Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure
ID: c6b0870e-113e-5cf3-9ae4-c3ab1c78eb61
STIX ID: report--c6b0870e-113e-5cf3-9ae4-c3ab1c78eb61
Feed Name: DataBreaches.Net
Threat Score
CISA warns that Iran-affiliated APT actors are actively exploiting internet-facing OT devices—notably Rockwell/Allen-Bradley PLCs—to disrupt controllers and manipulate HMI/SCADA displays, causing operational disruption and financial loss; the advisory includes affected products, IOCs, TTPs, recommended mitigations, and guidance to remove PLCs from direct internet exposure and check logs for suspicious traffic on OT-related ports.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
