Iranian Hackers Target Siemens and Schneider Industrial Systems, CISA Warns
ID: 0b352ed4-0817-5224-9270-a45385a16269
STIX ID: report--0b352ed4-0817-5224-9270-a45385a16269
Feed Name: Infosecurity Magazine (News)
CISA and the FBI warn that Iranian-affiliated actors are actively targeting internet-exposed PLCs and industrial systems across Rockwell/Allen-Bradley, Schneider Electric and Siemens by using vendor configuration software on third-party hosted infrastructure to exfiltrate project files, inject malicious ladder logic that overrides safety instructions, and manipulate HMI/SCADA displays, causing operational disruption and financial loss across government, water/wastewater and energy sectors; the advisory lists targeted models, relevant ports and IOCs and recommends removing direct Internet exposure, reviewing logs, and following vendor security best practices.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
