Executive Gov
  • Home
  • Acquisition & Procurement
  • Agencies
    • DoD
    • Intelligence
    • DHS
    • Civilian
    • Space
  • Cybersecurity
  • Technology
  • Awards
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news
No Result
View All Result
Executive Gov
  • Home
  • Acquisition & Procurement
  • Agencies
    • DoD
    • Intelligence
    • DHS
    • Civilian
    • Space
  • Cybersecurity
  • Technology
  • Awards
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news
No Result
View All Result
Executive Gov
No Result
View All Result
Home Cybersecurity

Federal Agencies Update Warning on Iranian Cyber Actors Targeting PLCs

by Jane Edwards
July 23, 2026
in Cybersecurity, DHS, News
Cybersecurity. CISA and other federal agencies have issued an update to a cyber advisory warning of Iran cyber threat actors.

CISA, FBI, the Environmental Protection Agency and other U.S. government partners have issued an update to a joint cyber advisory warning of Iran-affiliated cyber actors exploiting programmable logic controllers across U.S. critical infrastructure.

  • CISA, FBI and EPA have updated a joint cybersecurity advisory on Iran-linked threat activity
  • New guidance targets malicious PLC code changes and expands the manufacturers covered
  • The 2026 Homeland Security Summit will examine AI, cyber defense and more

The Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency, FBI, the Environmental Protection Agency and other government partners have issued an update to a joint cybersecurity advisory warning of Iran-affiliated cyber actors exploiting programmable logic controllers, or PLCs, across U.S. critical infrastructure.

Table of Contents

    • You might also like
    • Office of Naval Research Unveils 2026 Science & Technology Strategy
    • USAFE-AFAFRICA Expands Layered Defenses Against Growing UAS Threat
    • GAO Urges ODNI Action on Personnel Vetting, Intelligence Challenges
  • What Does the Updated Advisory Cover?
  • What Has the Iran-Affiliated Activity Targeted?
  • What New Mitigations Are Recommended?
  • What Did Federal Officials Say About the Cyberthreat?
  • What Other Recent Actions Has CISA Taken?

You might also like

Office of Naval Research Unveils 2026 Science & Technology Strategy

USAFE-AFAFRICA Expands Layered Defenses Against Growing UAS Threat

GAO Urges ODNI Action on Personnel Vetting, Intelligence Challenges

Federal Agencies Update Warning on Iranian Cyber Actors Targeting PLCs

As threats to the nation’s critical infrastructure continue to evolve, government and industry leaders will gather at the Potomac Officers Club’s 2026 Homeland Security Summit on Nov. 12 to discuss AI, cyber defense, border security and operational capabilities at major DHS agencies. Register now to join the conversation shaping the future of homeland security.

CISA said Wednesday the update to the advisory issued in April responds to ongoing Iranian cyber activity aimed at internet-connected operational technology devices. The update includes new indicators of compromise, detection guidance and additional mitigation steps.

What Does the Updated Advisory Cover?

The updated cybersecurity advisory offers new guidance for detecting malicious changes in reusable code modules used in Rockwell Automation PLC programs. It also broadens the advisory’s scope beyond Rockwell Automation, noting that Schneider Electric and Siemens, along with other PLC manufacturers, have also been targeted. CISA said the wider scope highlights why operational technology owners and operators need to limit direct internet access and secure PLC deployment.

What Has the Iran-Affiliated Activity Targeted?

According to the advisory, threat actors have disrupted PLCs across U.S. critical infrastructure sectors, leading to operational disruptions and financial losses for affected organizations. The actors attempted to download malicious project files and alter data on human machine interfaces and supervisory control and data acquisition displays. Targeted sectors include water and wastewater systems, energy, local municipalities, and other government services and facilities.

What New Mitigations Are Recommended?

The updated advisory recommends that organizations take the following additional steps:

  • Consult PLC manufacturers’ existing guidance to help secure operational technology deployments
  • Tightly restrict network access to PLC devices
  • Check project files on PLCs for unauthorized modifications
  • Keep service providers informed of active threats aimed at internet-connected PLC devices

What Did Federal Officials Say About the Cyberthreat?

Chris Butera, CISA’s acting executive assistant director for cybersecurity, said the agency has repeatedly cautioned critical infrastructure stakeholders that threat actors linked to Iran are targeting poorly secured, internet-connected accounts and devices. He called on organizations to consult the updated advisory and put the recommended actions in place.

Brett Leatherman, assistant director of the FBI’s cyber division, said Iranian cyber actors remain focused on U.S. critical infrastructure and that the bureau continues working to identify and disrupt that activity. 

“This advisory provides network defenders with the information they need to identify malicious activity, strengthen their defenses, and reduce opportunities for Iranian cyber actors to disrupt the essential services Americans rely on,” Leatherman added.

Jess Kramer, EPA assistant administrator for water, said cyberthreats represent a significant risk to the nation’s drinking water and wastewater systems, given how many communities, businesses, hospitals and schools depend on them. She called on water systems to remain alert, stay current on emerging threats and put cybersecurity best practices into place.

What Other Recent Actions Has CISA Taken?

