Full analysis, recommended actions, tabletop scenarios, and cited sources in the complete issue.
INCIDENT · HIGH
Brazil’s submarine yard went dark on 9 August. The record of it arrived on the 22nd, from the people who did it.
Itaguaí Construções Navais — the yard responsible for Brazil’s submarine development programme, PROSUB, building conventional boats for the Brazilian Navy and working on the nuclear-propelled project — identified a ransomware attack at around 23:00 on Sunday 9 August. Data in the IT environment was encrypted: mail servers, systems, files, databases. The company shut the environment down immediately to stop the malware spreading, and brought in specialist firms for a full scan, root-cause investigation, server rebuild and restoration from backup.
Then nothing. The website stayed offline. The company did not respond to the one regional journalist who asked, and has never said publicly whether this was encryption only or whether data was also accessed, copied or transferred. Thirteen days later, on 22 August, the LockBit5 leak site listed the yard’s domain. As of 1 September the company has still issued no statement of its own.
Why it matters: for twenty-two days, the only account of what happened at a state-owned naval shipbuilder came from a regional newspaper the company declined to speak to. The second account came from the attacker. That gap is a supply-chain problem before it is a communications one. Subcontractors, equipment suppliers and classification surveyors downstream cannot assess their own exposure without knowing whether design data or credential material left the network, and the absence of a data-theft denial is not the same as a denial. Anyone sharing a portal, a transfer account or an engineering-collaboration platform with the yard is currently working from a picture written by the people who attacked it.
OT/ICS · HIGH
The exploit was written by a machine, and dressed up as your monitoring software
On 19 August the NSA, CISA, the FBI, the Department of Energy and the Environmental Protection Agency jointly published advisory AA26-231A. Threat actors are conducting reconnaissance and capability development against Siemens PLC installations “using AI-generated exploitation scripts disguised as legitimate monitoring tools.” The method is spelled out: open-source automation libraries — snap7 — combined with AI-assisted scripting to build custom tools that mimic legitimate OT monitoring software, giving read and write access to controller memory, configuration and ladder logic over S7comm on TCP port 102. Targets are found through Censys and ZoomEye. Affected: S7-200, S7-300, S7-400, S7-1200 and S7-1500, including F-series safety controllers.
The agencies say why the AI part matters instead of leaving it as colour: it “dramatically reduc[es] the technical expertise and time required to develop working ICS exploitation scripts and malicious tools.”
Why it matters: the advisory tells a maritime reader two things at once, and both are true. The six sectors named as most targeted do not include transportation — and the advisory’s own opening line says the targeting “is broader than Siemens PLCs” and that all PLC owners should apply the mitigations. S7 controllers run ship-to-shore and yard cranes, lock gates, bunkering and loading skids, ballast treatment and ro-ro ramp hydraulics, and the advisory’s specific warning about third-party integrators with remote access is squarely a port problem: most terminal PLC estates are maintained by an OEM or integrator, and the asset owner frequently does not know which remote paths exist. The vulnerability has not changed. What has changed is how many people can now build a working, disguised tool against it.