← All briefings Weekly Briefing

Issue: July 26, 2026

Coverage period: 20 - 26 July 2026

1. Critical Infrastructure Watch - Iran-Affiliated Actors Expand PLC Targeting; Update Directly Relevant to Device-Manufacturing OT Environments

On 22 July 2026, CISA, the FBI, NSA, the EPA, the Department of Energy, the Department of the Treasury, and U.S. Cyber Command’s Cyber National Mission Force jointly updated Cybersecurity Advisory AA26-097A, first issued in April 2026, on Iranian-affiliated cyber actors exploiting internet-exposed programmable logic controllers (PLCs) across U.S. critical infrastructure.

What changed this week

The update expands the advisory’s scope beyond the originally named Unitronics and Rockwell Automation targeting to add confirmed activity against Schneider Electric and Siemens PLCs, naming specific affected product lines including Rockwell CompactLogix and Micro850, Schneider BMX P34/Modicon M340, and Siemens S7-1200 series controllers. New guidance was also added on detecting malicious modifications to reusable code modules within Rockwell PLC programs. The FBI reported observing threat actors download malicious project files to a targeted PLC at a U.S. critical infrastructure organization, along with manipulation of human-machine interface (HMI) and SCADA display data that produced operational disruption and direct financial loss - with indicators of compromise dated as recently as this month.

Manufacturer relevance

This advisory targets water, energy, and government-facility operators rather than healthcare specifically, but the named PLC families (Rockwell/Allen-Bradley, Schneider Electric, Siemens) are widely deployed on device-manufacturing production lines, not just in hospital facilities. The attack pattern described - default credentials, insecure remote access, and unpatched firmware enabling configuration manipulation - maps directly onto common OT exposures in medical device manufacturing plants. Manufacturers running any of the named PLC families in production or packaging lines should confirm these controllers are not directly internet-accessible, review remote-access configurations against the advisory’s mitigations, and check reusable code modules for unauthorized changes.

Sources: Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure - CISA (AA26-097A, updated 22 July 2026); CISA, FBI warn that Iran-linked hackers are expanding target set for water, energy - Cybersecurity Dive

2. Sector Intelligence - Health-ISAC Publishes First-Ever CISO Benchmarking Report and Q2 Threat Heartbeat

On 20 July 2026, Health-ISAC released two companion publications: its inaugural CISO Benchmarking Report and the Q2 2026 Health Sector Heartbeat threat assessment.

CISO Benchmarking Report

The benchmarking report - Health-ISAC’s first of its kind - reflects survey input from 76 health-sector CISOs across providers, payers, pharma, medical devices, and global operations. It covers top cybersecurity risks and emerging threats, CISO reporting lines and responsibilities, 2026 budget outlook and spending allocation, security workforce sizing and the persistent workforce shortage, NIST CSF and other framework adoption maturity, and the growing use of AI by both defenders and adversaries in the health sector.

Q2 2026 Health Sector Heartbeat

The threat report logged 2,755 total cyber-incident events across all critical-infrastructure sectors in Q2 2026, with 402 incidents specifically impacting the health sector in H1 2026 - a run rate that, if sustained, would make 2026 a record year (H1 2026’s 5,672 all-sector incidents already exceed H2 2025’s 4,860, a 17% increase). Health-ISAC issued 193 targeted alerts to members during the quarter, nearly half concerning misconfigured or dangling DNS records, and profiled the extortion group World Leaks, which has listed at least two dozen health-sector victims (predominantly hospitals) and operates a journalist portal giving media 24-hour advance access to stolen data ahead of public posting.

Manufacturer relevance

The benchmarking data gives device manufacturers a rare sector-specific yardstick for CISO budget, staffing, and framework-maturity comparisons, since medical device organizations were an explicit respondent segment. The Heartbeat’s incident trend and DNS-misconfiguration alert volume are a useful prompt for manufacturers to audit their own external DNS hygiene and to factor extortion-focused groups like World Leaks into third-party and data-exposure risk assessments alongside the ShinyHunters activity covered in prior briefings.

Sources: 2026 Health-ISAC CISO Benchmarking Report - Health-ISAC; Health-ISAC releases its Q2 2026 healthcare threat report - Paubox

Disclaimer: This briefing is prepared by Aktriva for informational purposes only and does not constitute legal, regulatory, or compliance advice. Information is drawn from publicly available sources; while we aim for accuracy, errors or omissions may occur despite our review process. Readers should independently verify developments against primary regulatory sources and consult qualified advisors before making compliance decisions.

Want this tailored to your regulatory strategy?

Talk to our team about what this week's developments mean for your specific device and timeline.

Schedule a Consultation