Executive Gov
  • Home
  • Acquisition & Procurement
  • Agencies
    • Department of War
    • Intelligence Community
    • DHS
    • Federal Civilian
    • Space
  • Cybersecurity
  • Technology
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news
No Result
View All Result
Executive Gov
  • Home
  • Acquisition & Procurement
  • Agencies
    • Department of War
    • Intelligence Community
    • DHS
    • Federal Civilian
    • Space
  • Cybersecurity
  • Technology
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news
No Result
View All Result
Executive Gov
No Result
View All Result
Home Cybersecurity

Federal Agencies Update Warning on Iranian Cyber Actors Targeting PLCs

by Jane Edwards
July 23, 2026
in Cybersecurity, DHS, News
Cybersecurity. CISA and other federal agencies have issued an update to a cyber advisory warning of Iran cyber threat actors.

CISA, FBI, the Environmental Protection Agency and other U.S. government partners have issued an update to a joint cyber advisory warning of Iran-affiliated cyber actors exploiting programmable logic controllers across U.S. critical infrastructure.

  • CISA, FBI and EPA have updated a joint cybersecurity advisory on Iran-linked threat activity
  • New guidance targets malicious PLC code changes and expands the manufacturers covered
  • The 2026 Homeland Security Summit will examine AI, cyber defense and more

The Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency, FBI, the Environmental Protection Agency and other government partners have issued an update to a joint cybersecurity advisory warning of Iran-affiliated cyber actors exploiting programmable logic controllers, or PLCs, across U.S. critical infrastructure.

Table of Contents

    • You might also like
    • GAO: DHS Unlikely to Fully Realize $10.5B in Projected Contract Savings
    • Pentagon Unveils Secure Space Network
    • CMS Shifts AI Strategy From Usage Metrics to Results, CIO Says
  • What Does the Updated Advisory Cover?
  • What Has the Iran-Affiliated Activity Targeted?
  • What New Mitigations Are Recommended?
  • What Did Federal Officials Say About the Cyberthreat?
  • What Other Recent Actions Has CISA Taken?

You might also like

GAO: DHS Unlikely to Fully Realize $10.5B in Projected Contract Savings

Pentagon Unveils Secure Space Network

CMS Shifts AI Strategy From Usage Metrics to Results, CIO Says

Federal Agencies Update Warning on Iranian Cyber Actors Targeting PLCs

As threats to the nation’s critical infrastructure continue to evolve, government and industry leaders will gather at the Potomac Officers Club’s 2026 Homeland Security Summit on Nov. 12 to discuss AI, cyber defense, border security and operational capabilities at major DHS agencies. Register now to join the conversation shaping the future of homeland security.

CISA said Wednesday the update to the advisory issued in April responds to ongoing Iranian cyber activity aimed at internet-connected operational technology devices. The update includes new indicators of compromise, detection guidance and additional mitigation steps.

What Does the Updated Advisory Cover?

The updated cybersecurity advisory offers new guidance for detecting malicious changes in reusable code modules used in Rockwell Automation PLC programs. It also broadens the advisory’s scope beyond Rockwell Automation, noting that Schneider Electric and Siemens, along with other PLC manufacturers, have also been targeted. CISA said the wider scope highlights why operational technology owners and operators need to limit direct internet access and secure PLC deployment.

What Has the Iran-Affiliated Activity Targeted?

According to the advisory, threat actors have disrupted PLCs across U.S. critical infrastructure sectors, leading to operational disruptions and financial losses for affected organizations. The actors attempted to download malicious project files and alter data on human machine interfaces and supervisory control and data acquisition displays. Targeted sectors include water and wastewater systems, energy, local municipalities, and other government services and facilities.

What New Mitigations Are Recommended?

The updated advisory recommends that organizations take the following additional steps:

  • Consult PLC manufacturers’ existing guidance to help secure operational technology deployments
  • Tightly restrict network access to PLC devices
  • Check project files on PLCs for unauthorized modifications
  • Keep service providers informed of active threats aimed at internet-connected PLC devices

What Did Federal Officials Say About the Cyberthreat?

Chris Butera, CISA’s acting executive assistant director for cybersecurity, said the agency has repeatedly cautioned critical infrastructure stakeholders that threat actors linked to Iran are targeting poorly secured, internet-connected accounts and devices. He called on organizations to consult the updated advisory and put the recommended actions in place.

Brett Leatherman, assistant director of the FBI’s cyber division, said Iranian cyber actors remain focused on U.S. critical infrastructure and that the bureau continues working to identify and disrupt that activity. 

“This advisory provides network defenders with the information they need to identify malicious activity, strengthen their defenses, and reduce opportunities for Iranian cyber actors to disrupt the essential services Americans rely on,” Leatherman added.

Jess Kramer, EPA assistant administrator for water, said cyberthreats represent a significant risk to the nation’s drinking water and wastewater systems, given how many communities, businesses, hospitals and schools depend on them. She called on water systems to remain alert, stay current on emerging threats and put cybersecurity best practices into place.

What Other Recent Actions Has CISA Taken?

