惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

大猫的无限游戏
大猫的无限游戏
阮一峰的网络日志
阮一峰的网络日志
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
WordPress大学
WordPress大学
博客园 - 叶小钗
Hugging Face - Blog
Hugging Face - Blog
博客园 - 司徒正美
Last Week in AI
Last Week in AI
罗磊的独立博客
量子位
Jina AI
Jina AI
T
Tailwind CSS Blog
Apple Machine Learning Research
Apple Machine Learning Research
IT之家
IT之家
美团技术团队
雷峰网
雷峰网
爱范儿
爱范儿
S
SegmentFault 最新的问题
小众软件
小众软件
月光博客
月光博客
酷 壳 – CoolShell
酷 壳 – CoolShell
人人都是产品经理
人人都是产品经理
The Cloudflare Blog
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报

The Register - Security

India's cyber agency sets clock at 12 hours to tackle exploited bugs as AI turns up the heat Are we human? MyPillow must decide whether to be firm or soft as ransomware crims demand pay Experts pour cold borscht on Farage's Russian hack claim AI eyes scanning for bugs create a worrisome Linux security trend A Russian speaker and jailbroken Gemini went on a hacking spree and emptied at least one MAGA victim's crypto wallets Techie claims Trump Mobile website was leaking thousands of people's data Dems slam Trump for making cybersecurity hold out the tin cup while splurging on ballroom and Jan. 6 'slush fund' Attackers spill plaintext passwords of 46k Myspace93 users after 2021 breach Microsoft open-sources agentic AI safety tools Are we human? America's top cyber-defense agency left a GitHub repo open with with passwords, keys, tokens – and incredibly obvious filenames America's top cyber-defense agency left a GitHub repo open with passwords, keys, tokens – and incredibly obvious filenames Shai-Hulud copycat worm infects yet another npm package MPs want social media treated more like unsafe toys than harmless apps Nobody believes the 'criminals and scumbags' who hacked Canvas really deleted stolen student data To gain root access, intruder just had to ask AWS patched Quick auth bypass, says customers weren't using control Disgruntled researcher releases two more Microsoft zero-days Malware crew TeamPCP open-sources its Shai-Hulud worm on GitHub Foxconn confirms cyberattack after ransomware crew claims it stole confidential Apple, Nvidia files US bank reports itself after slinging customer data at 'unauthorized AI app' Anthropic’s bug-hunting Mythos was greatest marketing stunt ever, says cURL creator Best Western Hotels confirms web app data breach Arctic Wolf cuts 250 jobs in AI push 1 in 8 workers say selling company logins is justifiable Iran cyberspies LARPing as ransomware crims in espionage ops UK age-gating plans risk breaking the internet, privacy groups warn India orders infosec red alert in case Mythos sparks crime 'CopyFail' attackers start cashing in on Linux flaw
Iran cyber actors disrupting US water, energy facilities,...
2026-04-08 · via The Register - Security

Iranian-affiliated actors have escalated intrusions targeting critical US water and energy facilities, in some cases disrupting operations, the FBI and American cyber defense agencies said on Tuesday.

The US government alert comes as the war lted by the US and Israel enters its sixth week, with President Donald Trump threatening to wipe out Iran's civilization before Pakistan convinced him to agree to a two-week ceasefire.

Iran's cyber intrusions targeting critical infrastructure have been ongoing since March, according to the feds, and they aim to disrupt operational technology (OT) devices, specifically programmable logic controllers (PLCs) manufactured by Rockwell Automation/Allen-Bradley. 

PLCs are used to control and monitor industrial equipment in water treatment plants, food production sites, oil refineries, power grids, and other critical facilities, and they've been a longtime favorite target of Iranian cyber crews.

In 2023, the FBI and friends blamed a series of attacks targeting Unitronics Vision Series PLCs on CyberAv3ngers, a group affiliated with the Islamic Revolutionary Guard Corps (IRGC). These weren't sophisticated cyberattacks, however. CyberAv3ngers broke into US-based water facilities by using default passwords for internet-accessible PLCs.

A year later, the same crew infected PLCs, human-machine interfaces (HMIs), and other OT devices with custom malware, and used that access to remotely control US and Israel-based water and fuel management systems.

Iranian threat actors are now moving faster and broader and targeting both IT and OT infrastructure

The latest round of OT-device attacks also targets PLCs, HMIs, and supervisory control and data acquisition (SCADA) displays, according to a joint alert from the FBI, CISA, National Security Agency, Environmental Protection Agency, Department of Energy, and US Cyber Command.

"The FBI assesses a group of Iranian-affiliated APT actors are targeting internet-exposed PLCs with the intent to cause disruptions - including maliciously interacting with project files, and manipulating data displayed on HMI and SCADA displays - to US critical infrastructure organizations," the joint alert said. 

"These PLCs were deployed across multiple US critical infrastructure sectors within a wide variety of industrial automation processes … Some of the victims experienced operational disruption and financial loss," it continued.

The FBI declined to provide additional details about the disruptions.

A threat analyst, who asked to remain anonymous because of safety concerns, confirmed to The Register that Iran-linked attackers are "looking for opportunities to disrupt utilities here and in the Middle East."

Sergey Shykevich, threat intelligence group manager at Check Point Research, told The Register that the FBI advisory "confirms what we've observed for months: Iran's cyber escalation follows a known playbook."

It's also worth noting that the energy and utilities sector was the fifth-most targeted industry in the US last month, according to Check Point's cyberattack tracking.

The security company, which has headquarters in Tel Aviv, documented "identical" targeting against Israeli PLCs last month, Shykevich said. 

"Iranian threat actors are now moving faster and broader and targeting both IT and OT infrastructure," he added. "It is not the first time Iranian actors are targeting operational technology in the US for disruption purposes, so organizations shouldn't treat this as a new threat, but as an accelerating one."

For companies, this means making sure systems are patched, multi-factor authentication has been turned on, and critical OT systems aren't exposed to the internet, Shykevich said. 

US government agencies also suggest that anyone using Rockwell Automation/Allen-Bradley-manufactured PLCs review the vendor's guidance, which includes disconnecting all internet-connected devices.

Plus, check available logs for suspicious traffic on the ports associated with OT devices, including 44818, 2222, 102, and 502, especially traffic originating from overseas hosting providers. ®