惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

雷峰网
雷峰网
博客园 - 聂微东
酷 壳 – CoolShell
酷 壳 – CoolShell
宝玉的分享
宝玉的分享
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
罗磊的独立博客
Hugging Face - Blog
Hugging Face - Blog
T
Tailwind CSS Blog
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
IT之家
IT之家
博客园_首页
博客园 - 三生石上(FineUI控件)
博客园 - 叶小钗
Apple Machine Learning Research
Apple Machine Learning Research
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
量子位
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
人人都是产品经理
人人都是产品经理
美团技术团队
小众软件
小众软件
Jina AI
Jina AI
S
SegmentFault 最新的问题
博客园 - Franky
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com

Truesec

CRA Reporting Starts on 11 September: What Businesses Need To Know - Truesec Privilege Escalation Vulnerability in Falcon Crowdstrike - Truesec SonicWall Vulnerabilities Exploited in the Wild - Truesec Privileged Access Management (PAM) Is No Longer Optional  - Truesec Australian Arrests Allegedly Disrupt TeamPCP, but the Shai-Hulud Threat Persists - Truesec DDoS Attacks Against Norwegian Government Sites - Truesec Critical Citrix NetScaler Memory-Overflow Vulnerability - Truesec Iranian Cyberattacks Against Critical Infrastructure - Truesec Russia Targets Businesses and Officials Behind Europe’s Ukraine Defense Supply Chain - Truesec The World Is Moving at Machine Speed. Are We Ready? - Truesec False CVE in Overwhelmed Verification System - Truesec LLMjacking Is a New Cyber Threat - Truesec Rogue AI Agent Allegedly Hack Hugging Face - Truesec Microsoft SharePoint Server Vulnerabilities Actively Exploited - Truesec Russian Intelligence Targets SOHO Routers - Truesec Cyber Warfare in the Iran War - Truesec Organized Cybercrime Merging with Other Crime - Truesec AI Used in Ransomware Attack The Fortibleed Campaign: Truesec's Experience Fortibleed: Truesec's Experience Supply Chain Attack Compromising Arch Linux AUR Packages with Infostealer and Rootkit - Truesec FortiNet SSO Vulnerability CVE-2025-59718 and CVE-2025-59719 Leading to Full System Compromise - Truesec Critical Vulnerabilities in Ivanti Sentry Allows Code Execution as Root (CVE-2026-10520 & CVE-2026-10523) Typosquatting: When Your Domain Is Used Against You AI in Cybersecurity: Separating Operational Reality from Speculation Compromised @redhat-Cloud-Services Npm Packages Distribute Credential-Stealing Worm GitHub Hacks Highlights Need for Repository Security Installation of a Syslog Log Collector Critical Cisco Secure Workload Vulnerability Allows Unauthenticated Site Admin Access (CVE-2026-20223) Securing IT, OT, and IoT When the Digital Meets the Physical
Iranian APT Target US Critical Infrastructure
2026-04-10 · via Truesec

Threat Insight

On April 7, CISA, together with the FBI, NSA, and several other U.S. government agencies, issued a joint advisory regarding active exploitation of internet‑facing operational technology (OT) devices. The activity is focused on programmable logic controllers (PLCs) from Rockwell Automation / Allen‑Bradley, with the advisory noting that other PLC platforms may also be at risk. [1]

The advisory confirms that several U.S. critical infrastructure sectors have already experienced operational disruption. In response, CISA urges organizations to actively assess their environments against the published tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs) to determine whether they are currently affected or have been compromised in the past. [1]

U.S. authorities assess the activity to be conducted by Iranian‑affiliated advanced persistent threat (APT) actors. Impacted sectors include government services and facilities, water and wastewater management, and energy. Similar PLC‑focused activity has previously been attributed to CyberAv3ngers, also known as the Shahid Kaveh Group, which has established links to Iran’s Islamic Revolutionary Guard Corps (IRGC) Cyber Electronic Command (CEC). [1]

The context is relevant. The activity coincides with a period of heightened geopolitical tension, occurring just days ahead of a Pakistani‑brokered ceasefire involving the U.S., Israel, and Iran, with further negotiations scheduled in Islamabad on April 11. At the same time, tensions in the Strait of Hormuz remain elevated, with limited maritime traffic despite public statements that the route is open, and reports of transit restrictions and significant tolls imposed by Iran. [2]

Assessment

This activity fits a long‑standing Iranian cyber approach, where OT and critical infrastructure environments are used as leverage during periods of geopolitical pressure. Based on historic targeting patterns and current intelligence, the United States and Israel remain the primary focus of Iranian threat actors.

That said, European organizations should not view this activity as geographically contained. OT environments often rely on shared vendors, similar architectures, and comparable exposure models. As a result, European organizations operating the same PLC platforms face overlapping technical risk, even when they are not the primary strategic target.

Organizations in Europe using Rockwell Automation / Allen‑Bradley PLCs or other internet‑accessible OT components should follow the actions recommended by CISA. [1] This includes reviewing external exposure, validating segmentation and access controls, and ensuring adequate monitoring and logging for OT‑specific activity. With U.S. and Iranian negotiations expected to continue over the weekend, maintaining situational awareness is prudent.

For critical infrastructure operators, understand your OT attack surface, confirm visibility across industrial environments, and be ready to act on relevant indicators tied to the published TTPs. A measured, intelligence‑led response remains the most effective course of action.

References

[1] https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-097a
[2] https://www.bbc.com/news/articles/cp3l4yk5rlgo