CISA has issued a warning for water utilities to identify and secure internet-exposed PLCs following significant cyberattacks in July 2026. The attacks targeted over 100 systems, mainly programmable logic controllers (PLCs) that were connected directly to the internet without proper security measures.
CISA's guidance, published on August 21, outlines steps for organizations to locate vulnerabilities, utilize tools like Shodan and Censys, and secure necessary remote access through centralized systems rather than direct connections. The document stresses the importance of monitoring and securing protocols to prevent malicious access and reinforces that the observed pattern of attacks reflects a broader threat to critical infrastructure from nation-state actors.