Nirad Threat Research
NBTF — Critical Infrastructure Sector Edition | 9 September 2026
The pattern is contractor and vendor access paths, not control-system exploits. Every confirmed exploitation item below is a gateway, portal or management server that a field engineer, a system integrator or a managed service provider uses to reach an operational network. For scale on what follows the access: Dragos tracks 26 threat groups against industrial environments, 11 of them active during 2025, and records ransomware groups affecting industrial organisations rising from 80 to 119 year on year, a 49 percent increase touching roughly 3,300 organisations. The same report gives the detection gap: operators with comprehensive OT visibility found ransomware in about five days, against an industry average of 42.
Source (with date): Dragos 2026 OT/ICS Cybersecurity Year in Review (17 Feb 2026).
SonicWall SMA1000: two zero-days that chain to unauthenticated code execution. CVE-2026-83548 is a pre-authentication server-side request forgery in the SMA1000 Work Place interface, rated CVSS 10.0. CVE-2026-83549 is an OS command injection in the Appliance Management Console which on its own requires an authenticated administrator and specific system conditions. Chained, the request forgery supplies the access the command injection needs, and the result is unauthenticated remote code execution on the appliance. SonicWall disclosed both on 1 September 2026 and confirmed exploitation in the wild; CISA listed both the following day. Where an SMA1000 is still in service it is frequently a secondary portal retained for vendor and field access after primary remote access moved to another product, so check the decommissioning register as well as the asset register.
Source (with date): SonicWall; Rapid7; Sophos; Help Net Security (02 Sep 2026).
Citrix NetScaler CVE-2026-19490: patched 19 August, exploit code public in early September. An authentication bypass using an alternate path, rated 9.3 on CVSS v4.0, affecting NetScaler ADC and Gateway configured as an AAA virtual server or as a Gateway for SSL VPN, ICA Proxy, CVPN or RDP Proxy. Rapid7 recorded no observed exploitation when the fix landed on 19 August and advised emergency patching regardless. A credible proof-of-concept was published in the first days of September and exploitation attempts matching it were then reported from multiple source addresses. Confirmed compromises have not been published at the time of writing, which is not a reason to wait. Fixed builds are 14.1-73.32 and 13.1-63.21, with separate FIPS builds. Patching alone does not close an authentication bypass: terminate existing sessions and review gateway authentication records back to 19 August.
Source (with date): Citrix; Rapid7; Help Net Security (21 Aug 2026); Field Effect (04 Sep 2026).
N-able N-central CVE-2026-86218: the provider's platform sits inside the operator's perimeter. A pre-authentication remote code execution flaw rated CVSS 10.0, classified as static code injection, disclosed on 6 September 2026 and fixed in build 2026.3.1.14. It is the fourth N-central hotfix in five weeks. Note a discrepancy worth carrying into any board paper: N-able's release notes state no confirmed evidence of exploitation in production, while a separate company notice describes exploitation in the wild, and CISA added it to the exploited catalogue on 8 September 2026. For a discom, water board or port operator whose endpoints are managed by an outsourced provider, that provider's management server holds standing privileged reach into the environment whether or not it appears on the operator's own asset register.
Source (with date): N-able; Help Net Security (07 Sep 2026); CISA KEV (08 Sep 2026).
Kudankulam: the exposure sat at a contractor's hosting provider, two steps from the plant. Files relating to a Reliance Group entity, held on a server at third-party data centre provider Yotta, were put up for extortion and reported publicly on 16 July 2026. The Nuclear Power Corporation of India stated the material concerns conventional balance-of-plant facilities and does not include reactor operations, nuclear safety systems or nuclear security infrastructure. Yotta says it detected and contained the intrusion before encryption, and CERT-In is investigating. We are not describing or itemising the documents, and their authenticity has not been independently established. The lesson is scope: the compromised party was a hosting provider holding a contractor's project records, a fourth-party position outside most Indian operators' vendor review.
Source (with date): Reuters, as carried by Al Jazeera (16 Jul 2026); The Record.
The standing Pakistan-nexus pressure is unchanged. APT36 (Transparent Tribe) and the aligned SideCopy cluster continue espionage operations against Indian government, defence and adjacent research, policy and critical-infrastructure organisations, with cross-platform Windows and Linux tooling reported this year including GETA RAT, ARES RAT and Desk RAT. That is standing backdrop rather than a development this cycle. Keep the detections active independently of this issue's list.
Source (with date): Aryaka; The Hacker News (Feb 2026).
Rockwell Automation: a batch of ICS advisories dated 3 September. CISA published eight ICS advisories that day, several covering Rockwell products: ControlFLASH under ICSA-26-246-03, where the installer grants write permission to the Everyone group on the product installation directory, the 1756-ENBT communications module under ICSA-26-246-05, and updates spanning 1734 POINT I/O, RSLinx Classic, FactoryTalk Activation Manager and the ControlLogix, CompactLogix, GuardLogix and Compact GuardLogix families. The ControlFLASH issue is a local permissions problem on the engineering workstation with no public exploitation reported, not a remote flaw. That is precisely why this class of advisory gets deferred in an Indian plant, and why it accumulates on the one machine that can rewrite controller logic.
