Security News

Cybersecurity news aggregator

⚔️
HIGH Attacks SecurityWeek

US Warns of Iranian Hackers Targeting Siemens, Schneider, and Rockwell ICS Devices

Iranian APT actors are targeting internet-exposed PLCs from Siemens, Schneider Electric, and Rockwell Automation by using vendor configuration software to download malicious project files that override safe operating parameters and disable critical alarms. The attacks specifically target Rockwell Automation CompactLogix and Micro850, Schneider Electric Modicon M340 (BMX P34), and Siemens S7-1200 series PLCs via ports 44818, 2222, 102, 502, and 22. The updated advisory provides new detection guidance and indicators of compromise; organizations should immediately isolate critical OT systems from the internet and audit PLC project files for unauthorized modifications.
Read Full Article →

ICS/OT US Warns of Iranian Hackers Targeting Siemens, Schneider, and Rockwell ICS Devices An updated advisory from federal agencies provides information on the techniques used to hack programmable logic controllers. By Eduard Kovacs | July 23, 2026 (1:28 AM ET) Flipboard Reddit Whatsapp Whatsapp Email The US government has updated a recent cybersecurity advisory describing Iran-linked attacks on critical infrastructure organizations, warning that hackers have been targeting industrial control systems (ICS) made by Siemens, Schneider Electric, and Rockwell Automation. The advisory was initially published in early April, when federal agencies said Iranian hackers had been conducting disruptive attacks targeting operational technology (OT) devices at organizations in the government services and facilities, energy, and water and wastewater sectors. The authoring agencies said at the time that threat groups had hacked internet-exposed programmable logic controllers (PLCs), naming Allen-Bradley devices made by Rockwell Automation. The hackers had used malicious PLC project files and manipulated the data displayed on human-machine interfaces (HMIs) and supervisory control and data acquisition (SCADA) systems. The updated advisory , published on July 22, adds Schneider Electric and Siemens to the list of vendors whose PLCs have been targeted by Iranian APT actors and notes that devices from other companies may also be targeted. In the case of one victim in the United States, FBI investigators discovered that the attacker had used configuration software to download a malicious project file to a PLC. Advertisement. Scroll to continue reading. “Analysis indicated the project file retained ladder logic for downstream function but added logic that overrode specific instruction sets responsible for maintaining safe operating parameters in the victim’s environment,” the updated advisory explains. Investigators are aware of attacks against Rockwell Automation CompactLogix and Micro850, Schneider Electric Modicon M340 (BMX P34), and Siemens S7-1200 series PLCs. The attacks targeted ports 44818, 2222, 102, 502, and 22, and the hackers connected to the vulnerable PLCs via manufacturers’ programming software and leased third-party-hosted infrastructure. The vendor configuration software targeted by APTs includes Rockwell Automation Studio 5000 Logix Designer, Schneider Electric EcoStruxure Control Expert, and Siemens TIA Portal. According to the updated advisory, the hackers extracted and exfiltrated PLC project files and then modified and deleted the logic in those files. The attackers included add-on instructions and manipulated data on HMI and SCADA displays. “Additionally, the changes disabled critical shutdown and alarm logic, allowing systems to enter unsafe conditions without notifying operators of the anomalies,” the advisory notes. The advisory now includes new guidance for detecting malicious activity, as well as updated indicators of compromise (IoCs). Iranian hacker groups targeting ICS/OT The Iranian government has been using hacktivist personas to carry out many of the attacks targeting ICS/OT. The group named CyberAv3ngers made many headlines in the past years for its attacks on such systems. A group named Handala has taken the lead this year, starting with a highly disruptive attack on the US medical technology giant Stryker . Last month, Handala claimed it could have disrupted the water supply after hacking systems owned by California Water Service (Cal Water). The hackers’ statements suggested they had gained deep access to ICS, but the water utility said it had found no evidence of activity in its OT environment. While cyber adversaries once focused primarily on exposed, poorly secured ICS , these latest findings demonstrate that their capabilities are steadily advancing, underscoring the need for organizations to maintain proactive, up-to-date defenses. Related : Iran-Linked Hackers Using Modular C&C Framework in Cyberattacks Related : LA Metro Cyberattack Linked to Iranian State-Sponsored Hackers Related : Iranian APT Targets Aviation, Software Companies With Updated Tools Written By Eduard Kovacs Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Eduard Kovacs Oracle Patches Over 1,400 Vulnerabilities With Quarterly Security Updates Ransomware Group Threatening to Leak Data Stolen From Coca-Cola’s Fairlife OpenAI Says Its AI Models Broke Loose and Hacked Hugging Face Meta Paid $78,000 Bounty for Vulnerability Exposing Customer Support Data Exploitation of ServiceNow Vulnerability Seen Days After Disclosure SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch New Index Tracks Material Breaches — And Refuses to Add Up the Losses WP2Shell WordPress Vulnerabilities Exploited in the Wild Latest News Suno, Paidwork Data Breaches Affect Tens of Millions of Accounts Palo Alto Networks to Acquire Observability Platform Provider Embrace Flaw in Adobe Extension With 300M Installs Enabled WhatsApp Data Theft When Identity Verification Fails: Lessons from a Real-World SIM Swap and Near Account Takeover Vibe-Coded Apps Riddled With Exploitable Security Flaws StrongestLayer Raises $4.1 Million in Seed Funding Extension Fourth SharePoint Vulnerability Exploited in Past Month’s Wave of Attacks Endpoint Security Firm Glow Launches With $180M in Funding at $1.2B Valuation Trending Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Closing the Exploitation Gap July 22, 2026 Join this live webinar as we explore why exploitation is outpacing remediation, where risk is growing fastest, and what security leaders can do to close the gap before attackers take advantage. Register Virtual Event: CodeSecCon 2026 August 19, 2026 CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps! Register People on the Move Jazz has named Sean Robinson, Rickie Goyal, Danielle Guetta, Shani Nago, and Lior Magram as VPs and Michael Calev as COO. AJ Shipley has been appointed Chief Product Officer at CrowdStrike. Brinqa has named Ron Dovich as Chief AI and Automation Officer, David Allen as CTO, Steve Biagioni as CFO, and James Walta as VP of Product. More People On The Move Expert Insights When Identity Verification Fails: Lessons from a Real-World SIM Swap and Near Account Takeover Identity confidence changes throughout every interaction and should be reassessed continuously as new risk signals emerge. (Torsten George) Legacy Systems, Real-World Impacts: The Reality of OT Security Legacy systems, safety concerns, and critical infrastructure risks make OT vulnerability disclosure one of cybersecurity's most challenging balancing acts. (Tod Beardsley) The Shift Toward Business-Aligned Risk Management Moving from isolated, technical data to a continuous risk lifecycle can help organizations align security controls with actual business consequences. (Steve Durbin) How to Conduct a Successful Audit of AI-Driven Software Development As AI-generated code becomes commonplace, CISOs need new audit strategies to measure developer practices, govern AI tool usage, and identify software risks before they reach production. (Matias Madou) Frontier AI: Six Questions Every Enterprise Should Ask Security Vendors From model selection and automation to validation and measurable results, the right questions can help enterprises separate genuine AI capabilities from marketing hype. (Joshua Goldfarb) Flipboard Reddit Whatsapp Whatsapp Email

Share this article