惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

腾讯CDC
Microsoft Azure Blog
Microsoft Azure Blog
L
LangChain Blog
Y
Y Combinator Blog
Microsoft Security Blog
Microsoft Security Blog
宝玉的分享
宝玉的分享
B
Blog RSS Feed
MongoDB | Blog
MongoDB | Blog
Jina AI
Jina AI
D
Docker
B
Blog
Engineering at Meta
Engineering at Meta
Last Week in AI
Last Week in AI
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
I
InfoQ
G
Google Developers Blog
博客园 - Franky
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
The GitHub Blog
The GitHub Blog
T
The Blog of Author Tim Ferriss
大猫的无限游戏
大猫的无限游戏
阮一峰的网络日志
阮一峰的网络日志
U
Unit 42

Cybersecurity Dive - Latest News

Dozens of Red Hat npm packages targeted in supply chain attack Turning tension into collaboration: How CIOs and CISOs can lead together Trump signs EO seeking early government access to powerful AI models Anthropic shares Mythos with 150 more organizations, including critical infrastructure operators Without strong governance, companies put credit ratings at risk in AI era CISA adds critical Palo Alto Networks firewall flaw to KEV as company, researchers warn of exploitation How Canva scaled to 260+M users while elevating security and productivity Top 4 data security best practices for the AI-enabled enterprise CISA urges security teams to check for software development compromises How CISOs can manage sovereign-cloud security risks IBM’s new $5B initiative will help enterprises rapidly patch open-source vulnerabilities Enterprise data is creeping its way into shadow AI tools Coordinated operation takes down Glassworm botnet Leading AI models are more vulnerable to malicious prompts than vendors claim Iranian government, not hacktivist group, breached LA Metro system, security firm says FBI warns about PhaaS platform used to access Microsoft 365 environments Iran-linked hackers target key US, allied sectors with sophisticated spear-phishing messages New York regulator calls for additional cyber mitigation amid heightened threat environment CISA asks cybersecurity community to alert it to vulnerability exploitation Grafana Labs links GitHub environment breach to TanStack npm supply chain attack 7-Eleven hit by data breach Microsoft disrupts cybercrime operation that hid behind legitimate software Compromised coding tool helped hackers breach thousands of GitHub repositories Telecom sector launches its own private ISAC Patch bypass allows hackers to exploit prior flaw in SonicWall SSL-VPN Grafana Labs says hacker gained access to codebase through leaked token How a government contest launched a revolution in AI-based bug hunting Attackers exploit critical flaw in Cisco Catalyst SD-WAN Controller MSPs need AI to fight AI-fueled cyberthreats: Guardz More money is going to physical security, but it’s often CISOs that oversee it: EY
Iran-linked hackers target water, energy in US, FBI and C...
David Jones · 2026-04-08 · via Cybersecurity Dive - Latest News

An article from site logo

Nation-state actors have exploited flaws in industrial programmable logic controllers, leading to disruption and financial losses.

Published April 8, 2026

An Iranian flag flutters in front of a building with many windows

The flag of Iran is seen in front of the International Atomic Energy Agency (IAEA) headquarters on May 24, 2021, in Vienna, Austria. The FBI and CISA warned in April 2026 about Iran-linked hackers targeting devices in water, energy, and other critical infrastructure facilities. Michael Gruber via Getty Images

The FBI and the Cybersecurity and Infrastructure Security Agency in a joint advisory released Tuesday warned that Iran-linked threat actors have exploited internet-facing devices at U.S. critical infrastructure sites, including water, energy and municipal locations. 

The hackers have targeted programmable logic controllers (PLCs) made by Rockwell Automation/Allen-Bradley, in attacks involving malicious interactions with project files. The attacks led to data manipulation on both the human machine interface and supervisory control and data acquisition displays, according to the advisory.

The agencies did not specify the number or specific locations of the attacks, but noted the incidents resulted in financial losses and operational disruption, the advisory stated.

The Environmental Protection Agency, Department of Energy, National Security Agency and U.S. Cyber Command also participated in the advisory, which urged security teams to enable multifactor authentication, remove devices from the public internet and check logs for suspicious activity, as well as place physical-mode switches on Rockwell devices to the “run” position.

Rockwell Automation authentication bypass vulnerability

At the center of the campaign is an authentication bypass vulnerability in Rockwell Automation’s Logix controllers. Rockwell Automation in March updated an advisory on the flaw (CVE-2021-22681in its Studio 5000 Logix Designer software that could allow a cryptographic key to be found and let a non-Rockwell application connect with Logix controllers. 

The company at the time also issued an advisory reminding customers to disconnect devices from the open internet and harden security on their PLC environments. The Rockwell guidance was specifically referenced in the federal advisory Monday. 

The company “takes seriously the security of its products and solutions and has been closely coordinating with government agencies,” a spokesperson told Cybersecurity Dive. 

More than 3,000 Rockwell devices remain visible on the public internet, either because organizations are not aware they are exposed or they underestimate the risk, Markus Mueller, field CISO at Nozomi Networks, told Cybersecurity Dive. 

“The public exposure of these OT devices creates a vast attack surface that a motivated and capable adversary can exploit, which is especially relevant given the current conflict,” Mueller said. 

The recent attacks are reminiscent of prior exploitation of Unitronics PLCs by Iran hackers during the Gaza war in 2023-2024. The previous targeting was linked to an Islamic Revolutionary Guard Corp.-linked actor tracked as CyberAv3ngers.

Hundreds of U.S. water systems were found to have weak security configurations that exposed them to hacking and, in dozens of cases, water utilities were compromised. 

Iran-linked threat actors have targeted numerous critical infrastructure targets in Israel, the Persian Gulf region and the U.S. since the beginning of the war in late February. 

Stryker, a major U.S. medical technology provider, was attacked in March after hackers manipulated the company’s Microsoft Intune environment. The attack led to brief disruptions of the company’s manufacturing, ordering and shipping capabilities.