Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
US Alerts on Iranian Cyber Threat to Industrial Control Systems

US Alerts on Iranian Cyber Threat to Industrial Control Systems

Posted on July 23, 2026 By CWS

The US government has issued an updated advisory highlighting the persistent cybersecurity threat posed by Iranian actors targeting critical infrastructure. The advisory notes that industrial control systems (ICS) from Siemens, Schneider Electric, and Rockwell Automation are under attack.

Details of Cyber Attacks on Industrial Systems

Initially released in April, the advisory detailed how Iranian hackers targeted operational technology (OT) devices within sectors like government services, energy, and water management. These attacks involved internet-exposed programmable logic controllers (PLCs), specifically mentioning devices from Rockwell Automation.

The attackers employed malicious project files to disrupt human-machine interfaces (HMIs) and supervisory control and data acquisition (SCADA) systems. The updated advisory now includes Siemens and Schneider Electric as additional targets.

Investigative Findings and Attack Techniques

In a particular case in the US, the FBI discovered that attackers had used configuration software to download harmful project files onto a PLC. These files altered ladder logic, overriding safety instructions in the affected environment.

The advisory identifies attacks targeting Rockwell Automation’s CompactLogix and Micro850, Schneider Electric’s Modicon M340, and Siemens’ S7-1200 series PLCs. Hackers accessed these systems through specific ports and utilized software like Rockwell’s Studio 5000 Logix Designer, Schneider’s EcoStruxure Control Expert, and Siemens’ TIA Portal.

Implications and Response Measures

The advisory emphasizes the hackers’ ability to extract and manipulate PLC project files, disrupting critical shutdown and alarm logic. This allowed unsafe conditions to go unnoticed by operators.

New guidance and updated indicators of compromise (IoCs) have been provided to help organizations detect and mitigate these threats. Cybersecurity experts stress the importance of maintaining robust defenses against these advancing capabilities.

Iranian Hacker Groups and Recent Activities

Iranian government-linked hacker groups, often using hacktivist personas, have been implicated in these attacks. Notable among these are CyberAv3ngers and Handala, the latter recently claiming responsibility for an attack on US medical technology firm Stryker.

Handala has also been linked to a purported disruption attempt on California Water Service’s systems, though the utility reported no evidence of activity. The evolving threat landscape highlights the need for vigilant, updated cybersecurity practices.

Related reports indicate ongoing Iranian cyber activities, including the use of modular command-and-control frameworks and targeting of sectors like aviation and software with sophisticated tools.

Security Week News Tags:APT attacks, cyber threats, Cybersecurity, ICS security, industrial control systems, Iranian hackers, Rockwell Automation, Schneider Electric, Siemens, US cyber advisory

Post navigation

Previous Post: Anthropic Debuts AI-Powered Code Security Plugin
Next Post: Urgent Warning: Check Point Vulnerability Exploited

Related Posts

Iran Monitors US Troops, New MacOS Malware Discovered Iran Monitors US Troops, New MacOS Malware Discovered Security Week News
Louis Vuitton Data Breach Hits Customers in Several Countries Louis Vuitton Data Breach Hits Customers in Several Countries Security Week News
Palo Alto Networks to Acquire Observability Platform Chronosphere in .35 Billion Deal Palo Alto Networks to Acquire Observability Platform Chronosphere in $3.35 Billion Deal Security Week News
SAP Addresses Critical Vulnerabilities in S/4HANA SAP Addresses Critical Vulnerabilities in S/4HANA Security Week News
Google Says Android pKVM Earns Highest Level of Security Assurance Google Says Android pKVM Earns Highest Level of Security Assurance Security Week News
Trent AI Launches with M Seed Funding Boost Trent AI Launches with $13M Seed Funding Boost Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Urgent Warning: Check Point Vulnerability Exploited
  • US Alerts on Iranian Cyber Threat to Industrial Control Systems
  • Anthropic Debuts AI-Powered Code Security Plugin
  • Iranian Hackers Prepare for Potential Cyber Disruption
  • AI-Coded Applications: Security Challenges Uncovered

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Urgent Warning: Check Point Vulnerability Exploited
  • US Alerts on Iranian Cyber Threat to Industrial Control Systems
  • Anthropic Debuts AI-Powered Code Security Plugin
  • Iranian Hackers Prepare for Potential Cyber Disruption
  • AI-Coded Applications: Security Challenges Uncovered

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark