A Nuclear Plant's Drawings Leaked Through a Contractor
India's largest nuclear plant lost 14.3 gigabytes of blueprints this week through a contractor's file storage. The documents contractors already hold are the exposure, and the federal program built for exactly that problem just went on pause.
Summary
India's largest nuclear plant lost 14.3 gigabytes of paperwork this week. The files went out through a contractor. They included blueprints for the ventilation and cooling systems, plus floor layouts of the control rooms. Nobody broke into the reactor, and nobody had to. The documents that describe the plant were already sitting outside the plant.
Findings
The Hacker News tied the spill on 20 Jul 26 to Reliance Infra, an Indian contractor connected to the Kudankulam nuclear plant. The leaked set held the ventilation and cooling drawings along with the control-room floor plans. Those are the files a contractor holds because he did the work.
The same week brought the third SharePoint bug under active attack in a month. SharePoint is Microsoft's document storage system, and many companies run it on their own servers. The new bug, numbered CVE-2026-50522, scores 9.8 out of 10 and hits every supported self-hosted version. Once a working example of the attack went public, attackers started pulling a server's secret signing keys with a single request. Those self-hosted SharePoint servers are where contractor document sets live, the submittal packages and the as-builts from every job a shop ever closed out.
The Cybersecurity and Infrastructure Security Agency (CISA) released seven advisories for industrial control systems (ICS) on 21 Jul 26. The covered gear runs from a Tycon remote power monitor up to Rockwell's FactoryTalk platform. And SonicWall's SMA 1000 remote-access boxes have been fully compromised since late June, with two flaws chained together for total control. Monitoring data from the security firm Rapid7 shows a ransomware crew called Inc stealing passwords off those boxes. From there the crew moves toward the servers that control every login on the network. Seven days produced fresh holes in the gear the drawings describe and in the places the drawings sit.
Meanwhile the one federal program aimed at contractor-held information stopped moving. The Cybersecurity Maturity Model Certification (CMMC) sets the security rules defense contractors have to meet. The Pentagon put its Phase 2 requirements on hold for sixty days on 13 Jul 26. The 10 Nov 26 enforcement date sits frozen with them. A task force has been reviewing the whole program since 17 Jul 26.
Impact
I see network gear and control systems drawn out in as-builts, passed around with no labels, daily. As-builts are the drawings that show how a job actually got built. Those are the obvious ones. Submittal packages and turnover binders never even get considered. One riser diagram plus one panel schedule tells a stranger where everything lives and how it all talks. What leaked in India this week is sitting on file shares all over this country, unlabeled, in folders named after the job.
These are exactly the documents that should count as controlled unclassified information (CUI), the government's label for sensitive but unclassified material. Contractors already hold them, and that is why CMMC is the right idea. Strip the letters off and the requirement is simple. Know what you hold, and control who touches it. That discipline, applied at one contractor, would have kept the cooling drawings of a nuclear plant off the open internet.
Recommendations
Spend an hour this week listing what your shop holds, every as-built and turnover binder and the server it sits on. If you run your own SharePoint, patch CVE-2026-50522 and change the machine keys, because the patch alone does not remove anyone who already copied them. The same goes for the SonicWall fixes from 14 Jul 26. Then watch the CMMC task force. The review runs sixty days, and when the comment window opens, the small shops that actually hold these drawings should be the ones talking.
Works Cited
- Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More (The Hacker News, 20 Jul 26)
- Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC (The Hacker News, 21 Jul 26)
- Tycon Systems TPDIN-Monitor-WEB2, ICSA-26-202-01 (CISA, 21 Jul 26)
- Rockwell Automation FactoryTalk Services Platform, ICSA-26-202-07 (CISA, 21 Jul 26)
- Inc Ransomware Exploits SonicWall SMA Zero-Days (Dark Reading, 17 Jul 26)
- Pentagon announces 'immediate suspension' of CMMC Phase II mandates (Breaking Defense, 13 Jul 26)
- Pentagon task force to review CMMC hits the ground running (DefenseScoop, 17 Jul 26)