Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
US Alerts on Iranian Cyber Threat to Industrial Control Systems

US Alerts on Iranian Cyber Threat to Industrial Control Systems

Posted on July 23, 2026 By CWS

The US government has issued an updated advisory highlighting the persistent cybersecurity threat posed by Iranian actors targeting critical infrastructure. The advisory notes that industrial control systems (ICS) from Siemens, Schneider Electric, and Rockwell Automation are under attack.

Details of Cyber Attacks on Industrial Systems

Initially released in April, the advisory detailed how Iranian hackers targeted operational technology (OT) devices within sectors like government services, energy, and water management. These attacks involved internet-exposed programmable logic controllers (PLCs), specifically mentioning devices from Rockwell Automation.

The attackers employed malicious project files to disrupt human-machine interfaces (HMIs) and supervisory control and data acquisition (SCADA) systems. The updated advisory now includes Siemens and Schneider Electric as additional targets.

Investigative Findings and Attack Techniques

In a particular case in the US, the FBI discovered that attackers had used configuration software to download harmful project files onto a PLC. These files altered ladder logic, overriding safety instructions in the affected environment.

The advisory identifies attacks targeting Rockwell Automation’s CompactLogix and Micro850, Schneider Electric’s Modicon M340, and Siemens’ S7-1200 series PLCs. Hackers accessed these systems through specific ports and utilized software like Rockwell’s Studio 5000 Logix Designer, Schneider’s EcoStruxure Control Expert, and Siemens’ TIA Portal.

Implications and Response Measures

The advisory emphasizes the hackers’ ability to extract and manipulate PLC project files, disrupting critical shutdown and alarm logic. This allowed unsafe conditions to go unnoticed by operators.

New guidance and updated indicators of compromise (IoCs) have been provided to help organizations detect and mitigate these threats. Cybersecurity experts stress the importance of maintaining robust defenses against these advancing capabilities.

Iranian Hacker Groups and Recent Activities

Iranian government-linked hacker groups, often using hacktivist personas, have been implicated in these attacks. Notable among these are CyberAv3ngers and Handala, the latter recently claiming responsibility for an attack on US medical technology firm Stryker.

Handala has also been linked to a purported disruption attempt on California Water Service’s systems, though the utility reported no evidence of activity. The evolving threat landscape highlights the need for vigilant, updated cybersecurity practices.

Related reports indicate ongoing Iranian cyber activities, including the use of modular command-and-control frameworks and targeting of sectors like aviation and software with sophisticated tools.

Security Week News Tags:APT attacks, cyber threats, Cybersecurity, ICS security, industrial control systems, Iranian hackers, Rockwell Automation, Schneider Electric, Siemens, US cyber advisory

Post navigation

Previous Post: Anthropic Debuts AI-Powered Code Security Plugin
Next Post: Urgent Warning: Check Point Vulnerability Exploited

Related Posts

AI Agent Security: Analysis of Top 100 and Key Findings AI Agent Security: Analysis of Top 100 and Key Findings Security Week News
Vulnerability Allowed Scraping of 3.5 Billion WhatsApp Accounts Vulnerability Allowed Scraping of 3.5 Billion WhatsApp Accounts Security Week News
WhatsApp Introduces Usernames for Enhanced Privacy WhatsApp Introduces Usernames for Enhanced Privacy Security Week News
Recently Disrupted DanaBot Leaked Valuable Data for 3 Years Recently Disrupted DanaBot Leaked Valuable Data for 3 Years Security Week News
Dior Says Personal Information Stolen in Cyberattack Dior Says Personal Information Stolen in Cyberattack Security Week News
Organizations Warned of Exploited PaperCut Flaw Organizations Warned of Exploited PaperCut Flaw Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • CrowdStrike Debuts SafeMind: Innovative AI Cybersecurity
  • MikroTik RouterOS Flaw Exploited: Urgent Patch Required
  • Critical Flaw in ASUS Control Center Exposes Systems
  • REVSTEALER Modules Disable Security to Run Crypto Miner
  • MikroTik Routers Vulnerable to Unauthenticated SSH Attacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • CrowdStrike Debuts SafeMind: Innovative AI Cybersecurity
  • MikroTik RouterOS Flaw Exploited: Urgent Patch Required
  • Critical Flaw in ASUS Control Center Exposes Systems
  • REVSTEALER Modules Disable Security to Run Crypto Miner
  • MikroTik Routers Vulnerable to Unauthenticated SSH Attacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark