Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Iran-Linked Cyberattacks Disrupt US Infrastructure

Iran-Linked Cyberattacks Disrupt US Infrastructure

Posted on April 8, 2026 By CWS

Iran-linked cyberattacks have recently disrupted several critical infrastructure sectors in the United States, according to a joint advisory issued by federal agencies. The attacks targeted operational technology (OT) devices, causing significant concern among officials.

Widespread Impact on Critical Sectors

The FBI, CISA, NSA, EPA, DOE, and United States Cyber Command collectively warned of these cyber threats in a recent advisory. The attacks have impacted multiple sectors, including Government Services, Water and Wastewater Systems, and Energy Sectors.

Iranian-linked threat actors have been found to be actively targeting internet-exposed programmable logic controllers (PLCs), particularly those manufactured by Rockwell Automation/Allen-Bradley. However, other vendors are also potentially at risk.

Potential for Extensive Disruptions

The advisory highlighted that organizations across various U.S. critical infrastructure sectors experienced disruptions due to malicious interactions with project files and data manipulation on human-machine interface (HMI) and supervisory control and data acquisition (SCADA) displays.

Due to the extensive use of these PLCs and the possibility of other OT devices being targeted, federal agencies urge U.S. organizations to review tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs) to identify current or historical activities on their networks.

Similarities with Previous Attacks

The recent cyber activity resembles past operations linked to groups such as CyberAv3ngers, known for targeting U.S. infrastructure sectors. This group, associated with Iran’s Islamic Revolutionary Guard Corps (IRGC), has previously attacked water utilities in both the United States and Ireland.

In October 2024, it was reported that CyberAv3ngers utilized OpenAI’s ChatGPT tool to plan industrial control system attacks, aiding them in reconnaissance and vulnerability exploitation.

Escalating Iran-Linked Operations

The attacks are part of a broader trend of increasing Iran-linked cyber operations. Notably, the Handala group targeted medical technology giant Stryker, wiping over 200,000 devices. The U.S. government has linked Handala to Iranian state actions, following the seizure of numerous websites used by the group.

Federal agencies recommend that organizations assess their OT environments for vulnerabilities and apply recommended mitigations to prevent exploitation by such cyber threats.

To support defense efforts, downloadable lists of IOCs are available in both XML and JSON formats, providing valuable resources for organizations seeking to reinforce their cybersecurity measures.

Conclusion

As cyber threats linked to Iran continue to escalate, it is crucial for U.S. organizations to remain vigilant and proactive in defending their critical infrastructure. By staying informed and implementing recommended security measures, the risk of compromise can be significantly reduced.

Security Week News Tags:critical infrastructure, cyber threats, Cyberattacks, CyberAv3ngers, Cybersecurity, Handala, Iran, OT devices, PLC vulnerabilities, US infrastructure

Post navigation

Previous Post: Hackers Exploit Npm Package to Target AI Developers
Next Post: How Fiber Optic Cables Can Secretly Eavesdrop on Conversations

Related Posts

Threat Actors Use SVG Smuggling for Browser-Native Redirection Threat Actors Use SVG Smuggling for Browser-Native Redirection Security Week News
Akira Ransomware Attacks Fuel Uptick in Exploitation of SonicWall Flaw Akira Ransomware Attacks Fuel Uptick in Exploitation of SonicWall Flaw Security Week News
Help Desk at Risk: Scattered Spider Shines Light on Overlook Threat Vector Help Desk at Risk: Scattered Spider Shines Light on Overlook Threat Vector Security Week News
VMware Flaws That Earned Hackers 0,000 at Pwn2Own Patched VMware Flaws That Earned Hackers $340,000 at Pwn2Own Patched Security Week News
Third DraftKings Hacker Pleads Guilty Third DraftKings Hacker Pleads Guilty Security Week News
CISA Expands KEV List with iOS Vulnerability Additions CISA Expands KEV List with iOS Vulnerability Additions Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • AI Discovers Decade-Old RCE Flaw in Apache ActiveMQ
  • Iranian Cyber Threats Target U.S. Infrastructure
  • How Fiber Optic Cables Can Secretly Eavesdrop on Conversations
  • Iran-Linked Cyberattacks Disrupt US Infrastructure
  • Hackers Exploit Npm Package to Target AI Developers

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • AI Discovers Decade-Old RCE Flaw in Apache ActiveMQ
  • Iranian Cyber Threats Target U.S. Infrastructure
  • How Fiber Optic Cables Can Secretly Eavesdrop on Conversations
  • Iran-Linked Cyberattacks Disrupt US Infrastructure
  • Hackers Exploit Npm Package to Target AI Developers

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark