Rockwell Automation published security advisory SD1790 on 30 July, revising it the following day, covering MicroLogix 1100 and 1400 controllers rather than the 1400 alone that CISA's alert names 1. Rockwell attaches no CVE identifier to it, and states plainly that the document gives operational recovery steps for a controller an attacker has already locked rather than disclosing a vulnerability. Nothing in SD1790 is a patch. It tells an engineer how to get back into a device whose password has been changed underneath them.
The mitigation resource CISA points water operators towards comes from the NCSC, the UK's National Cyber Security Centre, and is titled Secure Connectivity Principles for Operational Technology. That document is version 1.0 and carries a publication date of March 2024 2. It was co-developed with international partner agencies at the time and has not been reissued for this activity.
The third citation cannot be examined at all. CISA names a separate FBI bulletin on the same controller targeting and does not reproduce it, so its contents are unavailable to anyone reading the alert. What the bulletin says, and whether it adds anything the alert does not, remains outside the public record.
A reader taking the citation list as evidence of a coordinated response mounted this week would be reading a 2024 guidance document, a vendor recovery note written this month, and an unpublished federal bulletin as a single act. Coordinated action on this beat looks different when it happens: NCSC's July naming of a Russian intelligence unit arrived with a long list of co-signing governments, technical detail and a publication date of its own . Nothing of that kind accompanies the water alert, whose only new document is the alert.
