Two August KEV additions put CISA’s most aggressive remediation tier into practice for the first time. The operational shift isn’t the calendar, it’s the requirement to determine whether an attacker got there first.
A three month investigation into a December 2025 attack on a Polish combined heat and power plant found something no one had documented before: attackers reaching an operational technology network through a private cellular APN. There was no exploited CVE and no malware. Every destructive step used a supported device function.