Summary
CISA has issued a warning about a significant increase in cyberattacks targeting over 100 internet-exposed US water systems in July 2026, with threat actors modifying PLC passwords and IP addresses, leading to disruptions like boil water notices. While attribution is uncertain, reports suggest an Iranian group may be responsible, and CISA urges the removal of PLCs from public internet access.