Skip to content
You can now search across every topic, entity and event.What's new
Cybersecurity: Threats and Defences
3AUG

The alert's citations predate the alert

2 min read
16:08UTC

Rockwell published advisory SD1790 on 30 July with no CVE attached, and the NCSC guidance CISA points water operators to is version 1.0 from March 2024. Only the alert itself is new.

TechnologyAssessed
Key takeaway

Check the publication date on every document an alert cites before treating the list as new action.

Rockwell Automation published security advisory SD1790 on 30 July, revising it the following day, covering MicroLogix 1100 and 1400 controllers rather than the 1400 alone that CISA's alert names 1. Rockwell attaches no CVE identifier to it, and states plainly that the document gives operational recovery steps for a controller an attacker has already locked rather than disclosing a vulnerability. Nothing in SD1790 is a patch. It tells an engineer how to get back into a device whose password has been changed underneath them.

The mitigation resource CISA points water operators towards comes from the NCSC, the UK's National Cyber Security Centre, and is titled Secure Connectivity Principles for Operational Technology. That document is version 1.0 and carries a publication date of March 2024 2. It was co-developed with international partner agencies at the time and has not been reissued for this activity.

The third citation cannot be examined at all. CISA names a separate FBI bulletin on the same controller targeting and does not reproduce it, so its contents are unavailable to anyone reading the alert. What the bulletin says, and whether it adds anything the alert does not, remains outside the public record.

A reader taking the citation list as evidence of a coordinated response mounted this week would be reading a 2024 guidance document, a vendor recovery note written this month, and an unpublished federal bulletin as a single act. Coordinated action on this beat looks different when it happens: NCSC's July naming of a Russian intelligence unit arrived with a long list of co-signing governments, technical detail and a publication date of its own . Nothing of that kind accompanies the water alert, whose only new document is the alert.

Deep Analysis

In plain English

When a government cybersecurity agency issues an alert, it often points to supporting documents from other agencies to show the advice is coordinated and well-established. Here, some of those citations don't hold up well under a closer look. CISA's water-sector alert points to guidance from the UK's NCSC, but that document is more than two years old, first published in March 2024, not new advice issued alongside this specific campaign. CISA also names an FBI bulletin on the same topic, but no one could find a copy of it. And the industrial equipment maker Rockwell Automation published its own guidance the same week, but it's explicitly a 'how to reset a locked controller' instruction sheet, not a software patch for a security flaw, because there isn't a flaw to patch, only a device left too exposed to the internet.

Deep Analysis
Root Causes

Rockwell's own advisory, SD1790, states explicitly that it is 'operational recovery guidance rather than a vulnerability disclosure,' meaning it tells operators how to factory-reset a password-locked MicroLogix controller, not how to patch a flaw. No CVE is attached because there isn't one: the attack exploits weak or exposed device access, not a coding defect Rockwell can fix in firmware.

That distinction matters structurally because CISA's own alert names Rockwell's MicroLogix 1400 specifically, but SD1790 as published also covers the MicroLogix 1100, a scope CISA's alert text doesn't mention. A reader following only CISA's wording would miss half the affected product line.

What could happen next?
  • Risk

    Readers who assume Rockwell's SD1790 is a patch may skip the actual fix, disconnecting or securing remote access, and wait instead for a firmware update that isn't coming.

  • Meaning

    An alert's citation list is not proof of fresh coordinated action; each cited document needs checking against its own publication date and scope.

First Reported In

Update #12 · KEV deadlines fell from 14 days to three

Rockwell Automation· 3 Aug 2026
Read original
Different Perspectives
Group-IB
Group-IB
Group-IB, headquartered in Singapore, documented on 19 March that The Gentlemen began inside Qilin's own affiliate programme and split from it over a payment dispute. Its analysis makes this window's leak-site tally readable as a fracture inside one ransomware operation rather than the arrival of an unknown crew.
ENISA
ENISA
ENISA placed EU drinking water and wastewater in its cyber risk zone for the first time on 28 May, finding one in three water entities had never run a risk assessment. CISA's 30 July advisory to American operators reads as the operational sequel to a gap European regulators had already documented two months earlier.
House of Lords and NCSC
House of Lords and NCSC
The Cyber Security and Resilience Bill sits at House of Lords committee stage, its amendment paper running to 23 July. Separately, the NCSC guidance CISA cited when directing water operators to disconnect controllers is version 1.0 from March 2024, a two-year-old British document doing operational work in an American alert published last week.
heise online
heise online
heise online reported on 27 July that Russian state attackers, named as APT28, ran the hotel WiFi credential-harvesting campaign. Its attribution is firmer than ReliaQuest's own hedged low-to-medium confidence assessment of the same intrusion, a difference in national reporting posture rather than a settled dispute over who is responsible.
CISA and ReliaQuest
CISA and ReliaQuest
CISA compressed remediation deadlines under BOD 26-04 while, in the same window, telling water and wastewater operators to disconnect internet-exposed controllers rather than patch them. ReliaQuest, investigating the hotel WiFi campaign, held its assessment of the intrusion route at low-to-medium confidence and declined to name a state sponsor.
AIVD
AIVD
AIVD co-signed AA26-204A alongside CISA, the NSA and the FBI, adding its signature to the fifteen-agency coalition naming LAUNDRY BEAR. Dutch involvement continues a pattern of joint Five Eyes-adjacent advisories the agency has co-issued with CISA and NCSC through 2026.