📅 Sept 10, 2026 | 10am CT / 4pm BST
On July 2026, attackers exploited internet-exposed PLCs and a reused vendor configuration to gain access to 30+ water and wastewater utilities across multiple US states. The activity shares characteristics with prior Iranian-affiliated PLC intrusions referenced in CISA’s AA26-097A advisory, though attribution is not confirmed.
Join Karl Sigler, Nolen Johnson, and Nikita Kazymirskyi for the technical mechanism, the exposure data, and remediation guidance direct from the researchers tracking this campaign, plus live Q&A.
You'll learn
-
How a single reused vendor configuration let attackers scale access across 30+ unrelated utilities
-
Where attribution actually stands, and how that differs from the headlines
-
Remediation priorities for water and public sector OT: remote access, credentials, logic integrity, and vendor review
Speakers
-
Nolen Johnson, Director of Hardware/ OT Security, LevelBlue
-
Nikita Kazymirsky, Principal Security Researcher, LevelBlue
Moderator