Beyond the PLC advisory update, CISA has pursued several other initiatives to strengthen critical infrastructure security and government-industry collaboration. The agency and four international cybersecurity partners recently issued guidance to help software manufacturers and online service providers establish coordinated vulnerability disclosure programs that support collaboration with security researchers. 

CISA shared key lessons from a May cyber incident involving the unauthorized release of internal CISA Amazon Web Services GovCloud keys and other data to a public repository. The agency also established the Alliance of National Councils for Homeland Operational Resilience-Critical Infrastructure to expand information sharing and strengthen government-industry collaboration on critical infrastructure security. 

In May, CISA and the FBI also issued an alert on a Russian phishing campaign targeting users of a commercial messaging application.

Stay connected via Google News
Follow us for the latest travel updates and guides.
Add as preferred source on Google
Share5Tweet19
Previous Post

Office of Naval Research Unveils 2026 Science & Technology Strategy

Next Post

House FY2027 Intelligence Authorization Act Focuses on AI, Oversight and OSINT

Recommended For You

NSA, ODNI, CISA Offer Supply Chain Security Guidance for Software Developers

by Jane Edwards
September 2, 2022
NSA, ODNI, CISA Offer Supply Chain Security Guidance for Software Developers

The National Security Agency, the Office of the Director of National Intelligence and the Cybersecurity and Infrastructure Security Agency have issued guidance outlining best practices that developers can...

Read moreDetails

Gen. Charles Brown Nominated to Lead Joint Chiefs of Staff

by Jane Edwards
May 25, 2023
Gen. Charles Q. Brown

Gen. Charles “CQ” Brown, chief of staff of the U.S. Air Force, has been nominated to serve as chairman of the Joint Chiefs of Staff, Reuters reported Wednesday....

Read moreDetails

Senate Panel OKs FY24 Appropriations Bills for DOD, Other Federal Agencies

by Jane Edwards
July 28, 2023
Congress

The Senate Appropriations Committee has passed a package of 12 appropriations bills that would allocate fiscal year 2024 funds for federal agencies – including the departments of Defense, Health...

Read moreDetails

Army, General Atomics Demo Anti-Drone Weapon Prototypes to Meet ‘Unlimited-Ammo’ Goals

by Scott Nicholas
April 26, 2016
Army, General Atomics Demo Anti-Drone Weapon Prototypes to Meet 'Unlimited-Ammo' Goals

The U.S. Army and members of a General Atomics team displayed prototypes of anti-drone weapons that look to meet what the service branch calls "unlimited-ammunition" goals at the Maneuver Fires Integrated Experiment...

Read moreDetails

Tyto Athene Raises Funds for Fisher House Foundation; Chris Meilhammer Quoted

by reynolitoresoor
September 23, 2021
Tyto Athene

Tyto Athene announced Wednesday that its 13th Annual Golf Tournament, held on September 9th, 2021 at 1757 Golf Club in Dulles, Virginia, raised over $53,000 for the Fisher...

Read moreDetails
Sign Up For Our Newsletter
Subscribe to our mailing list to receives daily updates direct to your inbox!
Invalid email address
Your privacy is guranteed.
Thanks for subscribing!

Sponsors

About ExecutiveGov

ExecutiveGov, published by Executive Mosaic, is a site dedicated to the news and headlines in the federal government. ExecutiveGov serves as a news source for the hot topics and issues facing federal government departments and agencies such as Gov 2.0, cybersecurity policy, health IT, green IT and national security. We also aim to spotlight various federal government employees and interview key government executives whose impact resonates beyond their agency.

CATEGORIES

  • Acquisition & Procurement
  • Announcements
  • Articles
  • Artificial Intelligence
  • Australia
  • Awards
  • Big Data & Analytics News
  • C4ISR
  • C5ISR
  • Cloud
  • Contract Awards
  • Cybersecurity
  • Defense And Intelligence
  • Defense Security Cooperation
  • Department of War
  • DHS
  • Digital Assets
  • Digital Modernization
  • Events
  • Executive Moves
  • Executive Spotlights
  • Federal Civilian
  • Financial Reports
  • Foreign Military Sales
  • General News
  • GovCon Expert
  • Government Cloud
  • Government Technology
  • GSA
  • Healthcare IT
  • Industry News
  • Intelligence Community
  • Legislation
  • M&A Activity
  • Middle East
  • National Security
  • News
  • Policy Updates
  • Press Releases
  • Profiles
  • Space
  • Technology
  • Videos
  • Wash100
Sign Up For Our Newsletter
Subscribe to our mailing list to receives daily updates direct to your inbox!
Invalid email address
Your privacy is guranteed.
Thanks for subscribing!

Copyright 2026 Executive Mosaic. All Rights Reserved. Site Archive

No Result
View All Result
  • Home
  • Acquisition & Procurement
  • Agencies
    • Department of War
    • Intelligence Community
    • DHS
    • Federal Civilian
    • Space
  • Cybersecurity
  • Technology
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news

Copyright 2026 Executive Mosaic. All Rights Reserved. Site Archive

Get your free GovCon news!

Get your latest GovCon news and insights. Become a VIP and subscribe to the GovConWire Daily News.

Invalid email address
We promise not to spam you. You can unsubscribe at any time.
Thanks for subscribing!