惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

酷 壳 – CoolShell
酷 壳 – CoolShell
H
Hacker News: Front Page
P
Palo Alto Networks Blog
T
ThreatConnect
Apple Machine Learning Research
Apple Machine Learning Research
博客园_首页
T
True Tiger Recordings
P
Privacy & Cybersecurity Law Blog
B
Blog
IT之家
IT之家
Last Week in AI
Last Week in AI
F
Full Disclosure
Hacker News: Ask HN
Hacker News: Ask HN
C
Comments on: Blog
Microsoft Azure Blog
Microsoft Azure Blog
C
Cybersecurity and Infrastructure Security Agency CISA
Microsoft Security Blog
Microsoft Security Blog
博客园 - 【当耐特】
N
News and Events Feed by Topic
NISL@THU
NISL@THU
腾讯CDC
雷峰网
雷峰网
Security Latest
Security Latest
李成银的技术随笔
M
Microsoft Research Blog - Microsoft Research
L
LangChain Blog
L
Lohrmann on Cybersecurity
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
C
Check Point Blog
Y
Y Combinator Blog
Recent Announcements
Recent Announcements
博客园 - Franky
N
News | PayPal Newsroom
V
V2EX
A
About on SuperTechFans
The Register - Security
The Register - Security
月光博客
月光博客
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Google Online Security Blog
Google Online Security Blog
MyScale Blog
MyScale Blog
Cisco Talos Blog
Cisco Talos Blog
Vercel News
Vercel News
WordPress大学
WordPress大学
C
Cyber Attacks, Cyber Crime and Cyber Security
The Hacker News
The Hacker News
IntelliJ IDEA : IntelliJ IDEA – the Leading IDE for Professional Development in Java and Kotlin | The JetBrains Blog
IntelliJ IDEA : IntelliJ IDEA – the Leading IDE for Professional Development in Java and Kotlin | The JetBrains Blog
爱范儿
爱范儿
A
Arctic Wolf
L
LINUX DO - 最新话题
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More

Truesec

Securing IT, OT, and IoT When the Digital Meets the Physical Russia Rolls Out Surveillance Through State-Backed “Super App” MAX Device Code Phishing via Fake File-Sharing Invitation Active Exploitation of PAN‑OS Authentication Portal RCE Windows Client Security Baselines: When Assumptions Meet Incident Response Reality Entra ID Password Protection: From “P@ssw0rd” to Protected GitHub Under Attack: How Small Exposures Snowball into Large‑Scale Compromises European Risks Linked to the U.S. – Iran Conflict Mythos: What It Actually Means and What It Does Not Russian Espionage Campaign Targets Home Routers How Nordic Organizations Must Adjust Their Cybersecurity to a Changing Operating Environment Critical Vulnerability in “Ninja Forms – File Upload” WordPress Plugin (CVE-2026-07409) Remote Access – Is VPN the Almighty Solution? Malicious Axios Packages Published to npm in New Supply Chain Compromise RCE Vulnerability in F5 BIG-IP APM (CVE-2025-53521) No Further Increase in Iranian Cyber Operations Malicious PyPI Package – LiteLLM Supply Chain Compromise Dutch Intelligence Warns of Russian Campaign Against Signal and Whatsapp Users Multiple Vulnerabilities, One Critical, in Ubiquiti UniFi Network Application
Iranian APT Target US Critical Infrastructure
2026-04-10 · via Truesec

Threat Insight

On April 7, CISA, together with the FBI, NSA, and several other U.S. government agencies, issued a joint advisory regarding active exploitation of internet‑facing operational technology (OT) devices. The activity is focused on programmable logic controllers (PLCs) from Rockwell Automation / Allen‑Bradley, with the advisory noting that other PLC platforms may also be at risk. [1]

The advisory confirms that several U.S. critical infrastructure sectors have already experienced operational disruption. In response, CISA urges organizations to actively assess their environments against the published tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs) to determine whether they are currently affected or have been compromised in the past. [1]

U.S. authorities assess the activity to be conducted by Iranian‑affiliated advanced persistent threat (APT) actors. Impacted sectors include government services and facilities, water and wastewater management, and energy. Similar PLC‑focused activity has previously been attributed to CyberAv3ngers, also known as the Shahid Kaveh Group, which has established links to Iran’s Islamic Revolutionary Guard Corps (IRGC) Cyber Electronic Command (CEC). [1]

The context is relevant. The activity coincides with a period of heightened geopolitical tension, occurring just days ahead of a Pakistani‑brokered ceasefire involving the U.S., Israel, and Iran, with further negotiations scheduled in Islamabad on April 11. At the same time, tensions in the Strait of Hormuz remain elevated, with limited maritime traffic despite public statements that the route is open, and reports of transit restrictions and significant tolls imposed by Iran. [2]

Assessment

This activity fits a long‑standing Iranian cyber approach, where OT and critical infrastructure environments are used as leverage during periods of geopolitical pressure. Based on historic targeting patterns and current intelligence, the United States and Israel remain the primary focus of Iranian threat actors.

That said, European organizations should not view this activity as geographically contained. OT environments often rely on shared vendors, similar architectures, and comparable exposure models. As a result, European organizations operating the same PLC platforms face overlapping technical risk, even when they are not the primary strategic target.

Organizations in Europe using Rockwell Automation / Allen‑Bradley PLCs or other internet‑accessible OT components should follow the actions recommended by CISA. [1] This includes reviewing external exposure, validating segmentation and access controls, and ensuring adequate monitoring and logging for OT‑specific activity. With U.S. and Iranian negotiations expected to continue over the weekend, maintaining situational awareness is prudent.

For critical infrastructure operators, understand your OT attack surface, confirm visibility across industrial environments, and be ready to act on relevant indicators tied to the published TTPs. A measured, intelligence‑led response remains the most effective course of action.

References

[1] https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-097a
[2] https://www.bbc.com/news/articles/cp3l4yk5rlgo