Historical intelligence backfill. This assessment covers reporting originally published on 2026-08-22 and was added to the RWP archive on 2026-09-07.

OT Intelligence · OT

AA26-231A — five U.S. agencies on Siemens S7, snap7, and AI-written S7comm scripts

Week of 15–22 August 2026. NSA/CISA/FBI/DOE/EPA: active threat to S7-200 through S7-1500, port 102, python-snap7, scripts dressed as monitoring tools. Recon and capability development — not a confirmed U.S. process-manipulation event in the advisory text RWP is using.

RWP Ventures · 2026-09-07 · event 2026-08-22 · 2 min read · priority 8.8

Bottom line up front

CONFIRMED 19 August 2026, AA26-231A — NSA, CISA, FBI, DOE, EPA. Active threat to Siemens S7-200, S7-300 (314/315/317), S7-400, S7-1200 (1211C–1217C), S7-1500 including F-series safety. Actors scan Censys/ZoomEye for TCP/102, then use AI-assisted Python around snap7.dll / python-snap7 to read/write memory, config, and ladder logic over S7comm, masquerading as monitoring tools. Sectors named: critical manufacturing, energy, water, chemical, food, commercial facilities; S7 also in the DIB.

The agencies frame this as persistent reconnaissance and capability development to prepare for operational effects. AI “dramatically reducing the technical expertise and time required” is their wording. RWP does not independently re-verify in-the-wild process manipulation for this backfill week. This is not a CVE-of-the-week and it is not a replacement for AA26-097A (engineering-client abuse against internet PLCs). It is a second, Siemens-specific hunt.

OT threat posture

Internet-reachable S7comm is now a joint-advisory hunt, not a blog hypothesis.

1. Most significant development

AA26-231A. Inventory S7, pull 102 off the internet, hunt snap7 on engineering workstations.

2. Adversary / campaign activity

USG: active targeting of those S7 families. Attribution beyond “threat actors” is not something this weekly invents. AA26-097A Iran-affiliated activity remains a separate CONFIRMED thread (Rockwell/Schneider/Siemens engineering software).

3. Vulnerabilities and active exploitation

No new CVE is required to speak S7comm to an exposed CPU. The “exploit” is the protocol plus a library engineers already use.

4. ICS / SCADA impact

CONFIRMED as USG: recon capability including logic read/write. UNKNOWN this week: a named U.S. plant with confirmed unauthorized logic change tied to this advisory.

5. IT-to-OT exposure

Port 102 on WAN. Python + snap7 on jump hosts. AI-generated “monitoring” tools in the same directory as TIA Portal.

6. Sector impact

Water and energy are in the byline because EPA and DOE signed. Manufacturing is the volume install base.

7. Defensive priorities

  1. No S7 on the public internet.
  2. Block/monitor 102 at the perimeter; anomalous S7comm outside maintenance windows.
  3. Hunt python-snap7 / snap7.dll on non-engineering boxes.
  4. Known-good project compare — same control as AA26-097A.

8. What changed from last week

ICS Patch Tuesday and Winnipeg HVAC were last week. This week USG named the Siemens installed base as an active threat.

9. What OT defenders should watch next

A follow-on with a named victim or a CVE train. UK small-operator generation (disclosed the following days) is availability, not this S7 script.

10. RWP assessment

Confidence: High on the advisory text. Medium on “AI wrote the exploit” as a briefing slogan — the operational fact is snap7 + exposed 102. Do not wait for ICS-specific malware.

Historical intelligence backfill of the week ending 22 August 2026; added 7 September 2026.

Sources

  1. CISA — AA26-231A Defending against an active threat to Siemens S7
  2. Defcon Level — U.S. agencies Siemens S7 advisory 19 August 2026
  3. BlackBerry — Siemens S7 what water utilities need to know
  4. CISA — AA26-097A Iran-affiliated PLC exploitation (prior spine)