Ethical Hacking News
CISA has expanded its alert on Iranian-affiliated hackers attacking critical infrastructure in the US, including water and energy facilities, by targeting internet-facing devices from multiple vendors. The attack highlights the importance of cybersecurity in critical infrastructure and serves as a reminder for organizations to take proactive measures to mitigate potential risks.
CISA has expanded its alert regarding Iranian-affiliated hackers targeting critical infrastructure in the US. The alert now includes devices from vendors such as Schneider Electric and Siemens in addition to Rockwell Automation/Allen-Bradley. Attackers are using tactics like exploiting open ports and utilizing software to gain remote access to PLCs. Organizations can mitigate the risk by implementing isolated architectures and controlling network access to PLC devices. The attack highlights the importance of cybersecurity in critical infrastructure, particularly in light of the ongoing conflict between the US and Iran.
The United States Cybersecurity and Infrastructure Security Agency (CISA) has recently expanded its alert regarding Iranian-affiliated hackers targeting critical infrastructure in the country. The alert initially focused on programmable logic controllers (PLCs) manufactured by Rockwell Automation/Allen-Bradley, but has now been widened to include devices from other vendors such as Schneider Electric and Siemens.
This expansion highlights the importance of being aware of what is accessible and comes after a series of attacks on PLCs that began in March. The attackers, who are believed to be affiliated with Iran's Islamic Revolutionary Guard Corps (IRGC) Cyber Electronic Command (CEC), have been using various tactics such as exploiting open ports and utilizing software like Dropbear Secure Shell (SSH) to gain remote access.
Once inside the system, the attackers extract device project files and modify or delete their logic. This can lead to critical shutdown and alarm logic being disabled, allowing systems to enter unsafe conditions without notifying operators. To mitigate this risk, CISA has suggested that organizations consider implementing isolated architectures and controlling network access to PLC devices.
Other measures that can be taken include checking project files running on PLCs for unauthorized changes, ensuring that service providers are aware of threats targeting PLCs, and changing default passwords.
The attack by Iranian-affiliated hackers is part of a larger conflict between the US and Iran that has been ongoing since March. The use of PLCs as a target in these attacks serves as a reminder of the importance of cybersecurity in critical infrastructure.
In addition to this alert, there have been other recent developments in the field of cybersecurity. For example, researchers have identified a flaw in OpenAI's ChatGPT link that could allow a rogue AI agent to be smuggled into a company's network. This highlights the need for vigilance and awareness when it comes to cybersecurity threats.
Furthermore, a recent attack on a water company resulted in the organization being fined nearly £1 million due to its lack of security measures. This serves as an example of the consequences that can result from inadequate cybersecurity.
In conclusion, the expansion of CISA's alert regarding Iranian-affiliated hackers targeting critical infrastructure highlights the importance of being aware of what is accessible and taking steps to mitigate potential risks. By implementing isolated architectures and controlling network access to PLC devices, organizations can reduce their vulnerability to these types of attacks.
Related Information:
https://www.ethicalhackingnews.com/articles/Iran-linked-Crews-Exploit-Vulnerabilities-in-US-Industrial-Kit-Prompting-CISA-to-Expand-Alert-ehn.shtml
https://www.theregister.com/security/2026/07/23/iran-linked-crews-are-probing-more-flavors-of-us-industrial-kit/5277003
Published: Thu Jul 23 09:52:30 2026 by llama3.2 3B Q4_K_M