Skip to main content
Labshock
LoginStart Free
← All Updates
EDUCATIONAugust 23, 2026

Two Federal Advisories, No Zero Day

Water utilities in July, Siemens controllers in August, five agencies between them — and not one zero day. The stated causes were exposure, default credentials and missing segmentation.

Two federal advisories in three weeks.

Not one zero day between them.

30 July, Water

The FBI and EPA reported activity against water utilities in at least seven states.

Allen-Bradley MicroLogix controllers, sitting on the public internet. Somebody changed IP addresses and passwords. Operators lost view, then lost control.

Reported effects were pressure loss and flooding.

20 August, Siemens

Five agencies on a single advisory — NSA, CISA, FBI, DOE and EPA.

The scope covered S7-200, 300, 400, 1200 and 1500, and the F-series safety controllers as well.

Method: internet scan, then default credentials. After that, read and write access to memory, configuration and ladder logic.

Now Read What Both Say About Cause

No zero day.

  • Internet exposed
  • Weak or default password
  • No segmentation

Same finding, two sectors, three weeks apart.

What Changed Is Not The Protocol, It Is The Cost

Mass scanning used to be work. Now it is one query in a search engine for internet-connected devices.

Speaking S7comm used to mean learning a library yourself. The August advisory notes that actors are now using AI to generate that tooling, which cuts the expertise and the time the work used to require.

The barrier was never the protocol. The barrier was patience, and patience got cheap.

That is the part worth sitting with. Nothing in either advisory describes a new capability. What changed is how little effort the old capability now takes.

Both Of These Already Run Inside Labshock

Eastwater Facility is a water plant in Signalspire, where the air gap topic lives.

Spindlespeed runs S7 and S7comm in Logicveil, with direct manipulation of an S7 PLC — the protocol write-up is at labshocksecurity.com/news/s7comm-protocol-anatomy-siemens-plc-port-102

Not slides about them. A running process you point tools at and break without calling anybody.

The Question I Keep Asking

DNP3 and IEC 104 are public, documented and object oriented.

What happens when that same cost curve reaches the grid?

Firegate is already built for that. And the first mitigation in the water alert is a jump host brokering the connection — which is exactly the boundary we build and test in the firewall and zoning masterclass: labshocksecurity.com/news/masterclass-firewall-zoning-ot

OT security must be testable.

Not documented.

Try It Yourself

  • Read both advisories in full at cisa.gov before you take anybody's summary, including this one.
  • Answer the three causes for your own estate: what is reachable from the internet, what still holds default credentials, and where segmentation is assumed rather than tested.
  • Test the answers somewhere you are allowed to break things: github.com/zakharb/labshock
  • Compare findings with other operators: discord.gg/bpmaQFfW76
LABSHOCK SECURITY — OT SECURITY MUST BE TESTABLE, NOT DOCUMENTED