OT Intelligence · OT

OT this week was a CISA ICS stack, not a new wiper — internet-facing controllers are still the incident

31 August–7 September 2026. Nine ICS advisories on 3 September plus Rockwell Logix CIP DoS on the 1st. No new Stage 2 ICS malware in public reporting this week. The live threat remains exposed PLCs and engineering paths named in AA26-097A and AA26-231A.

RWP Ventures · 2026-09-07 · 4 min read · priority 8.2

Bottom line up front

CONFIRMED This week’s public OT calendar was vendor/CISA paper, not a named plant-floor malware event. On 1 September CISA posted ICSA-26-244-03 — Rockwell ControlLogix/CompactLogix/GuardLogix 5580/5380 families, CVE-2026-9637, CIP message length DoS, CVSS 7.5, firmware trains through V36.012; vendor fix V37.011 / 34.015 / 35.014 as listed. On 3 September CISA listed a stack: Tycon TPDIN-Monitor-WEB3, Pyramid Solutions NetStaX EtherNet/IP stack, Inductive Automation Ignition, Rockwell 1756-ENBT, ArmorStart LT, ControlFLASH, IXON VPN client, OPC Foundation OPC UA LDS, plus Schneider Easergy/EcoStruxure/PowerLogic/Saitel Update A. Those are vulnerability advisories. They are not confirmation that any of those products were popped in a 2026 process incident this week.

The live OT threat that still has evidence is unchanged: internet-reachable PLCs, vendor engineering software as the client, password/IP changes, malicious project files. That is AA26-097A (April, updated 22 July to Schneider/Siemens) and the 30 July FBI/EPA seven-state water PSA, plus AA26-231A (19 August) on Siemens S7 recon with AI-generated scripts dressed as monitoring tools. Dragos Q2: 1,140 industrial ransomware claims, no ransomware operator at ICS Kill Chain Stage 2. Do not upgrade this week’s ICSA list into FrostyGoop.

OT threat posture

Exposure and engineering-path abuse remain higher confidence than novel ICS malware. Ransomware still hurts plants by killing the IT and hypervisors OT depends on.

1. Most significant development

The 1–3 September CISA ICS drop, because it is what asset owners can actually ticket this week: Logix CIP DoS, Ignition (the historian/SCADA glue in a lot of US plants), IXON VPN (remote access into machines), EtherNet/IP stack, OPC UA discovery. A DoS on Logix is availability. Ignition and IXON are IT-to-OT doors. Treat the 3 September list as a patch/compensating-control queue, not as “nine new APT campaigns.”

2. Adversary / campaign activity

No new joint advisory this week. Continuing:

UNKNOWN a 31 Aug–7 Sep named victim with confirmed ladder-logic change.

3. Vulnerabilities and active exploitation

CONFIRMED (advisory): CVE-2026-9637 Logix CIP DoS.

CONFIRMED (catalog): 3 September ICSA-26-246-01 through -08 and the Schneider update. Read each CSAF before you brief a CVSS; this weekly does not invent scores for that stack.

NOT this week’s story: N-able N-central CVSS 10 (IT/RMM). It can become an IT-to-OT path if that RMM can reach engineering jump hosts. That is ASSESSED exposure, not a confirmed ICS compromise.

4. ICS / SCADA impact

No CONFIRMED new loss-of-view/loss-of-control event dated this week in primary USG or major OT-vendor reporting that RWP reviewed. Prior water PLC tampering (July) and UK small-generator outage (late July, disclosed August) remain the last well-sourced availability hits — they are not this week’s news.

5. IT-to-OT exposure

IXON VPN client on the 3 September list is the clean example: remote access into machines is how “IT ransomware” becomes a halted line without touching a coil. N-central (see this week’s IT briefing) is the same class if MSPs manage plant Windows. Ignition sits on both sides of the DMZ in too many drawings. Hunt: internet-facing 44818/102/502/2222/22, Studio 5000/TIA/Control Expert from VPS, unexpected project downloads.

6. Sector impact

Water/wastewater: still the PSA. Energy/manufacturing: S7 and Logix firmware debt. Building/data-center cooling: not a new 2026 week-specific incident; last month’s Winnipeg HVAC ransomware and NERC large-load note remain the context, not this week’s lead.

7. Defensive priorities

  1. Internet-facing PLC eradication — still number one. VPN or jump host, never the controller.
  2. Logix firmware to the trains Rockwell named in ICSA-26-244-03.
  3. Work the 3 September ICSA pile in this order: remote access (IXON), SCADA/Ignition, then device firmware.
  4. Validate running project files against a known-good (AA26-097A).
  5. Do not wait for ICS-specific malware. Dragos already told you Q2 ransomware did not need it.

8. What changed from last week

There was no prior RWP weekly OT on this site — this is the first cycle. Versus late August: Siemens S7 advisory is now 19 days old; this week added Logix DoS and a mixed ICS vuln stack. No new leak-site quarter. No new USG PLC campaign update.

9. What OT defenders should watch next

Whether CISA/FBI refresh AA26-097A or the water PSA. Whether any 3 September product shows in-the-wild notes. Q3 industrial ransomware counts. Friday 11 September is the scheduled weekly OT job — this briefing fills the empty tab now; that job should add material developments, not reprint this page.

10. RWP assessment

Confidence: High that this week is hygiene and ICS paper. High that exposed controllers remain the incident class. Low that a new OT malware family dropped in the last seven days. Labeling a manufacturer ransomware victim as “OT compromise” without process evidence remains a briefing error.

This assessment covers 31 August–7 September 2026 and was published 7 September 2026.

Sources

  1. CISA — ICS advisories 3 September 2026
  2. CISA — ICSA-26-244-03 Rockwell Automation Logix Platform
  3. CISA — AA26-231A Defending against an active threat to Siemens S7
  4. CISA — AA26-097A update 22 July 2026 Iran-affiliated PLC exploitation
  5. FBI/EPA — 30 July 2026 WWS internet-facing PLC PSA
  6. Dragos — Q2 2026 industrial ransomware (no Stage 2 ICS cases)