Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
5,219 PLCs at Risk from Iranian Cyber Threats, Censys Reports

5,219 PLCs at Risk from Iranian Cyber Threats, Censys Reports

Posted on April 10, 2026 By CWS

The recent warnings from multiple U.S. agencies, including the FBI and CISA, have highlighted a significant cybersecurity threat targeting Rockwell Automation/Allen-Bradley programmable logic controllers (PLCs). The joint advisory, released on April 7, 2026, underscores the active targeting of these devices by Iranian-affiliated advanced persistent threat (APT) actors. The focus on industrial systems crucial to national infrastructure has raised alarm.

Targeting Critical Infrastructure

Rockwell Automation’s PLCs are integral to various critical infrastructures, such as water treatment facilities, energy sectors, and government operations. The advisory, labeled AA26-097A, confirms this threat as an ongoing concern, posing substantial risks to operational technology (OT) environments across the United States and globally. The attackers are associated with the Islamic Revolutionary Guard Corps Cyber Electronic Command (IRGC-CEC) and operate under several aliases.

Since November 2023, this group has been linked to breaches involving at least 75 Unitronics PLCs in U.S. water and wastewater facilities, as noted in a previous CISA advisory. The recent shift to targeting Rockwell devices marks a significant escalation, with activities traced back to at least March 2026.

Exposed Devices and Attack Strategies

Censys researchers have discovered 5,219 internet-exposed hosts that identify as Rockwell Automation/Allen-Bradley devices, revealing the full scope of potential targets. A staggering 74.6% of these are located in the United States, translating to 3,891 vulnerable hosts. Other countries like Spain, Taiwan, and Italy also report significant exposures.

The threat actors are exploiting legitimate engineering software, Studio 5000 Logix Designer, to access these PLCs, allowing them to manipulate critical systems undetected. This campaign includes probing additional OT protocols, suggesting an expansion of their target range across various platforms.

Vulnerabilities and Mitigation Measures

Almost 49.1% of the exposed devices are linked through Verizon Business cellular modems, with AT&T Mobility accounting for another 13.3%. These connections, often utilized in pump stations, electrical substations, and municipal facilities, highlight a significant deployment risk.

Censys also reports significant co-exposed services that broaden the attack surface, including VNC services appearing on 771 instances, and Telnet and Modbus on numerous others. These vulnerabilities align with the malicious behaviors outlined in the advisory AA26-097A.

Organizations are urged to take immediate action to mitigate these risks. This includes removing direct internet exposure of Rockwell/Allen-Bradley PLCs, switching devices to secure modes, and disabling vulnerable services. Implementing multi-factor authentication and updating firmware are also recommended. Reviewing inbound traffic from known operator IPs is critical to ensure security.

For continuous updates, follow us on Google News, LinkedIn, and X, and set CSN as a preferred source in Google.

Cyber Security News Tags:APT actors, Censys report, critical infrastructure, cyber attack prevention, cyber threats, Cybersecurity, industrial security, infrastructure protection, internet security, Iranian APT, network security, operational technology, PLC exposure, PLC vulnerabilities, Rockwell PLCs

Post navigation

Previous Post: Cybersecurity News: Stryker Cyberattack and More
Next Post: Android Crypto Wallets at Risk Due to SDK Flaw

Related Posts

China-Linked Hackers Target Telecoms With New Malware China-Linked Hackers Target Telecoms With New Malware Cyber Security News
New Malvertising Threat Exploits Facebook Ads for Scams New Malvertising Threat Exploits Facebook Ads for Scams Cyber Security News
Critical Convoy Vulnerability Let Attackers Execute Remote Code on Affected Servers Critical Convoy Vulnerability Let Attackers Execute Remote Code on Affected Servers Cyber Security News
ESET Warns AI-driven Malware Attack and Rapidly Growing Ransomware Economy ESET Warns AI-driven Malware Attack and Rapidly Growing Ransomware Economy Cyber Security News
SpyCloud Launches Supply Chain Identity Protection SpyCloud Launches Supply Chain Identity Protection Cyber Security News
India Continues to Be the Top Target for Mobile Attacks with 38% Increase in Threats India Continues to Be the Top Target for Mobile Attacks with 38% Increase in Threats Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • EngageSDK Flaw Puts Millions of Crypto Wallets at Risk
  • HPE Aruba 5G Vulnerability Allows Credential Theft
  • Exposed GitHub Copilot Flaw Risks Sensitive Data
  • Android Crypto Wallets at Risk Due to SDK Flaw
  • 5,219 PLCs at Risk from Iranian Cyber Threats, Censys Reports

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • EngageSDK Flaw Puts Millions of Crypto Wallets at Risk
  • HPE Aruba 5G Vulnerability Allows Credential Theft
  • Exposed GitHub Copilot Flaw Risks Sensitive Data
  • Android Crypto Wallets at Risk Due to SDK Flaw
  • 5,219 PLCs at Risk from Iranian Cyber Threats, Censys Reports

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark