07/22/2026 2:30 PM EST

Today, the Cybersecurity and Infrastructure Security Agency (CISA), in partnership with the Federal Bureau of Investigation (FBI), National Security Agency (NSA), Environmental Protection Agency (EPA), Department of Energy (DOE), United States Cyber Command – Cyber National Mission Force (CNMF), and Department of the Treasury (Treasury) released an updated joint Cybersecurity Advisory Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure.
This update re-emphasizes the ongoing threat from Iranian-affiliated advanced persistent threat (APT) actors targeting internet-connected operational technology (OT) devices, including programmable logic controllers (PLCs) manufactured by Rockwell Automation/Allen-Bradley, Schneider Electric, Siemens, and potentially other brands/manufacturers. These attacks have resulted in operational disruptions and financial losses across multiple U.S. critical infrastructure sectors, including Government Services and Facilities, Water and Wastewater Systems, and Energy.
What’s New in This Update:
- Expanded Targeting: The advisory now includes observed targeting of Schneider Electric and Siemens PLCs, in addition to Rockwell Automation/Allen-Bradley and potentially other branded/manufacturer devices.
- Updated Technical Details: New information on threat actor tactics, including use of configuration software to exfiltrate device project files, and expanded details on targeted ports and device models.
- Enhanced Mitigations: Additional recommendations for securing cellular modems, implementing isolated architectures, validating project files, and detecting malicious changes in reusable code modules (such as Add-On Instructions/AOIs).
- New Indicators of Compromise (IOCs): Updated tables of internet protocol (IP) addresses and timeframes associated with Iranian-affiliated APT activity.
Iranian-affiliated APT actors continue to adapt their tactics, targeting a wider range of devices and sectors. Proactive review of this advisory and implementation of the recommended mitigations are critical to defending your organization’s OT assets and ensuring operational resilience.
Learn more by reading the updated advisory and reviewing CISA’s Iran Threat Overview and Advisories.
Discover more from #News247WorldPress
Subscribe to get the latest posts sent to your email.

