LIVE · cybersecurity feed
Live wire
patch

US Warns of Iranian Hackers Targeting Siemens, Schneider, and Rockwell ICS Devices

An updated advisory from federal agencies provides information on the techniques used to hack programmable logic controllers. The post US Warns of Iranian Hackers Targeting Siemens, Schneider, and Rockwell ICS Devices appeared first on SecurityWeek.

zeroday.news · 9d ago

Federal agencies have issued an updated advisory warning of Iranian-backed hackers actively targeting Industrial Control Systems (ICS) devices, specifically naming products from Siemens, Schneider Electric, and Rockwell Automation. The advisory details the techniques employed by these threat actors to compromise Programmable Logic Controllers (PLCs), critical components in industrial environments.

The reported activity indicates a focused effort by the Iranian-backed groups to gain unauthorized access and potentially manipulate PLCs. These devices are the operational brains of many industrial processes, responsible for automating tasks and controlling machinery. Compromise of PLCs can lead to significant disruptions, equipment damage, or even safety hazards within critical infrastructure and manufacturing sectors.

While the advisory does not specify the exact vulnerabilities exploited, attacks on PLCs often leverage a range of methods. These can include exploiting known software vulnerabilities in the PLC firmware or associated management software, weak or default authentication credentials, or network-based attacks that bypass perimeter defenses to reach the control network. Phishing campaigns targeting engineers and operators to steal credentials are also a common initial access vector for such sophisticated threat actors.

The named vendors — Siemens, Schneider Electric, and Rockwell Automation — are major providers of industrial automation and control systems globally. Their products are widely deployed across various critical infrastructure sectors, including energy, water, manufacturing, and transportation. The broad scope of these vendors suggests a potentially wide range of affected organizations.

Typical mitigation strategies for defending against such threats include implementing robust network segmentation to isolate ICS networks from enterprise networks, enforcing strong authentication mechanisms, regularly patching and updating PLC firmware and associated software, and conducting thorough security audits of industrial control systems. Additionally, continuous monitoring for unusual activity on ICS networks and employee training on cybersecurity best practices are crucial.

This warning underscores the persistent and evolving threat landscape facing industrial control systems. Nation-state actors, such as the reported Iranian-backed groups, continue to demonstrate capabilities and intent to target critical infrastructure. The focus on PLCs highlights the strategic importance of these devices in industrial operations and the potential for significant impact should they be compromised.

patch
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerabilitycritical

Rails patches critical Active Storage flaw with RCE potential

A critical vulnerability in the Active Storage framework can allow an unauthenticated attacker to read arbitrary files from a Rails application, and potentially escalate to remote code execution (RCE). [...]

CVE-2026-48449critical

Adobe fixed a maximum-severity vulnerability flaw in Campaign Classic

Adobe fixed a maximum severity vulnerability in Campaign Classic that could let attackers run code remotely without user interaction. Adobe has addressed a critical vulnerability, tracked as CVE-2026-48449 (CVSS score of 10.0), in Adobe Campaign Classic, the company’s enterprise marketing automation platform. The flaw is caused by incorrect authorization and could allow attackers to execute […]

vulnerabilitycritical

Ruby on Rails Patches Critical Vulnerability

The flaw can be exploited by unauthenticated attackers to read arbitrary files and potentially achieve remote code execution (RCE). The post Ruby on Rails Patches Critical Vulnerability appeared first on SecurityWeek.

malware

Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens

Microsoft says Russian hackers hijacked hotel Wi-Fi portals to spread malware and steal Microsoft 365 tokens from travelers. Microsoft Threat Intelligence disclosed CaptiveCrunch, a campaign it attributes to Storm-2945, an operational sub-cluster of Midnight Blizzard, the Russian SVR-linked group also known as APT29 and Cozy Bear. Since early May 2026, Storm-2945 has been manipulating DNS […]

security

Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments

The funding round was led by SYN Ventures, with participation from existing investors DataTribe and TEDCO. The post Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments appeared first on SecurityWeek.

ai

7 States’ Water Systems Hit by Cyberattacks Likely Tied to Iran

Plus: The FBI eyes AI-powered tech to detect future crimes, Russia charges Telegram’s founder, xAI sues to stop a state’s “nudification” ban, and the Democrats learn a lesson about getting scammed.