Historical intelligence backfill. This assessment covers reporting originally published on 2026-08-08 and was added to the RWP archive on 2026-09-07.
OT this week was still internet PLCs — FBI/EPA water, then firmware you extract with the vendor tool
Week of 1–8 August 2026. The 30 July FBI/EPA seven-state water PSA was still the incident. Nozomi's PLC firmware-extraction note showed why “air-gapped” controllers are not a binary.
Bottom line up front
CONFIRMED This week did not add a new named ICS malware family. The live OT incident class was still the 30 July FBI/EPA public service announcement: internet-facing MicroLogix in U.S. water systems, seven states, IP and password changes, some degraded operations. That sits on the same evidence spine as AA26-097A (Studio 5000 / Control Expert / TIA Portal against internet PLCs). Nozomi's 6 August firmware-extraction write-up is research, not a campaign: if you can talk the programming protocol, you can often pull native firmware without a 0-day. Tengu (27 July) is Mirai-derived IoT persistence — CONFIRMED as botnet research, not a plant-floor payload.
Do not upgrade a water billing or HVAC story from adjacent weeks into this week's lead. Do not call Tengu ICS malware.
OT threat posture
Exposure and engineering-path abuse remain higher confidence than novel ICS malware.
1. Most significant development
The water PSA was eight days old and still the thing a utility CISO could brief without inventing a wiper.
2. Adversary / campaign activity
Iran-affiliated internet-PLC activity: USG (AA26-097A). FBI/EPA: USG. UNKNOWN a new 1–8 August victim with confirmed ladder-logic change in primary reporting RWP reviewed for this backfill.
3. Vulnerabilities and active exploitation
The week's technical note is firmware extraction via the same channel you use to program the box — compensating control is who is allowed to speak that protocol, not a CVE number in this weekly.
4. ICS / SCADA impact
CONFIRMED degraded water operations in the July PSA. No CONFIRMED new loss-of-control event dated this week.
5. IT-to-OT exposure
Programming laptops, vendor VPNs, and internet 44818/102/502. Tengu is a reminder that cameras and DVRs on the same WAN as a plant are botnet fuel, not FrostyGoop.
6. Sector impact
Water/wastewater: PSA. Manufacturing: still AA26-097A engineering clients. Do not flatten IoT botnets into those sectors.
7. Defensive priorities
- Internet-facing PLC eradication.
- Known-good project files (AA26-097A).
- Treat programming interfaces as privileged as RDP.
- IoT cameras off the OT VLAN.
8. What changed from last week
This is an archive week: water PSA still dominant; firmware-extraction research landed; no new joint advisory.
9. What OT defenders should watch next
ICS Patch Tuesday and CISA's mid-August advisory stack. Dragos Q2 ransomware numbers.
10. RWP assessment
Confidence: High that this week is hygiene plus research. Low that a new OT malware family dropped.
Historical intelligence backfill of the week ending 8 August 2026; added 7 September 2026.