CISA widens alert beyond Rockwell controllers as intruders target internet-facing devices across critical infrastructure

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has broadened its alert regarding Iranian-affiliated hacking groups targeting critical infrastructure, including facilities in the water and energy sectors. Initially, the advisory concentrated on programmable logic controllers (PLCs) produced by Rockwell Automation/Allen-Bradley. However, the updated warning indicates that these activities may now also involve devices from Schneider Electric, Siemens, and potentially other PLC brands.
This expansion of the alert comes as the conflict between the U.S. and Iran enters its fourth month, with authorities observing Iranian-affiliated advanced persistent threat (APT) groups attempting to disrupt PLCs since March. PLCs are essential components used for controlling and monitoring industrial processes.
The observed activity bears resemblance to previous attacks on PLCs attributed to CyberAv3ngers, also known as the Shahid Kaveh Group. This group is reportedly affiliated with the Islamic Revolutionary Guard Corps (IRGC) Cyber Electronic Command (CEC) in Iran.
The primary focus of these attacks is on internet-facing PLCs, with CISA noting that attackers are targeting devices through open ports. The targeting of ports associated with protocols used by other operational technology (OT) vendors suggests an opportunistic approach, extending beyond Rockwell Automation/Allen-Bradley to include devices from companies like Schneider Electric and Siemens.
In one documented instance, the attackers leveraged Dropbear Secure Shell (SSH) software on victim modems to establish remote access via port 22. Once access was gained, the attackers proceeded to extract device project files and either modify or delete their logic.
CISA further reported that these modifications included disabling critical shutdown and alarm logic. This allowed systems to enter unsafe conditions without notifying operators of the anomalies, posing significant risks to operational safety and integrity.
The broadened scope of the advisory underscores the critical need for organizations to be vigilant about their internet-accessible devices. Beyond earlier recommendations to disconnect PLCs from the public internet, authorities now suggest implementing isolated architectures and strictly controlling network access to PLC devices.
Additionally, organizations are advised to regularly inspect project files running on PLCs for any unauthorized changes. It is also crucial to ensure that service providers are aware of the threats targeting PLCs and that all default passwords are changed to stronger, unique credentials.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed