The July 2026 refresh of joint advisory AA26 097A names a wider set of US industrial vendors and devices the same Iranian affiliated crews are now probing.
CISA, the FBI, and NSA updated joint advisory AA26-097A in July 2026 to name a wider set of US vendors and devices the same Iranian-affiliated crews are now probing. The advisory flags reconnaissance, not a strike. Operators can use the lead time.
Programmable logic controllers, or PLCs, are the small ruggedized computers that run valves, pumps, and conveyor belts inside factories, water plants, and power stations. The category falls under "operational technology," or OT, the industrial cousin of office IT that most cybersecurity coverage is built around. OT is what makes the difference between a phishing email and a tank overflow: a phishing email can embarrass a company, a manipulated PLC can move a river.
The history of this actor set is a story of widening scope. In 2023, a group calling itself CyberAv3ngers hit Israeli-made Unitronics Vision Series PLCs at US water utilities by using the default password the devices ship with. By 2024, the same crew had moved past credentials to custom malware that could remotely operate water and fuel management systems, per the FBI's IC3 mirror of the advisory. In April 2026, The Register reported the next step: Rockwell Automation and Allen-Bradley PLCs at US water and energy facilities. Check Point Research has tied the same actor set to Israeli targets, suggesting the scope is not US-specific.
The July 2026 refresh formally acknowledges a widening probe surface. Iranian-affiliated crews are now scanning more vendors, more device families, more sectors. The Register's July 23 piece calls it "more flavors of US industrial kit." That is reconnaissance, the cheapest and most patient stage of an attack, and the one that gives defenders the most lead time if they choose to use it.
The lead time is the asymmetry. Adversaries can spend months mapping a plant from the outside. Defenders often cannot answer a basic question, which assets are reachable from the internet, in less than a week. The advisory's value is not its fear factor; it tells operators what the probes are looking for, so they can audit external exposure of OT assets before a more serious event lands. The reason OT visibility lags is structural: a Windows laptop shows up in a vulnerability scan the day it joins the network, a PLC that has run the same program for fifteen years often shows up only when something breaks. Reconnaissance on the adversary's side runs at a different cadence than inventory on the defender's side.
Two practical moves follow. First, treat the indicators in the advisory as a cross-sector asset. A water utility seeing Unitronics scans should expect a food manufacturer nearby to see the same. Second, map every PLC and engineering workstation that is reachable from the corporate network, then shrink that map. Reconnaissance runs out of room when the visible surface does. The fuller indicator list tied to the July update is the next test of how wide the new scope really is.