Iran-linked crews are probing more flavors of US industrial kit
ID: 2ced4d7b-ea43-5798-9838-27b6d6363e05
STIX ID: report--2ced4d7b-ea43-5798-9838-27b6d6363e05
Feed Name: The Register (Security)
CISA expanded an advisory after observing Iranian-affiliated APTs targeting internet-facing PLCs (initially Rockwell/Allen-Bradley, now including Schneider Electric, Siemens and others) used in critical infrastructure; actors leveraged open ports and Dropbear SSH on victim modems to gain access, exfiltrate project files, and modify or delete logic — including disabling shutdowns and alarms — potentially allowing unsafe conditions. Authorities recommend disconnecting PLCs from public internet access, isolating architectures, auditing project files for unauthorized changes, changing defaults, and notifying service providers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
