{"slug": "161764-assets-on-port-102-sizing-the-industrial-control-surface-that-aa26-231a", "title": "161,764 Assets on Port 102: Sizing the Industrial Control Surface That AA26-231A Described", "summary": "A joint cybersecurity advisory, AA26-231A, issued in August 2026 by the NSA, CISA, the FBI, the Department of Energy, and the EPA, warned that threat actors are using internet scanning services to locate exposed Siemens S7 programmable logic controllers and deploying AI-generated scripts built on snap7.dll and python-snap7 to read and write PLC memory over the S7comm protocol on TCP port 102. ZoomEye queries cited in the analysis return 173 assets fingerprinted as Siemens S7, 10,160 as Siemens SIMATIC, 95,395 classified as PLC devices, and 161,764 with port 102 reachable, figures the analysis says measure different things and should not be conflated.", "body_md": "Joint Cybersecurity Advisory AA26-231A warned in August 2026 that threat actors were using internet scanning services to locate exposed Siemens S7 programmable logic controllers. The advisory did not include a count. ZoomEye can supply one, provided the scope of each query is stated as carefully as the number itself.\n\nAA26-231A was issued on 2026-08-19 by the NSA, CISA, the FBI, the Department of Energy, and the Environmental Protection Agency. It describes actors using scanning services to find internet-exposed or poorly protected PLCs running outdated software, then employing AI-generated scripts built on the open-source snap7.dll and python-snap7 libraries and disguised as legitimate monitoring tools. Those scripts read and write PLC memory, configuration data, and ladder logic over the S7comm protocol, typically on TCP port 102.\n\nThe advisory names the S7-200, S7-300, S7-400, S7-1200, and S7-1500 families, including F-series safety controllers. It lists no CVE identifiers and no indicators of compromise, and it refers generally to known vulnerabilities and misconfigurations rather than a single shared defect.\n\nZoomEye can be queried at several levels of specificity for this subject, and the resulting numbers describe different things. Presenting them without that distinction would be misleading.\n\n| Query | What it measures | Count | Collected |\n\n| --- | --- | ---: | --- |\n\n| `app=\"Siemens S7\"` | Assets fingerprinted as Siemens S7 | 173 | 2026-09-16 |\n\n| `app=\"Siemens SIMATIC\"` | Assets fingerprinted as Siemens SIMATIC | 10,160 | 2026-09-16 |\n\n| `port=\"102\"` | Assets with port 102 reachable | 161,764 | 2026-09-16 |\n\n| `device=\"plc\"` | Assets classified as PLC devices | 95,395 | 2026-09-16 |\n\nThe narrowest query, `app=\"Siemens S7\"`, returns 173 assets. This is the most specific fingerprint and the smallest population. The broader `app=\"Siemens SIMATIC\"` fingerprint, which covers a wider product family that includes S7 controllers among other devices, returns 10,160.\n\nThe port-based query returns 161,764 assets with port 102 reachable. Port 102 is associated with S7comm, but reachability on that port does not establish that the responding service is a Siemens controller, and it certainly does not establish that the device is vulnerable. Other services and other vendors' equipment can occupy the same port.\n\nThe device-class query returns 95,395 assets classified as PLCs. That classification spans all vendors, so it describes the general programmable-controller surface rather than Siemens specifically.\n\nThe gap between 173 and 161,764 is not a contradiction. It is the difference between a product fingerprint, which requires the scanner to identify specific product characteristics, and a port reachability check, which requires only that something answers on a port.\n\nFor an organization assessing its own risk, the useful query depends on the question being asked. An asset owner asking \"how many of my Siemens S7 controllers are reachable\" needs the narrow fingerprint plus internal inventory data. A researcher asking \"how large is the protocol surface associated with S7comm\" needs the port query, with the caveat that the result is a protocol surface rather than a product population.\n\nThe advisory's own framing supports the broader reading. It notes that the targeting activity is broader than Siemens devices and that all PLC owners and operators should apply relevant mitigations. The 95,395 device-class figure is consistent with that framing.\n\nThe advisory's central claim is that actors use internet scanning services to find exposed controllers. That claim makes external exposure the operative risk factor, and it makes exposure reduction the primary mitigation. A controller that is not reachable from the internet cannot be located by an internet scanning service.\n\nThe advisory lists potential consequences of unauthorized access: disruption of industrial processes, safety incidents, equipment damage, data compromise, cascading effects, and compliance violations. It also notes that firmware updates addressing known vulnerabilities are available through Siemens ProductCERT, while Siemens has stated that the advisory does not describe a new vulnerability in the S7 series.\n\nThose two statements are compatible. The advisory addresses exploitation of known weaknesses and misconfigurations in exposed devices, not a single new defect. The response is therefore layered: reduce exposure, update firmware, strengthen authentication, and monitor for anomalous protocol activity.\n\nExternal exposure data is most useful to an asset owner as a cross-check rather than as a primary source. An organization that believes its controllers are segmented can query its own address space and compare the result against its network documentation. A discrepancy between the two is actionable regardless of what the global figures show.\n\nFor that purpose, the narrow product fingerprint is the appropriate query, because it targets the specific device family named in the advisory. The port query is appropriate for verifying that no unexpected service is answering on port 102 anywhere in an owned range.\n\nBoth queries should be run against owned address space only. Scanning address space an organization does not control is not part of an exposure assessment.\n\nThe counts above describe what ZoomEye indexed at collection time. They are not counts of vulnerable devices, and they are not counts of compromised devices. Product fingerprints describe identified products. Port counts describe reachable services. Device-class counts describe a classification that spans vendors.\n\nThe advisory itself supplies no CVE identifiers and no IOCs, so no detection rule in this article should be read as derived from a published indicator. The advisory's value is its description of an active reconnaissance campaign and its recommended mitigations.\n\n`app=\"Siemens S7\"` (173), `app=\"Siemens SIMATIC\"` (10,160), `port=\"102\"` (161,764), `device=\"plc\"` (95,395); collected 2026-09-16", "url": "https://wpnews.pro/news/161764-assets-on-port-102-sizing-the-industrial-control-surface-that-aa26-231a", "canonical_source": "https://dev.to/kozhevniko/161764-assets-on-port-102-sizing-the-industrial-control-surface-that-aa26-231a-described-hik", "published_at": "2026-09-17 02:47:07+00:00", "updated_at": "2026-09-17 03:23:03.644308+00:00", "lang": "en", "topics": ["ai-safety", "ai-policy", "artificial-intelligence"], "entities": ["NSA", "CISA", "FBI", "Department of Energy", "Environmental Protection Agency", "Siemens", "ZoomEye", "python-snap7"], "alternates": {"html": "https://wpnews.pro/news/161764-assets-on-port-102-sizing-the-industrial-control-surface-that-aa26-231a", "markdown": "https://wpnews.pro/news/161764-assets-on-port-102-sizing-the-industrial-control-surface-that-aa26-231a.md", "text": "https://wpnews.pro/news/161764-assets-on-port-102-sizing-the-industrial-control-surface-that-aa26-231a.txt", "jsonld": "https://wpnews.pro/news/161764-assets-on-port-102-sizing-the-industrial-control-surface-that-aa26-231a.jsonld"}}