Skip to content
You can now search across every topic, entity and event.What's new
Cybersecurity: Threats and Defences
3AUG

The alert's citations predate the alert

2 min read
16:08UTC

Rockwell published advisory SD1790 on 30 July with no CVE attached, and the NCSC guidance CISA points water operators to is version 1.0 from March 2024. Only the alert itself is new.

TechnologyAssessed
Key takeaway

Check the publication date on every document an alert cites before treating the list as new action.

Rockwell Automation published security advisory SD1790 on 30 July, revising it the following day, covering MicroLogix 1100 and 1400 controllers rather than the 1400 alone that CISA's alert names 1. Rockwell attaches no CVE identifier to it, and states plainly that the document gives operational recovery steps for a controller an attacker has already locked rather than disclosing a vulnerability. Nothing in SD1790 is a patch. It tells an engineer how to get back into a device whose password has been changed underneath them.

The mitigation resource CISA points water operators towards comes from the NCSC, the UK's National Cyber Security Centre, and is titled Secure Connectivity Principles for Operational Technology. That document is version 1.0 and carries a publication date of March 2024 2. It was co-developed with international partner agencies at the time and has not been reissued for this activity.

The third citation cannot be examined at all. CISA names a separate FBI bulletin on the same controller targeting and does not reproduce it, so its contents are unavailable to anyone reading the alert. What the bulletin says, and whether it adds anything the alert does not, remains outside the public record.

A reader taking the citation list as evidence of a coordinated response mounted this week would be reading a 2024 guidance document, a vendor recovery note written this month, and an unpublished federal bulletin as a single act. Coordinated action on this beat looks different when it happens: NCSC's July naming of a Russian intelligence unit arrived with a long list of co-signing governments, technical detail and a publication date of its own . Nothing of that kind accompanies the water alert, whose only new document is the alert.

Deep Analysis

In plain English

When a government cybersecurity agency issues an alert, it often points to supporting documents from other agencies to show the advice is coordinated and well-established. Here, some of those citations don't hold up well under a closer look. CISA's water-sector alert points to guidance from the UK's NCSC, but that document is more than two years old, first published in March 2024, not new advice issued alongside this specific campaign. CISA also names an FBI bulletin on the same topic, but no one could find a copy of it. And the industrial equipment maker Rockwell Automation published its own guidance the same week, but it's explicitly a 'how to reset a locked controller' instruction sheet, not a software patch for a security flaw, because there isn't a flaw to patch, only a device left too exposed to the internet.

Deep Analysis
Root Causes

Rockwell's own advisory, SD1790, states explicitly that it is 'operational recovery guidance rather than a vulnerability disclosure,' meaning it tells operators how to factory-reset a password-locked MicroLogix controller, not how to patch a flaw. No CVE is attached because there isn't one: the attack exploits weak or exposed device access, not a coding defect Rockwell can fix in firmware.

That distinction matters structurally because CISA's own alert names Rockwell's MicroLogix 1400 specifically, but SD1790 as published also covers the MicroLogix 1100, a scope CISA's alert text doesn't mention. A reader following only CISA's wording would miss half the affected product line.

What could happen next?
  • Risk

    Readers who assume Rockwell's SD1790 is a patch may skip the actual fix, disconnecting or securing remote access, and wait instead for a firmware update that isn't coming.

  • Meaning

    An alert's citation list is not proof of fresh coordinated action; each cited document needs checking against its own publication date and scope.

First Reported In

Update #12 · KEV deadlines fell from 14 days to three

Rockwell Automation· 3 Aug 2026
Read original
Different Perspectives
ENISA
ENISA
ENISA published an SME cyber-resilience maturity model on 6 August and updated the Cyber Resilience Act reporting-platform FAQ on 31 August. The agency supplies common implementation tools for smaller operators, but it cannot fine organisations that do not use them.
UAE Cyber Security Council
UAE Cyber Security Council
On 10 August, the UAE Cyber Security Council said national teams contained attacks on aviation, energy and education before objectives were reached. Its second monthly statement, after a 3 July financial-sector disclosure, makes public reporting of stopped attacks part of its operating posture.
South African authorities
South African authorities
INTERPOL said on 25 August that South African authorities made 39 arrests, seized US$2.67 million and blocked 257 accounts during Operation Jackal IV. Their share of the 23-country operation shows the material enforcement burden in a cross-border fraud case.
Europol
Europol
On 2 September, Europol announced the sinkholing of Sality after a 31 August operation involving US, Bulgarian, Hungarian and Romanian authorities. Its more than 11 million linked IP addresses measure infrastructure contact, not confirmed victims, and show why technical partners joined the action.
CISA
CISA
From 3 August to 2 September, CISA recorded three-day deadlines for 24 of 37 KEV additions, compared with 34 of 39 from 10 June to 29 July. The falling share changes the urgency signal that US federal agencies and private-sector tooling draw from the catalogue.
Beacon
Beacon
On 3 September, Beacon said its final report found that an intruder likely exported its customer database during roughly one hour and 27 minutes on 27 July. Charities using the CRM now have a named exposure route, a compromised AWS access key in public build artefacts.