An alert issued earlier this year was updated, providing more guidance on Iranian-linked cyber activity.

American Public Power Association via Unsplash
In April of this year, The Cybersecurity Infrastructure & Security Agency (CISA), alongside other agencies, published a warning regarding Iranian cyber activity against United States critical infrastructure. Earlier this week, that alert was updated.
The original publication offered information about ongoing cyber exploitation conducted by Iranian-linked advanced persistent threat (APT) actors, such as tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs). This week, the alert provided additional guidance, including:
The biggest issue here is that most of these organizations simply can’t pause operations while an incident is investigated. Water utilities have to keep providing clean water. Energy providers have to maintain power and fuel availability. Local governments still need to support emergency services and public operations. Even a short disruption can force employees into slower manual processes, delay essential services, and create public safety concerns. Recovery costs can also hit smaller operators especially hard since many are limited by small security staffs, older equipment, or outside vendors having control over parts of their environment.
Protecting these systems starts with knowing every controller in use and who can access it. IT teams, plant operators, integrators, and security partners need a shared response plan rather than separate assumptions about who owns the problem. Trusted backups of PLC logic are critical, as are tested recovery procedures and experienced responders who can contain an intrusion quickly.
A single exposed controller may look like a local weakness. In critical infrastructure, it can become part of a much larger national security problem.
Pete Luban, Field CISO at AttackIQ:Iranian cyber activity is becoming less dependent on one product and more focused on weaknesses that repeat across operational environments. By targeting controllers from several manufacturers, attackers can reuse the same playbook wherever exposed devices and weak access controls exist.
The ability to alter project logic and disable safeguards raises the stakes considerably. A compromise may no longer stop at unauthorized access. It can interfere with the systems designed to prevent unsafe physical conditions. Organizations therefore can’t treat each exposed controller as an isolated equipment issue.
Disconnecting vulnerable devices is essential, but defenders also need to understand how attackers could move from an internet-facing asset into critical operations. A CTEM program can map those realistic paths and identify the exposures that create the greatest operational risk. Adversarial exposure validation can then determine whether segmentation, access controls, monitoring, and incident procedures hold up against the tactics outlined in the advisory. Defenders need more than a list of weaknesses. They need evidence that the exposures most likely to cause physical disruption have been addressed.
Nick Tausek, Lead Security Automation Architect at Swimlane:The latest warning moves the Iran-linked threat beyond broad concern and into specific, actionable detail. Security teams now have new indicators, targeted ports, affected device families, and examples of attackers changing PLC logic or disabling critical safeguards. The problem is getting that intelligence into active workflows before the attackers move again.
That’s hard to do when asset data, network alerts, threat intelligence, and incident procedures live in separate systems. Security teams may understand the threat, but still lose valuable time gathering context and determining which exposed devices require immediate attention. Agentic AI Automation, such as that employed by modern AI SOC applications, can bring those signals together, identify affected OT assets, enrich suspicious traffic, and coordinate response across security and operations teams. It can also help prioritize vulnerabilities based on internet exposure and operational importance instead of relying on a generic severity score. Human approval should remain central for any action that could affect physical systems.
Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!
Jordyn Alger is the managing editor for Security magazine. Alger writes for topics such as physical security and cyber security and publishes online news stories about leaders in the security industry. She is also responsible for multimedia content and social media posts. Alger graduated in 2021 with a BA in English – Specialization in Writing from the University of Michigan. Image courtesy of Alger
| # | Наименование новости | Тональность | Информативность | Дата публикации |
|---|---|---|---|---|
| 1 | Israeli intelligence warns US of alleged Iranian plot to assassinate Trump: Report | 0 | 5 | 10-07-2026 |
| 2 | State Department issues warning to Americans living and traveling abroad | 0 | 8.05 | 20-07-2026 |
| 3 | WP: Трамп одобрил проведение кибератаки Пентагоном против компьютерных систем Ирана | 0 | 0 | 23-06-2019 |
| 4 | ABC: иранские хакеры в последнее время резко увеличили число кибератак на территории США | 0 | 0 | 22-06-2019 |
| 5 | Cyber industry coalition urges federal action after suspected Iran-linked water hacks | 0 | 10.97 | 31-07-2026 |
| 6 | Apple issues warning to millions of iPhone users over sophisticated attack stealing data: Act NOW | -2 | 6 | 04-04-2026 |
| 7 | Apple reveals iPhones are under attack from 'sophisticated' hacks secretly accessing devices: 'Act Now' | -2 | 6 | 15-01-2026 |
| 8 | Millions of iPhones at risk of devastating 'DarkSword' cyberattack: 'Act NOW' | -2 | 6 | 19-03-2026 |
| 9 | America goes on cyber-offence | 5 | 7 | 22-03-2026 |
| 10 | США и Иран предупредили о тревожном сигнале | 0 | 5 | 20-07-2026 |