The Grid Is Being Shot At; CISA Is Publishing the Manual
The Iran-linked grid targeting and CISA's May ICS advisories are one story filed as two. The real exposure is how long isolated industrial systems wait for their patches.
Summary
CISA published an advisory on 8 Apr 26. Iran-linked actors were going after programmable logic controllers across US critical infrastructure, with the energy sector called out directly. Five weeks later, on 12 May 26 the agency pushed seven fresh ICS advisories on the exact gear those controllers sit in. That batch named Fuji Electric's Tellus platform and the Subnet PowerSYSTEM Center, with ABB's AC500 in the pile. Another round followed on 19 May 26 and pulled in Siemens and Schneider Electric, and Rockwell made that list too. Most of the cyber press ran the two dates as separate stories, one a geopolitics headline and one a maintenance footnote. I work on this gear, and from where I sit they are the same story.
Findings
The 8 Apr 26 advisory got the geopolitical treatment. It landed in the sixth week of the Iran war, so the trade press wrote it up in threat-actor language with the grid as the target. The May advisories got the boring treatment instead, routine patch hygiene, the sort of item that sinks under whatever ransomware ran that week. Both takes only work for a reader who has never had to maintain this equipment.
An unpatched controller is exposed the same way no matter who comes looking for it. The foreign service and the kid with a scanner find the same open port, and whoever left that controller reachable back in Nov 25 left it reachable for both of them.
I have programmed Rockwell and Siemens controllers on airfield lighting jobs, and I have put in Schneider gear on the same kind of work. It goes the same way every time. The controller is FAA regulated and it is supposed to talk only to its own kind, and it sits in a panel in a locked room. Then the ops crew wants to watch the graphics, so someone drops a monitoring tap on it. A remodel rolls through later and a new vendor screws a phone bracket to the wall, and at some point somebody edits a VLAN for a reason that made sense that morning. Through all of it the patches stay queued, and the advisory sits in a mailbox nobody opens, because everybody agreed years ago that the panel is not on the internet.
Here is the plain version. What actually gets you is the gap between the day the patch ships and the day the panel takes it, and the war headlines have nothing to do with how wide that gap runs.
Impact
Patch lag runs huge on this kind of system, the ones everybody treats as isolated and standalone. The grid intrusion and the May advisories are one event, caught at two moments on the same kill chain. They land on different desks, so they get filed as different news, and meanwhile the isolation the integrator built for safety is also the reason the patches never land.
The air gap ended the day the first monitoring tap went on, and the network drop is already punched in. Right now the one thing keeping that panel safe is that nobody has come looking for it yet.
Recommendations
Practical read first. If you commissioned an ICS panel inside the last two years, pull the CVEs on every model number you can still remember. The CISA ICS advisory feed costs nothing and it updates most days, so point it at whoever on your crew actually opens email. The KEV catalog took on seven entries on 20 May 26 and two more on 21 May 26. Nobody is hiding any of this from you.
Now the thing to watch. Next week it is airfield lighting. It runs on the same gear families as this week and the same faith in isolation, and the patches arrive late there too, when they arrive at all. I have spent real hours in those rooms, and if the pattern holds, that is the report I will be writing next.
Works Cited
- Robert Walton, NERC is 'actively monitoring the grid' following Iran-linked cyber threat (Utility Dive, 8 Apr 26)
- CISA Cybersecurity Advisory AA26-097A; Iran-linked targeting of PLCs (CISA, 8 Apr 26)
- CISA Releases Seven ICS Advisories May 12, 2026 (OpenText, 12 May 26)
- CISA ICS Advisories feed (CISA)
- CISA Adds Seven Known Exploited Vulnerabilities to Catalog (CISA, 20 May 26)
- CISA Adds Two Known Exploited Vulnerabilities to Catalog (CISA, 21 May 26)
- Anna Ribeiro, CISA flags ICS vulnerabilities in Siemens, Schneider Electric, Rockwell (Industrial Cyber, 19 Dec 25)
- Phil Muncaster, Industrial Control System Vulnerabilities Hit Record Highs (Infosecurity Magazine, 19 Feb 26)
- Leslie Abrahams and Lauryn Williams, Iran Conflict Heightens Cyber Threats to U.S. Energy Infrastructure (CSIS, 2 Apr 26)