ON April 7, 2026, a Joint Cybersecurity Advisory was released warning U.S. organizations about Iranian-affiliated cyber attacks on internet-connected operational technology (OT) devices, particularly programmable logic controllers (PLCs). These attacks have disrupted PLC operations affecting various critical infrastructure sectors through malicious interactions and data manipulation.
The July 22, 2026 update provides new guidance on detecting malicious changes in Rockwell Automation PLCs and expands the scope to other brands like Schneider Electric and Siemens. The advisory emphasizes the need to restrict direct internet access and implement secure deployment practices for PLCs. All internet-exposed PLCs are potentially at risk.