Beyond the PLC advisory update, CISA has pursued several other initiatives to strengthen critical infrastructure security and government-industry collaboration. The agency and four international cybersecurity partners recently issued guidance to help software manufacturers and online service providers establish coordinated vulnerability disclosure programs that support collaboration with security researchers. 

CISA shared key lessons from a May cyber incident involving the unauthorized release of internal CISA Amazon Web Services GovCloud keys and other data to a public repository. The agency also established the Alliance of National Councils for Homeland Operational Resilience-Critical Infrastructure to expand information sharing and strengthen government-industry collaboration on critical infrastructure security. 

In May, CISA and the FBI also issued an alert on a Russian phishing campaign targeting users of a commercial messaging application.

Stay connected via Google News
Follow us for the latest travel updates and guides.
Add as preferred source on Google
Share5Tweet19

Recommended For You

Office of Naval Research Unveils 2026 Science & Technology Strategy

by Jane Edwards
July 23, 2026
Office of Naval Research seal. ONR has introduced its 2026 science and technology strategy.

ONR has unveiled a new roadmap for naval science and technology investmentThe strategy centers on a five-part "FEED at Speed" frameworkThe 2026 Navy Summit will explore digital engineering,...

Read moreDetails

USAFE-AFAFRICA Expands Layered Defenses Against Growing UAS Threat

by Miles Jamison
July 23, 2026
Air Force logo. USAFE-AFAFRICA is enhancing counter-UAS defense with new equipment and expanded airmen training.

USAFE-AFAFRICA is enhancing counter-drone defense with new equipment and expanded trainingThe command is building a layered air defense network that combines sensors, effectors and other counter-UAS capabilitiesSystems such...

Read moreDetails

GAO Urges ODNI Action on Personnel Vetting, Intelligence Challenges

by Miles Jamison
July 23, 2026
GAO logo. The Government Accountability Office has urged ODNI to address personnel vetting and intelligence challenges.

GAO has reduced the number of priority recommendations requiring action from ODNI to sixODNI has implemented one of 14 priority recommendations identified by GAO in 2025The remaining recommendations...

Read moreDetails

Drone Dominance Program Opens $32M Solicitation for Reusable Bomber Drones

by Kristen Smith
July 23, 2026
Drones. The Drone Dominance Program has opened a solicitation for reusable bomber and dropper drones.

A newly opened category called Mission C targets reusable bomber and dropper dronesVendors that pass the program's Gauntlet benchmarks can win fixed-price dealsDrone Dominance is a $1.1 billion,...

Read moreDetails

FCC Overhauls Space and Earth Station Licensing Rules With New Part 100 Framework

by Jamie Bennet
July 23, 2026
Federal Communications Commission logo. The agency has adopted new rules overhauling Earth and space station licensing.

The Federal Communications Commission has adopted new rules in space and Earth station licensingThe new rules center on the Part 100 framework involving a “licensing assembly line” to...

Read moreDetails
Sign Up For Our Newsletter
Subscribe to our mailing list to receives daily updates direct to your inbox!
Invalid email address
Your privacy is guranteed.
Thanks for subscribing!

Sponsors

About ExecutiveGov

ExecutiveGov, published by Executive Mosaic, is a site dedicated to the news and headlines in the federal government. ExecutiveGov serves as a news source for the hot topics and issues facing federal government departments and agencies such as Gov 2.0, cybersecurity policy, health IT, green IT and national security. We also aim to spotlight various federal government employees and interview key government executives whose impact resonates beyond their agency.

CATEGORIES

  • Acquisition & Procurement
  • Announcements
  • Articles
  • Artificial Intelligence
  • Awards
  • Big Data & Analytics News
  • C4ISR
  • Civilian
  • Cloud
  • Contract Awards
  • Cybersecurity
  • Defense And Intelligence
  • Defense Security Cooperation
  • DHS
  • Digital Assets
  • Digital Modernization
  • DoD
  • Events
  • Executive Moves
  • Executive Spotlights
  • Federal Civilian
  • Financial Reports
  • Foreign Military Sales
  • General News
  • GovCon Expert
  • Government Cloud
  • Government Technology
  • GSA
  • Healthcare IT
  • Industry News
  • Intelligence
  • Legislation
  • M&A Activity
  • National Security
  • News
  • Policy Updates
  • Press Releases
  • Profiles
  • Space
  • Videos
  • Wash100
Sign Up For Our Newsletter
Subscribe to our mailing list to receives daily updates direct to your inbox!
Invalid email address
Your privacy is guranteed.
Thanks for subscribing!

Copyright 2026 Executive Mosaic. All Rights Reserved. Site Archive

No Result
View All Result
  • Home
  • Acquisition & Procurement
  • Agencies
    • DoD
    • Intelligence
    • DHS
    • Civilian
    • Space
  • Cybersecurity
  • Technology
  • Awards
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news

Copyright 2026 Executive Mosaic. All Rights Reserved. Site Archive

Get your free GovCon news!

Get your latest GovCon news and insights. Become a VIP and subscribe to the GovConWire Daily News.

Invalid email address
We promise not to spam you. You can unsubscribe at any time.
Thanks for subscribing!