Volt Typhoon — the state-sponsored group US agencies have tracked living quietly inside power, water, and comms networks — drew a fresh writeup from CISA on Thursday. The update leans on detection rather than new headlines: a day earlier the agency had expanded its guidance on spotting malicious changes tucked into reusable code modules inside industrial PLC programs, widening the manufacturer scope past Rockwell to Schneider Electric and Siemens. If you defend OT or critical-infrastructure systems, the value here is the hunting content, not a new incident — same actor, more concrete detection than the original advisory carried. Worth the read if PLCs sit anywhere in your threat model.