The Drawings Left the Fence
India's largest nuclear plant lost 14.3GB of blueprints this week through a contractor's file storage. The documents contractors already hold are the exposure, and the federal program built for exactly that problem just went on pause.
Summary
India's largest nuclear plant lost 14.3 gigabytes of paperwork this week. The files left through a contractor, and they included blueprints for the ventilation and cooling systems and floor layouts of the control rooms. Nobody breached the reactor, and nobody had to, because the documents that describe the plant were already sitting outside the fence.
Findings
The Hacker News' weekly recap on 20 Jul 26 tied the spill to Reliance Infra, a contractor connected to the Kudankulam plant. The leaked set held the ventilation and cooling drawings along with the control-room floor plans, the kind of files a contractor ends up holding because he did the work.
The same week brought the third SharePoint flaw under active attack in a month. CVE-2026-50522 scores a 9.8 and hits every supported on-prem version, and once a public proof of concept dropped, attackers started pulling a server's machine keys with a single request. On-prem SharePoint is where contractor document sets live, the submittal packages and the as-builts from every job a shop ever closed out.
CISA released seven industrial control advisories on 21 Jul 26, covering gear from a Tycon remote power monitor up to Rockwell's FactoryTalk platform. SonicWall's SMA 1000 remote-access boxes have been rooted since late June, two flaws chained for full control, and Rapid7's telemetry has the Inc ransomware crew stealing credentials off them and moving toward domain controllers. Seven days produced fresh holes in the gear the drawings describe and in the places the drawings sit.
Meanwhile the one federal program aimed at contractor-held information went quiet. The Pentagon put CMMC Phase 2 on hold on 13 Jul 26 for sixty days, the 10 Nov 26 enforcement date is parked, and a task force has been going over the whole program since 17 Jul 26.
Impact
I see network infrastructure and ICS systems in as-builts getting passed around with no labels, daily. Those are the obvious ones. Submittal packages and turnover documents aren't even being thought about. A riser diagram with a panel schedule tells a stranger where everything lives and how it talks, and what leaked in India this week is sitting on file shares all over this country, unlabeled, in folders named after the job.
These are exactly the type of documents that need to start being CUI. Contractors already hold them, and that's why CMMC is the right move. Strip the acronym off and the requirement is simple, know what you hold and control who touches it. That discipline, applied at one contractor, would have kept a nuclear plant's cooling drawings off the open internet.
Recommendations
Spend an hour this week listing what your shop holds, every as-built and turnover binder and the server it sits on. If you run on-prem SharePoint, patch CVE-2026-50522 and rotate the machine keys, because the patch alone does not evict anyone who already pulled them. The same goes for the SonicWall SMA fixes from 14 Jul 26. Then keep an eye on the CMMC task force. That review runs sixty days, and when the comment window opens, the small shops that actually hold these drawings should be the ones talking.
Works Cited
- Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More (The Hacker News, 20 Jul 26)
- Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC (The Hacker News, 21 Jul 26)
- Tycon Systems TPDIN-Monitor-WEB2, ICSA-26-202-01 (CISA, 21 Jul 26)
- Rockwell Automation FactoryTalk Services Platform, ICSA-26-202-07 (CISA, 21 Jul 26)
- Inc Ransomware Exploits SonicWall SMA Zero-Days (Dark Reading, 17 Jul 26)
- Pentagon announces 'immediate suspension' of CMMC Phase II mandates (Breaking Defense, 13 Jul 26)
- Pentagon task force to review CMMC hits the ground running (DefenseScoop, 17 Jul 26)