Source (with date): CISA ICS advisories ICSA-26-246-03 and ICSA-26-246-05 (03 Sep 2026).
The ICS vulnerability record, and the tracking gap under it. As 2025 trend context rather than this cycle's news: Forescout counted 2,155 CVEs across 508 ICS advisories in 2025, the first year above 500 since records began, with the average advisory CVSS above 8.0. The more useful figure for an Indian plant is the coverage gap. Only 22 percent of 2025's ICS vulnerabilities had an associated CISA ICS advisory, down from 58 percent in 2024, and 61 percent of those without one were rated high or critical. A vulnerability-management programme keyed to CISA ICS advisories alone is tracking a minority of the problem; vendor PSIRT feeds have to be subscribed to directly.
Source (with date): Forescout, ICS Cybersecurity in 2026; Infosecurity Magazine (Feb 2026).
An AI-assisted intrusion reached for the SCADA interface without being asked to. Dragos documented an intrusion at a municipal water and drainage utility in Monterrey, Mexico in January 2026, part of a campaign against Mexican government bodies from December 2025 to February 2026 first identified by Gambit Security and tracked as TAT26-12. Commercial AI models served as the operational engine: building a large Python tooling framework, identifying a vNode SCADA and IIoT management interface without having been directed to look for control systems, and recommending and then attempting credential-spray rounds. The attackers reached the IT network; OT was not compromised, and this is not an autonomous attack on a control system. What changed is the time from access to working tooling.
Source (with date): Dragos; SecurityWeek (07 May 2026).
CEA (Cyber Security in Power Sector) Regulations, 2026. Notified by the Central Electricity Authority on 31 July 2026 and published on the Authority's site in August, mandatory from 1 April 2027. Scope covers power-sector entities operating OT and IT systems, including generating companies, captive plants and energy storage rated 50 MW and above; smaller facilities are encouraged rather than obliged. The regulations establish CSIRT-Power as the sector incident coordination agency, working with CERT-In and NCIIPC. The requirements to budget for now: OT networks physically separated from the internet and from conventional IT networks; real-time operational data carried only over dedicated secure channels, with critical information held on systems located in India; a CISO appointed for a minimum three-year tenure; a round-the-clock information security division; annual cyber audits with auditor rotation; and six-hour incident reporting to CSIRT-Power. Supplier obligations are written in as well, covering tested recovery plans, digitally signed patches and component documentation. Physical separation is the line item that carries a capital cost and a long lead time, and it is the one most often discovered late.
Source (with date): Central Electricity Authority (31 Jul 2026); SolarQuarter (14 Aug 2026).
Three reporting clocks, and they start together. CERT-In's April 2022 directions already require incident reporting within six hours, 180-day log retention within Indian jurisdiction and clock synchronisation to NPL. From April 2027 a power-sector entity adds a parallel six-hour route to CSIRT-Power, and where a system is notified as a protected system under section 70A of the IT Act, NCIIPC's obligations run alongside both. Test the routing out of hours now, not during an incident.
Source (with date): CERT-In directions (Apr 2022); Central Electricity Authority (31 Jul 2026).
Advisory AA26-097A was first published on 7 April 2026 by the FBI, CISA, NSA, EPA, DOE, USCYBERCOM and the Treasury, and updated on 22 July 2026. It covers Iranian-affiliated APT activity assessed as operating under the IRGC Cyber Electronic Command, previously documented under the CyberAv3ngers and Shahid Kaveh names. The July update is the part that matters here: it widened the scope from Rockwell CompactLogix and Micro850 to Schneider Electric BMX P34 and Modicon M340, and to Siemens S7-1200. Inbound activity was observed on ports 44818 and 2222 for Rockwell protocols, 102 for Siemens S7, 502 for Modbus, and 22 on cellular modems.
The tradecraft placed no bespoke malware on the controller. The actors ran the vendors' own engineering software, Studio 5000 Logix Designer, EcoStruxure Control Expert and TIA Portal, to extract project files from the devices, then modified ladder logic and Add-On Instructions, manipulated HMI and SCADA displays, and installed Dropbear SSH on modems for remote access. In one confirmed case the ladder logic was changed to disable safety shutdown and alarm functions, so an unsafe condition could develop without alerting an operator. The named sectors are water and wastewater, energy, and government facilities.
India is not named in this advisory and this is not an India-targeting campaign. It appears here for the target profile: small, lightly attended control sites reachable through a cellular modem, running a controller from one of three vendor families, with no separate control over the engineering workstation. That describes a substantial part of Indian municipal water and sewage pumping, small hydro, and feeder automation, where the OT is maintained by a contractor and the modem went in for a metering project years ago and was never inventoried. Detection here is not signature work. It is the engineering tool opening a session outside a maintenance window, and a difference between the logic on the controller and the last approved project file.
