logo

Iran-linked crews are probing more flavors of US industrial kit

ID: 2ced4d7b-ea43-5798-9838-27b6d6363e05

STIX ID: report--2ced4d7b-ea43-5798-9838-27b6d6363e05

Feed Name: The Register (Security)

Threat Score
88/100

Date Published: 2026-07-23

Date Updated: 2026-07-23

...
...

CISA expanded an advisory after observing Iranian-affiliated APTs targeting internet-facing PLCs (initially Rockwell/Allen-Bradley, now including Schneider Electric, Siemens and others) used in critical infrastructure; actors leveraged open ports and Dropbear SSH on victim modems to gain access, exfiltrate project files, and modify or delete logic — including disabling shutdowns and alarms — potentially allowing unsafe conditions. Authorities recommend disconnecting PLCs from public internet access, isolating architectures, auditing project files for unauthorized changes, changing defaults, and notifying service providers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.