial control systems specifically: controllers, SCADA servers and the protocols joining them. Most vendors sell to both audiences and should say plainly which one a claim applies to.

How should a security vendor respond to an advisory with no numbers in it?

Publish a number the advisory lacks. Count exposure in your own telemetry, date it, name the method and its limits, then link the advisory for the qualitative claim. An ot cybersecurity buyer forwarding your page to a finance director needs one checkable figure far more than another paragraph about resilience.

Keep reading

Read more on this topic#

Ready to say something measured while the rest say unprecedented?

Security firms hire folkfox to turn advisories, telemetry and hard-won field numbers into ot cybersecurity content a finance director can check and an answer engine can quote.