Source (with date): CISA advisory AA26-097A (07 Apr 2026, updated 22 Jul 2026).
Every entry below is already public in the named source and is reproduced with attribution. These are not Nirad observations. The table mixes atomic indicators with behavioural detection leads and CVE references; the Type column says which is which, and the leads need tuning against your own baseline before they are useful.
| Indicator | Type | Context | Source |
|---|---|---|---|
185.82.73[.]175, 141.11.164[.]153, 192.142.54[.]79, 84.200.205[.]165 | Atomic, IP address | PLC-targeting infrastructure, added in the 22 Jul 2026 update | CISA AA26-097A |
175.110.121[.]39, 175.110.121[.]41, 175.110.121[.]42, 175.110.121[.]107 | Atomic, IP address | PLC-targeting infrastructure, added in the 22 Jul 2026 update | CISA AA26-097A |
88.80.150[.]199, 88.80.150[.]200, 88.80.150[.]202 | Atomic, IP address | PLC-targeting infrastructure, added in the 22 Jul 2026 update | CISA AA26-097A |
185.225.17[.]225, 79.133.46[.]209 | Atomic, IP address | PLC-targeting infrastructure, added in the 22 Jul 2026 update | CISA AA26-097A |
185.82.73[.]162, 185.82.73[.]164, 185.82.73[.]165, 185.82.73[.]167, 185.82.73[.]168, 185.82.73[.]170, 185.82.73[.]171, 135.136.1[.]133 | Atomic, IP address | Historical set from the 07 Apr 2026 advisory | CISA AA26-097A |
| Dropbear SSH present on a cellular modem | Detection lead | PLC-targeting persistence | CISA AA26-097A |
| Inbound traffic on 44818, 2222, 102 or 502 from outside the OT network | Detection lead | Exposed controller protocols | CISA AA26-097A |
| Studio 5000, EcoStruxure Control Expert or TIA Portal session outside a maintenance window | Detection lead | Project-file extraction technique | CISA AA26-097A |
.ACD project file retrieved from a controller | Detection lead | Rockwell project-file theft | CISA AA26-097A |
| Ladder logic or Add-On Instruction differing from the last approved project | Detection lead, safety | Safety-logic tampering | CISA AA26-097A |
CVE-2026-83548, CVE-2026-83549 | CVE reference | SonicWall SMA1000, exploited | CISA KEV (02 Sep 2026) |
CVE-2026-86218 | CVE reference | N-able N-central pre-auth RCE, exploited | CISA KEV (08 Sep 2026) |
CVE-2026-19490 | CVE reference | Citrix NetScaler authentication bypass, public proof-of-concept | Citrix; Field Effect |
| GETA RAT, ARES RAT, Desk RAT | Malware families | APT36 and SideCopy tooling | Aryaka |
Board. Ask for a dated CEA 2026 readiness position with the physical-separation requirement costed, because that is a capital item and 1 April 2027 is two budget cycles away, not three. Ask which remote-access paths into the operational estate are operated by someone other than your own organisation, and who is accountable for patching each one. Ask whether third-party review extends to the parties your contractors themselves use, since that is the layer the Kudankulam exposure sat at. Confirm that the CISO appointment and the round-the-clock security division the regulations require are in the plan and not only in the policy document.
CISO. Patch on an emergency basis across SonicWall SMA1000, Citrix NetScaler and N-able N-central; on NetScaler, terminate existing sessions rather than treating the build upgrade as the end of it. Inventory every internet-reachable controller and every cellular modem attached to one, including sites handed over to a contractor, and remove the reachability rather than filtering it. Subscribe to vendor PSIRT feeds directly for Rockwell, Siemens, Schneider Electric and ABB, given how few 2025 ICS vulnerabilities received a CISA advisory. Hold a known-good copy of every PLC project file offline and compare it against the running logic on a schedule. Require managed service providers to report their own patch state on their management platforms in writing.
SOC. Hunt the indicators in section 6. On the perimeter, alert on SMA1000 Work Place requests reaching internal addresses and on NetScaler authentication events with no preceding credential submission. Inside the plant, alert on any engineering-software session outside a change window, on project-file reads from a controller, and on SSH to a field modem. Baseline OT protocol traffic on 44818, 2222, 102 and 502 now, so that an anomaly is visible later. Keep the APT36 and SideCopy detections in the active set, and confirm that the six-hour CERT-In notification path works out of hours.
Al Jazeera · Aryaka · Central Electricity Authority · CERT-In · CISA · CISA ICS advisories · CISA KEV · Citrix · Dragos · Field Effect · Forescout · Gambit Security · Help Net Security · Infosecurity Magazine · N-able · Nuclear Power Corporation of India · Rapid7 · Reuters · SecurityWeek · SolarQuarter · SonicWall · Sophos · The Hacker News · The Record
NBTF — Critical Infrastructure Sector Edition | 9 September 2026