Federal agencies broaden alert on Iran-linked OT attacks
The observed incidents include “malicious project file interactions and manipulation of data on human machine interface (HMI) and supervisory control and data acquisition (SCADA) displays,” the advisory says.
The federal government has expanded a warning that it issued in April about attacks on internet-facing operational technology (OT) by hackers affiliated with the Iranian regime.
The initial advisory focused on programmable logic controllers (PLCs) from manufacturers Rockwell Automation and Allen-Bradley. Wednesday’s revision “expands the manufacturer scope to include observed targeting of Schneider Electric, Siemens and possible other PLC manufacturers,” according to a news release from CISA.
The observed incidents include “malicious project file interactions and manipulation of data on human machine interface (HMI) and supervisory control and data acquisition (SCADA) displays,” the advisory says. Targeted organizations suffered “operational disruption and financial loss.”
Source: https://therecord.media/federal-agencies-broaden-alert-on-iran-linked-ot-attacks
Related breach coverage
- US Agencies Warn of Laundry Bear Campaign Targeting Unpatched Zimbra Servers2026-07-24
US agencies warn Russian group Laundry Bear is exploiting a patched Zimbra flaw to steal email accounts from organizations running unpatched servers. The Cybersecurity and Infrastructure Security Agency (CISA), National Security Agency (NSA), Federal Bureau of Investigation (FBI) and other U.S. government and international partners published a joint advisory to warn that the Russia-linked APT […]
- US Warns of Iranian Hackers Targeting Siemens, Schneider, and Rockwell ICS Devices2026-07-23
An updated advisory from federal agencies provides information on the techniques used to hack programmable logic controllers. The post US Warns of Iranian Hackers Targeting Siemens, Schneider, and Rockwell ICS Devices appeared first on SecurityWeek.
- International alert spotlights Russia-linked attacks on Zimbra webmail2026-07-23
A Kremlin-backed group known as Laundry Bear has been using a zero-click phishing technique to break into Zimbra webmail accounts worldwide, the U.S. and other nations said.
- Unpatched Cursor Vulnerability Exposes Users to Code Execution2026-07-15
An attacker can create a malicious repository containing a git.exe in the project root, and Cursor executes it automatically. The post Unpatched Cursor Vulnerability Exposes Users to Code Execution appeared first on SecurityWeek.
