Security News

Cybersecurity news aggregator

HIGH Attacks SC Media

US warns of Iran-linked attacks on critical infrastructure

A multi-agency advisory warns of Iran-linked threat actors targeting critical infrastructure by establishing persistent access to internet-exposed operational technology (OT) devices from major manufacturers like Siemens, Schneider Electric, and Rockwell Automation. The attackers demonstrate advanced ICS engineering knowledge, specifically targeting safety logic systems to disable alarms and shutdown functions before disrupting processes. Recommended immediate actions include removing OT devices, particularly PLCs, from direct internet exposure, implementing compensating controls like secure gateways, and conducting network threat hunting for IOCs on ports 44818, 2222, 102, and 502.
Read Full Article →

Critical Infrastructure Security US warns of Iran-linked attacks on critical infrastructure July 24, 2026 Share By Steve Zurier (Adobe Stock) Seven agencies of the federal government on July 22 released an updated advisory that describes Iran-linked attacks on critical infrastructure. The agencies, which include the Cybersecurity and Infrastructure Security Agency (CISA), National Security Agency (NSA), and the U.S. Treasury, said the attackers were targeting devices made by leading operational technology (OT) manufacturers Siemens, Schneider Electric, and Rockwell Automation. As part of the advisory, the U.S. government offered the following guidance: Install PLCs consistent with manufacturers' guidelines and security best practices. Remove PLCs from direct internet exposure via secure gateways and firewalls; work with IT/OT team members and/or integrators to perform this action. Query available logs for the provided indicators of compromise (IOCs) and check available logs for suspicious traffic on the ports associated with OT devices, including 44818, 2222, 102, and 502, especially traffic originating from foreign hosting providers. “This story highlights one of the biggest problems I see in cybersecurity today,” said John Strand, owner at Black Hills Information Security. “Our attention span is too short. We spend a tremendous amount of time focused on ransomware and whatever the immediate crisis happens to be, while nation-state adversaries are quietly building long-term access into critical infrastructure .” Strand pointed out that the goal of adversaries like the Iranians isn’t to cause damage today: it’s to establish persistent access so they’re in position to act whenever the timing benefits them. For organizations that manage critical systems, Strand said the priority has to be compensating controls and network visibility. Teams should never expose OT systems to the internet, said Strand, but many of them are. Just as important, Strand said many of these devices can’t support modern EDR agents, which means defenders have to rely on strong network security. “That goes well beyond traditional firewalls, IDS, and IPS,” said Strand. “It requires continuous network threat hunting and behavioral analysis capable of identifying beaconing, command-and-control activity, and other subtle indicators of compromise before an attacker is ready to act.” Gunter Ollmann, chief technology officer at Cobalt, added that what stands out here isn't that PLCs got compromised: it's what the attackers did once they had access. “They didn't just disrupt operations, they specifically went after the safety logic, disabling the shutdown and alarm functions that are supposed to tell an operator something has gone wrong,” said Ollmann. “That's a deliberate choice to remove the safety net before touching the process itself, and it shows a level of ICS engineering knowledge that goes well beyond opportunistic hacking.” Ollmann said it’s also a reminder that OT security can't stop at network segmentation. These actors got in through vendor configuration software, the same tools engineers use for legitimate maintenance, and rode trusted infrastructure to get there. “If an organization is only watching for unauthorized access and not for unauthorized changes to project files and logic, this kind of manipulation can sit undetected for a long time,” said Ollmann. “The expansion from one PLC vendor to three in a single advisory update also tells us this isn't a one-off technique tied to a specific product. It's a repeatable playbook.” Steve Zurier Related Governance, Risk and Compliance FedRAMP director warns tech companies against selling to federal agencies if they can’t fix vulnerabilities SC Staff July 23, 2026 Technology companies that cannot quickly fix dangerous vulnerabilities should not be allowed to sell their products to federal agencies, according to Pete Waterman, director of the General Services Administration’s Federal Risk and Authorization Management Program (FedRAMP). Critical Infrastructure Security EU’s plan to remove risky telecom suppliers could cost 4 times more than estimated SC Staff July 22, 2026 A report by the GSMA, a global trade body representing the telecom industry, suggests the direct cost of replacing equipment from designated high-risk vendors could range from €30 billion to €40 billion. Critical Infrastructure Security National Guard’s Cyber Shield exercise focuses on power sector defense SC Staff July 22, 2026 This year's Cyber Shield exercise, the largest to date with the most international participants, is specifically targeting the power sector's critical infrastructure. Related Events Cybercast From code to cloud: Stopping attacks in the software supply chain On-Demand Event Virtual Conference Securing the Backbone: Strategies to Counter Cyber Threats to Critical Infrastructure in the Public Sector On-Demand Event Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe You can skip this ad in 5 seconds

Share this article