CISA Alert: Iranian Cyber Actors Exploiting PLCs Across US Critical Infrastructure

Available in: 中文
2026-04-07T18:51:41.333Z·1 min read
CISA, FBI, NSA, EPA, and DOE have jointly issued an advisory warning that Iranian-affiliated APT actors are actively exploiting internet-facing programmable logic controllers (PLCs) across multiple...

CISA, FBI, NSA, EPA, and DOE have jointly issued an advisory warning that Iranian-affiliated APT actors are actively exploiting internet-facing programmable logic controllers (PLCs) across multiple US critical infrastructure sectors.

What's Happening

Iranian threat actors are targeting:

Attack Details

The exploitation involves:

Urgent Recommendations

Organizations should immediately:

  1. Remove PLCs from direct internet exposure — Use secure gateways and firewalls
  2. Check logs for suspicious traffic — Ports 44818, 2222, 102, 502
  3. Watch for overseas hosting provider traffic on OT device ports
  4. Place Rockwell controllers in RUN mode via physical mode switch
  5. Review provided IOCs — CISA released STIX XML/JSON indicators

Context

This advisory comes amid escalating tensions between the US and Iran, including reported military strikes on Iranian infrastructure. The cyber dimension adds another layer to the confrontation, targeting the physical systems that control water, energy, and government operations.

IOCs Available

CISA has released downloadable STIX format indicators:

↗ Original source · 2026-04-07T00:00:00.000Z
← Previous: Anthropic Releases Claude Mythos: AI Model with Striking Cybersecurity Capabilities, Launches Project GlasswingNext: MacBook Neo Faces Supply Crisis: Demand Outstrips Binned A18 Pro Chip Supply →
Comments0