42 Minute WatchNolen Johnson | Director of Hardware/OT Security, LevelBlueNikita Kazymirsky | Principal Security Researcher, LevelBlue Karl Sigler | Senior Research Manager, LevelBlue
On July 2026, attackers exploited internet-exposed PLCs and a reused vendor configuration to gain access to 30+ water and wastewater utilities across multiple US states. The activity shares characteristics with prior Iranian-affiliated PLC intrusions referenced in CISA’s AA26-097A advisory, though attribution is not confirmed.
Join Karl Sigler, Nolen Johnson, and Nikita Kazymirskyi for the technical mechanism, the exposure data, and remediation guidance direct from the researchers tracking this campaign, and Q&A.
You'll learn:
How a single reused vendor configuration let attackers scale access across 30+ unrelated utilities
Where attribution actually stands, and how that differs from the headlines
Remediation priorities for water and public sector OT: remote access, credentials, logic integrity, and vendor review.