The Grid Attack and the Late Patches Are One Story
Hackers tied to Iran probed US grid controllers, and weeks later the government published bug notices for the same gear. The weak point is how long an isolated controller waits for its patch.
Summary
The Cybersecurity and Infrastructure Security Agency (CISA) is the federal office that tracks threats to US infrastructure. On 8 Apr 26 CISA warned that hackers tied to Iran were probing programmable logic controllers (PLC). A PLC is the small computer that runs industrial equipment. The warning named the energy sector. Five weeks passed, then on 12 May 26 CISA put out seven notices about security bugs in that same class of gear. A second round landed on 19 May 26. The press treated the April warning as war news and the May notices as boring maintenance news. I work on this gear. They are one story.
Findings
The 12 May batch named Tellus, a control platform from the Japanese maker Fuji Electric. It also named PowerSYSTEM Center, a program from the software company Subnet that utilities use to manage substation gear. A controller called the AC500, built by the Swiss equipment maker ABB, was in that batch too. A week later, on 19 May 26, CISA added Siemens and Schneider Electric, two of the biggest makers of industrial controls. Rockwell was on that round as well.
The two stories landed with different reporters, so they read like separate events. Both readings only work for someone who has never serviced this gear. An unpatched controller does not care who comes looking. A foreign government and a bored kid with a scanning tool find the same open port.
I have written programs for Siemens and Rockwell controllers on airfield lighting work. I have installed Schneider controls on that same kind of work. The pattern repeats on every job. The Federal Aviation Administration (FAA) regulates the controller. It sits in a panel in a locked room with no outside network connection. Then the ops crew asks to see the screens, so someone connects a monitoring line. A remodel comes through and a new vendor mounts a phone bracket on the wall. Somebody changes the network settings for a reason that seemed fine that morning. Through every one of those changes the patches stay queued. The bug notices land in an inbox nobody checks, because the whole team decided years back that the panel has no internet connection.
The real danger is the time between the day a patch ships and the day the panel receives it. The war headlines do not change that number.
Impact
Patch lag is huge on this kind of system. Everyone treats the equipment as isolated and standalone, so nobody sends it patches. The grid probing and the May notices describe one event at two moments. First somebody looks for a way into the controllers. Then the bugs that would let them in sit unfixed in those same controllers. The isolation was built for safety. That same isolation is why the patches never arrive. The panel stopped being disconnected when the first monitoring line went on. Nothing protects it today except that no attacker has found it yet.
Recommendations
If you commissioned a control panel in the last two years, look up the published bugs for each model number you remember. CISA posts free bug notices for industrial control systems (ICS) most days. Aim that feed at the person on your crew who actually opens email. CISA also keeps a list of bugs that hackers are already using. That list grew by seven on 20 May 26, then by two more the next day. None of this is hidden.
Next week I am looking at airfield lighting. That gear comes from the same makers and carries the same trust that nothing is connected. Patches run late on that gear too, when they show up at all. I have spent real hours in those rooms. If the pattern holds, you will read about it here next week.
Works Cited
- Robert Walton, NERC is 'actively monitoring the grid' following Iran-linked cyber threat (Utility Dive, 8 Apr 26)
- CISA Cybersecurity Advisory AA26-097A; Iran-linked targeting of PLCs (CISA, 8 Apr 26)
- CISA Releases Seven ICS Advisories May 12, 2026 (OpenText, 12 May 26)
- CISA ICS Advisories feed (CISA)
- CISA Adds Seven Known Exploited Vulnerabilities to Catalog (CISA, 20 May 26)
- CISA Adds Two Known Exploited Vulnerabilities to Catalog (CISA, 21 May 26)
- Anna Ribeiro, CISA flags ICS vulnerabilities in Siemens, Schneider Electric, Rockwell (Industrial Cyber, 19 Dec 25)
- Phil Muncaster, Industrial Control System Vulnerabilities Hit Record Highs (Infosecurity Magazine, 19 Feb 26)
- Leslie Abrahams and Lauryn Williams, Iran Conflict Heightens Cyber Threats to U.S. Energy Infrastructure (CSIS, 2 Apr 26)