惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Blog — PlanetScale
Blog — PlanetScale
J
Java Code Geeks
N
Netflix TechBlog - Medium
Martin Fowler
Martin Fowler
A
About on SuperTechFans
腾讯CDC
B
Blog RSS Feed
H
Hackread – Cybersecurity News, Data Breaches, AI and More
Microsoft Azure Blog
Microsoft Azure Blog
D
Docker
Y
Y Combinator Blog
Microsoft Security Blog
Microsoft Security Blog
F
Fortinet All Blogs
I
InfoQ
博客园 - 【当耐特】
美团技术团队
GbyAI
GbyAI
量子位
宝玉的分享
宝玉的分享
爱范儿
爱范儿
有赞技术团队
有赞技术团队
博客园 - Franky
L
LangChain Blog
阮一峰的网络日志
阮一峰的网络日志

Truesec

CRA Reporting Starts on 11 September: What Businesses Need To Know - Truesec Privilege Escalation Vulnerability in Falcon Crowdstrike - Truesec SonicWall Vulnerabilities Exploited in the Wild - Truesec Privileged Access Management (PAM) Is No Longer Optional  - Truesec Australian Arrests Allegedly Disrupt TeamPCP, but the Shai-Hulud Threat Persists - Truesec DDoS Attacks Against Norwegian Government Sites - Truesec Critical Citrix NetScaler Memory-Overflow Vulnerability - Truesec Russia Targets Businesses and Officials Behind Europe’s Ukraine Defense Supply Chain - Truesec The World Is Moving at Machine Speed. Are We Ready? - Truesec False CVE in Overwhelmed Verification System - Truesec LLMjacking Is a New Cyber Threat - Truesec Rogue AI Agent Allegedly Hack Hugging Face - Truesec Microsoft SharePoint Server Vulnerabilities Actively Exploited - Truesec Russian Intelligence Targets SOHO Routers - Truesec Cyber Warfare in the Iran War - Truesec Organized Cybercrime Merging with Other Crime - Truesec AI Used in Ransomware Attack The Fortibleed Campaign: Truesec's Experience Fortibleed: Truesec's Experience Supply Chain Attack Compromising Arch Linux AUR Packages with Infostealer and Rootkit - Truesec FortiNet SSO Vulnerability CVE-2025-59718 and CVE-2025-59719 Leading to Full System Compromise - Truesec Critical Vulnerabilities in Ivanti Sentry Allows Code Execution as Root (CVE-2026-10520 & CVE-2026-10523) Typosquatting: When Your Domain Is Used Against You AI in Cybersecurity: Separating Operational Reality from Speculation Compromised @redhat-Cloud-Services Npm Packages Distribute Credential-Stealing Worm GitHub Hacks Highlights Need for Repository Security Installation of a Syslog Log Collector Critical Cisco Secure Workload Vulnerability Allows Unauthenticated Site Admin Access (CVE-2026-20223) Securing IT, OT, and IoT When the Digital Meets the Physical Russia Rolls Out Surveillance Through State-Backed “Super App” MAX
Iranian Cyberattacks Against Critical Infrastructure - Tr...
Hjalmar Desmond · 2026-08-24 · via Truesec

Threat Insight

An Iranian threat actor has conducted a series of cyberattacks against critical infrastructure in USA and UK in late July 2026. Known targets include several community water treatment facilities in Minnesota, USA [1] and a relatively small energy plant in Britain. [2]

The attacks appear to have targeted operational technology (OT) devices like programmable logic controllers (PLCs). A warning from FBI specifically mentioned Rockwell Automation and Allen-Bradley PLCs – particularly the MicroLogix 1100 and 1400 series – although systems using PLCs from other brands were also advised to be cautious. [1]

Assessment

Based on available information, it appears that these attacks have been mostly unsophisticated and opportunistic attacks targeting relatively small plants with minimum security, likely having OT devices exposed to the internet without proper protection. Given the limited impact of these attacks, it appears they were mostly aimed at creating psychological impact rather than real damage.

Truesec has previously assessed that the risk of destructive cyberattacks from Iran against Europe as low, as long as European countries don’t get directly involved in the conflict between USA and Iran. This assessment still stands.

While UK and France are not participating in the US led attacks on Iran. Both countries are honoring their bilateral defense agreements with several Gulf-states and assist them in shooting down incoming Iranian missiles, which is likely the reason Iran have also targeted Britain in the wave of cyberattacks.

The main threat to critical infrastructure in the Nordics is still Russian threat actors. The above attacks still highlight the need for heightened cybersecurity awareness in all parts of critical infrastructure, not just the most vital parts of it. Swedish authorities have previously announced that a Russian threat actor has attempted a similar attack against a Swedish power plant. [3]

If you or your organization have concerns about the topic above or need support, please reach out to your Truesec contact for further assistance.

References

[1] https://www.fbi.gov/investigate/cyber/alerts/2026/malicious-cyber-actors-targeting-water-and-wastewater-sector-internet–facing-programmable-logic-controllers-causing-operational-disruptions
[2] https://www.telegraph.co.uk/news/2026/08/22/iranian-hackers-shut-down-uk-power-plant/
[3] https://www.tv4.se/artikel/17J99Fsf8GKue4fYSFcxVF/proryskt-angreppsfoersoek-mot-svenskt-vaermeverk