Iranian cyber activity hits US energy, water, and government networks
ID: e3981580-a0f4-556d-9bf4-eb042148d882
STIX ID: report--e3981580-a0f4-556d-9bf4-eb042148d882
Feed Name: Help Net Security
U.S. federal cybersecurity and law enforcement agencies warned that Iranian-affiliated APT actors have been accessing internet-exposed PLCs (including Rockwell/Allen-Bradley devices) using overseas IPs and leased infrastructure, sometimes via legitimate engineering software, to extract project files and manipulate HMI/SCADA displays—causing operational disruptions and financial loss across multiple critical infrastructure sectors. Agencies recommend disconnecting PLCs from public internet access, limiting remote connectivity, enabling programming protections or physical run switches, maintaining backups, and validating/log-reviewing suspicious activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
