Historical intelligence backfill. This assessment covers reporting originally published on 2026-08-08 and was added to the RWP archive on 2026-09-07.

OT Intelligence · OT

OT this week was still internet PLCs — FBI/EPA water, then firmware you extract with the vendor tool

Week of 1–8 August 2026. The 30 July FBI/EPA seven-state water PSA was still the incident. Nozomi's PLC firmware-extraction note showed why “air-gapped” controllers are not a binary.

RWP Ventures · 2026-09-07 · event 2026-08-08 · 2 min read · priority 8.3

Bottom line up front

CONFIRMED This week did not add a new named ICS malware family. The live OT incident class was still the 30 July FBI/EPA public service announcement: internet-facing MicroLogix in U.S. water systems, seven states, IP and password changes, some degraded operations. That sits on the same evidence spine as AA26-097A (Studio 5000 / Control Expert / TIA Portal against internet PLCs). Nozomi's 6 August firmware-extraction write-up is research, not a campaign: if you can talk the programming protocol, you can often pull native firmware without a 0-day. Tengu (27 July) is Mirai-derived IoT persistence — CONFIRMED as botnet research, not a plant-floor payload.

Do not upgrade a water billing or HVAC story from adjacent weeks into this week's lead. Do not call Tengu ICS malware.

OT threat posture

Exposure and engineering-path abuse remain higher confidence than novel ICS malware.

1. Most significant development

The water PSA was eight days old and still the thing a utility CISO could brief without inventing a wiper.

2. Adversary / campaign activity

Iran-affiliated internet-PLC activity: USG (AA26-097A). FBI/EPA: USG. UNKNOWN a new 1–8 August victim with confirmed ladder-logic change in primary reporting RWP reviewed for this backfill.

3. Vulnerabilities and active exploitation

The week's technical note is firmware extraction via the same channel you use to program the box — compensating control is who is allowed to speak that protocol, not a CVE number in this weekly.

4. ICS / SCADA impact

CONFIRMED degraded water operations in the July PSA. No CONFIRMED new loss-of-control event dated this week.

5. IT-to-OT exposure

Programming laptops, vendor VPNs, and internet 44818/102/502. Tengu is a reminder that cameras and DVRs on the same WAN as a plant are botnet fuel, not FrostyGoop.

6. Sector impact

Water/wastewater: PSA. Manufacturing: still AA26-097A engineering clients. Do not flatten IoT botnets into those sectors.

7. Defensive priorities

  1. Internet-facing PLC eradication.
  2. Known-good project files (AA26-097A).
  3. Treat programming interfaces as privileged as RDP.
  4. IoT cameras off the OT VLAN.

8. What changed from last week

This is an archive week: water PSA still dominant; firmware-extraction research landed; no new joint advisory.

9. What OT defenders should watch next

ICS Patch Tuesday and CISA's mid-August advisory stack. Dragos Q2 ransomware numbers.

10. RWP assessment

Confidence: High that this week is hygiene plus research. Low that a new OT malware family dropped.

Historical intelligence backfill of the week ending 8 August 2026; added 7 September 2026.

Sources

  1. FBI/EPA — 30 July 2026 WWS internet-facing PLC PSA
  2. CISA — AA26-097A update 22 July 2026 Iran-affiliated PLC exploitation
  3. Nozomi — PLC firmware extraction via programming interface (6 August 2026)
  4. Nozomi — Tengu Mirai-derived IoT (27 July 2026)