CISA has expanded the scope of its alert on Iranian-affiliated hackers attacking critical infrastructure


The US Cybersecurity and Infrastructure Security Agency (CISA) has expanded the scope of its alert on Iranian-affiliated hackers attacking critical infrastructure, including water and energy facilities.

The original advisory focused on programmable logic controllers (PLCs) manufactured by Rockwell Automation/Allen-Bradley. The update warns that the activity may also target devices from Schneider Electric, Siemens, “and potentially other branded/manufactured PLCs.”

The conflict between the US and Iran is well into its fourth month, and authorities have noticed Iranian-affiliated advanced persistent threat (APT) crews targeting PLCs to cause disruption since March.

Read more…
Source:  The Register


Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox


Related:

  • A new Android attack combines malware and ransomware in a cocktail of cybercrime

    September 11, 2026

    Unique malware variant spotted targeting Android users. When threat actors target people’s devices, they usually infect it with one of many malware strains: an infostealer, a remote access trojan, a backdoor, or a ransomware encryptor. Rarely do we see all of these functionalities merged into a single entity, and even rarer – to have it target Android ...

  • ShinyHunters expose 6.4M in attack on medical supplier McKesson

    September 10, 2026

    McKesson’s cyberattack last month affected roughly 6.4 million individuals, according to Have I Been Pwned (HIBP). The breach notification service added data leaked by serial extortionists ShinyHunters, revealing the scale of the attack for the first time. ShinyHunters initially claimed to have stolen 284 million documents from the medical and pharmaceutical supply company in August, although HIBP ...

  • Protecting organizations from AI-assisted executive impersonation and invoice fraud

    September 10, 2026

    Threat actors are increasingly improving their tactics to make suspicious emails look like legitimate email notifications to potential victims, deploying techniques that impersonate internally sent emails from executive team members. While this technique is not new, the adoption of AI has enabled threat actors to improve their campaign templates and construct emails tailored to their ...

  • Anthropic researcher resigns with warning about the dangers of AI development

    September 9, 2026

    An Anthropic researcher said he is resigning from the company over concerns the artificial intelligence firm and its competitors are not acting responsibly in AI development, echoing concerns raised inside and outside of the industry about the technology’s potential to elude human control. Jacob Coxon, who said he spent three years doing research at both Anthropic and ...

  • CISA, NSA, FBI warn Chinese AI firms of industrial‑scale knowledge distillation

    September 9, 2026

    Chinese AI companies’ core development strategy is to steal proprietary functionalities and capabilities from their US counterparts, law enforcement agencies have warned. The US Cybersecurity and Infrastructure Security Agency (CISA) has published a new security advisory, drafted jointly with the National Security Agency (NSA) and the Federal Bureau of Investigation (FBI), warning American AI companies about an ongoing “aggressive, malicious, ...

  • Microsoft fixes record 964 flaws, including 2 exploited zero-days

    September 9, 2026

    Microsoft’s September 2026 Patch Tuesday addresses 964 CVEs, including 104 rated Critical and 860 rated Important, making it the company’s largest Patch Tuesday release on record. Microsoft lists 974 CVEs in its full September security release. However, 10 of those affect cloud services or involve fixes that Microsoft applies itself, leaving 964 vulnerabilities that customers need to patch. The ...