Historical intelligence backfill. This assessment covers reporting originally published on 2026-08-22 and was added to the RWP archive on 2026-09-07.
AA26-231A — five U.S. agencies on Siemens S7, snap7, and AI-written S7comm scripts
Week of 15–22 August 2026. NSA/CISA/FBI/DOE/EPA: active threat to S7-200 through S7-1500, port 102, python-snap7, scripts dressed as monitoring tools. Recon and capability development — not a confirmed U.S. process-manipulation event in the advisory text RWP is using.
Bottom line up front
CONFIRMED 19 August 2026, AA26-231A — NSA, CISA, FBI, DOE, EPA. Active threat to Siemens S7-200, S7-300 (314/315/317), S7-400, S7-1200 (1211C–1217C), S7-1500 including F-series safety. Actors scan Censys/ZoomEye for TCP/102, then use AI-assisted Python around snap7.dll / python-snap7 to read/write memory, config, and ladder logic over S7comm, masquerading as monitoring tools. Sectors named: critical manufacturing, energy, water, chemical, food, commercial facilities; S7 also in the DIB.
The agencies frame this as persistent reconnaissance and capability development to prepare for operational effects. AI “dramatically reducing the technical expertise and time required” is their wording. RWP does not independently re-verify in-the-wild process manipulation for this backfill week. This is not a CVE-of-the-week and it is not a replacement for AA26-097A (engineering-client abuse against internet PLCs). It is a second, Siemens-specific hunt.
OT threat posture
Internet-reachable S7comm is now a joint-advisory hunt, not a blog hypothesis.
1. Most significant development
AA26-231A. Inventory S7, pull 102 off the internet, hunt snap7 on engineering workstations.
2. Adversary / campaign activity
USG: active targeting of those S7 families. Attribution beyond “threat actors” is not something this weekly invents. AA26-097A Iran-affiliated activity remains a separate CONFIRMED thread (Rockwell/Schneider/Siemens engineering software).
3. Vulnerabilities and active exploitation
No new CVE is required to speak S7comm to an exposed CPU. The “exploit” is the protocol plus a library engineers already use.
4. ICS / SCADA impact
CONFIRMED as USG: recon capability including logic read/write. UNKNOWN this week: a named U.S. plant with confirmed unauthorized logic change tied to this advisory.
5. IT-to-OT exposure
Port 102 on WAN. Python + snap7 on jump hosts. AI-generated “monitoring” tools in the same directory as TIA Portal.
6. Sector impact
Water and energy are in the byline because EPA and DOE signed. Manufacturing is the volume install base.
7. Defensive priorities
- No S7 on the public internet.
- Block/monitor 102 at the perimeter; anomalous S7comm outside maintenance windows.
- Hunt python-snap7 / snap7.dll on non-engineering boxes.
- Known-good project compare — same control as AA26-097A.
8. What changed from last week
ICS Patch Tuesday and Winnipeg HVAC were last week. This week USG named the Siemens installed base as an active threat.
9. What OT defenders should watch next
A follow-on with a named victim or a CVE train. UK small-operator generation (disclosed the following days) is availability, not this S7 script.
10. RWP assessment
Confidence: High on the advisory text. Medium on “AI wrote the exploit” as a briefing slogan — the operational fact is snap7 + exposed 102. Do not wait for ICS-specific malware.
Historical intelligence backfill of the week ending 22 August 2026; added 7 September 2026.
Sources
- CISA — AA26-231A Defending against an active threat to Siemens S7
- Defcon Level — U.S. agencies Siemens S7 advisory 19 August 2026
- BlackBerry — Siemens S7 what water utilities need to know
- CISA — AA26-097A Iran-affiliated PLC exploitation (prior spine)