LIVE · cybersecurity feed
Live wire
security

Federal agencies broaden alert on Iran-linked OT attacks

The observed incidents include “malicious project file interactions and manipulation of data on human machine interface (HMI) and supervisory control and data acquisition (SCADA) displays,” the advisory says.

zeroday.news · 10d ago

Federal agencies have broadened an alert regarding attacks on internet-facing operational technology (OT) by hackers linked to the Iranian regime. The updated warning, issued by the Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), and the Environmental Protection Agency (EPA), expands on an initial advisory from April.

The initial alert focused on programmable logic controllers (PLCs) manufactured by Rockwell Automation and Allen-Bradley. The revised advisory now includes observed targeting of Schneider Electric and Siemens PLCs, along with the possibility of other manufacturers.

According to CISA, the observed incidents involve "malicious project file interactions and manipulation of data on human machine interface (HMI) and supervisory control and data acquisition (SCADA) displays." These attacks have resulted in "operational disruption and financial loss" for targeted organizations.

PLCs are fundamental components in critical infrastructure sectors such as power utilities, wastewater treatment facilities, and manufacturing plants. Officials anticipate that the pressure from Iran-affiliated attackers will persist.

The agencies emphasized the importance for OT owners and operators to restrict direct internet access to these systems and ensure secure PLC deployment. PLCs from Schneider Electric and Siemens are extensively deployed both within the United States and internationally.

The advisory does not specify particular cyberthreat groups or individual attacks. Cybersecurity researchers note that attributing attacks to the Iranian government can be complex, as the regime has been known to utilize ransomware gangs or other groups as proxies to obscure its involvement. For instance, a pro-Iranian hacktivist group that targeted a Los Angeles transit agency was later identified by researchers as an arm of Iran’s intelligence services.

ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes

An attacker drained 1,196 Bitcoin addresses in 41 minutes on July 30, taking 1,082.65 BTC worth about $70.2 million at the time. Galaxy Research mapped the sweep and tied it to a firmware flaw in Coldcard, the Bitcoin-only hardware wallet made by Canadian firm Coinkite. A March 2021 firmware integration error routed seed generation to a deterministic software pseudorandom number generator (PRNG

vulnerabilitycritical

Rails patches critical Active Storage flaw with RCE potential

A critical vulnerability in the Active Storage framework can allow an unauthenticated attacker to read arbitrary files from a Rails application, and potentially escalate to remote code execution (RCE). [...]

malware

Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens

Microsoft says Russian hackers hijacked hotel Wi-Fi portals to spread malware and steal Microsoft 365 tokens from travelers. Microsoft Threat Intelligence disclosed CaptiveCrunch, a campaign it attributes to Storm-2945, an operational sub-cluster of Midnight Blizzard, the Russian SVR-linked group also known as APT29 and Cozy Bear. Since early May 2026, Storm-2945 has been manipulating DNS […]

CVE-2026-48449critical

Adobe fixed a maximum-severity vulnerability flaw in Campaign Classic

Adobe fixed a maximum severity vulnerability in Campaign Classic that could let attackers run code remotely without user interaction. Adobe has addressed a critical vulnerability, tracked as CVE-2026-48449 (CVSS score of 10.0), in Adobe Campaign Classic, the company’s enterprise marketing automation platform. The flaw is caused by incorrect authorization and could allow attackers to execute […]

security

Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments

The funding round was led by SYN Ventures, with participation from existing investors DataTribe and TEDCO. The post Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments appeared first on SecurityWeek.

vulnerabilitycritical

Ruby on Rails Patches Critical Vulnerability

The flaw can be exploited by unauthenticated attackers to read arbitrary files and potentially achieve remote code execution (RCE). The post Ruby on Rails Patches Critical Vulnerability appeared first on SecurityWeek.