Iran cyber actors disrupting US water, energy facilities, FBI warns
ID: ee8d4b95-0401-5c17-9e40-b1b2272b095c
STIX ID: report--ee8d4b95-0401-5c17-9e40-b1b2272b095c
Feed Name: The Register (Security)
US government agencies (FBI, CISA, NSA, EPA, DOE, and US Cyber Command) warned that Iranian-affiliated APT actors have escalated intrusions against US water and energy facilities, targeting internet-exposed Rockwell/Allen‑Bradley PLCs, HMIs, and SCADA displays to disrupt operations. The advisory notes past use of default credentials and later custom malware (attributed to CyberAv3ngers), reports operational disruptions and financial loss, and recommends disconnecting internet-exposed OT, applying patches, enabling MFA, following vendor guidance, and monitoring ports 44818, 2222, 102, and 502 for suspicious traffic.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
