Session
The Logic Looked Fine: Reversing Safety-System Bypass in Critical Infrastructure PLCs
In 2026, Iranian-affiliated actors disrupted PLC operations across US water, energy, and local-government infrastructure, and they didn't need a new zero-day. They targeted misconfigured, internet-facing controllers, reached them with the manufacturers' own programming software, and exfiltrated device project files. CISA and the FBI then identified modification and deletion of project logic, including Rockwell Add-On Instructions, along with manipulation of HMI and SCADA display data. The changes disabled critical shutdown and alarm logic. At one US victim the malicious file kept the downstream ladder logic in place and added logic that overrode the safe-operating-parameter instructions, which meant the process kept running while the checks meant to stop it did nothing.
This talk goes through that campaign from the public reporting in joint advisory AA26-097A. I'll cover how the exposed PLCs were reached and how project files left through Studio 5000, EcoStruxure Control Expert, and TIA Portal. Most of the time goes to the reusable modules, because an AOI becomes a blind spot as soon as integrity review stops at the top-level ladder. I'll also put the display manipulation in ATT&CK for ICS terms; it reads as manipulation of view rather than loss of view, and that distinction changes what an operator can do about it. Each stage maps to the techniques the advisory cites.
The second half is defense on a normal budget. Validating running projects against known-good logic, with the AOIs and safety routines actually opened. RUN mode and programming protections where the platform has them. Monitoring the ports the advisory names. Monitored gateways in front of controllers that have no way to enforce any of this on their own. I'll finish with AA26-231A, a separate August advisory that names no actor, about AI-generated scripts targeting Siemens S7 PLCs. It lowers the effort to build the tooling, and none of the defenses above change because of it.
Amanda Kollmorgan
Outrunning expectations in security, from the boardroom to the blue team.
Madison, Wisconsin, United States
Links
Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.
Jump to top