Executive Gov
  • Home
  • Acquisition & Procurement
  • Agencies
    • Department of War
    • Intelligence
    • DHS
    • Civilian
    • Space
  • Cybersecurity
  • Technology
  • Awards
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news
No Result
View All Result
Executive Gov
  • Home
  • Acquisition & Procurement
  • Agencies
    • Department of War
    • Intelligence
    • DHS
    • Civilian
    • Space
  • Cybersecurity
  • Technology
  • Awards
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news
No Result
View All Result
Executive Gov
No Result
View All Result
Home Cybersecurity

Federal Agencies Update Warning on Iranian Cyber Actors Targeting PLCs

by Jane Edwards
July 23, 2026
in Cybersecurity, DHS, News
Cybersecurity. CISA and other federal agencies have issued an update to a cyber advisory warning of Iran cyber threat actors.

CISA, FBI, the Environmental Protection Agency and other U.S. government partners have issued an update to a joint cyber advisory warning of Iran-affiliated cyber actors exploiting programmable logic controllers across U.S. critical infrastructure.

  • CISA, FBI and EPA have updated a joint cybersecurity advisory on Iran-linked threat activity
  • New guidance targets malicious PLC code changes and expands the manufacturers covered
  • The 2026 Homeland Security Summit will examine AI, cyber defense and more

The Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency, FBI, the Environmental Protection Agency and other government partners have issued an update to a joint cybersecurity advisory warning of Iran-affiliated cyber actors exploiting programmable logic controllers, or PLCs, across U.S. critical infrastructure.

Table of Contents

    • You might also like
    • FEMA Appoints Steven McAndrews as CIO
    • Raytheon Lands $23B Navy Tomahawk Missile Contract
    • DHA Seeks Industry Input on Modernizing Joint Medical Planning Tools
  • What Does the Updated Advisory Cover?
  • What Has the Iran-Affiliated Activity Targeted?
  • What New Mitigations Are Recommended?
  • What Did Federal Officials Say About the Cyberthreat?
  • What Other Recent Actions Has CISA Taken?

You might also like

FEMA Appoints Steven McAndrews as CIO

Raytheon Lands $23B Navy Tomahawk Missile Contract

DHA Seeks Industry Input on Modernizing Joint Medical Planning Tools

Federal Agencies Update Warning on Iranian Cyber Actors Targeting PLCs

As threats to the nation’s critical infrastructure continue to evolve, government and industry leaders will gather at the Potomac Officers Club’s 2026 Homeland Security Summit on Nov. 12 to discuss AI, cyber defense, border security and operational capabilities at major DHS agencies. Register now to join the conversation shaping the future of homeland security.

CISA said Wednesday the update to the advisory issued in April responds to ongoing Iranian cyber activity aimed at internet-connected operational technology devices. The update includes new indicators of compromise, detection guidance and additional mitigation steps.

What Does the Updated Advisory Cover?

The updated cybersecurity advisory offers new guidance for detecting malicious changes in reusable code modules used in Rockwell Automation PLC programs. It also broadens the advisory’s scope beyond Rockwell Automation, noting that Schneider Electric and Siemens, along with other PLC manufacturers, have also been targeted. CISA said the wider scope highlights why operational technology owners and operators need to limit direct internet access and secure PLC deployment.

What Has the Iran-Affiliated Activity Targeted?

According to the advisory, threat actors have disrupted PLCs across U.S. critical infrastructure sectors, leading to operational disruptions and financial losses for affected organizations. The actors attempted to download malicious project files and alter data on human machine interfaces and supervisory control and data acquisition displays. Targeted sectors include water and wastewater systems, energy, local municipalities, and other government services and facilities.

What New Mitigations Are Recommended?

The updated advisory recommends that organizations take the following additional steps:

  • Consult PLC manufacturers’ existing guidance to help secure operational technology deployments
  • Tightly restrict network access to PLC devices
  • Check project files on PLCs for unauthorized modifications
  • Keep service providers informed of active threats aimed at internet-connected PLC devices

What Did Federal Officials Say About the Cyberthreat?

Chris Butera, CISA’s acting executive assistant director for cybersecurity, said the agency has repeatedly cautioned critical infrastructure stakeholders that threat actors linked to Iran are targeting poorly secured, internet-connected accounts and devices. He called on organizations to consult the updated advisory and put the recommended actions in place.

Brett Leatherman, assistant director of the FBI’s cyber division, said Iranian cyber actors remain focused on U.S. critical infrastructure and that the bureau continues working to identify and disrupt that activity. 

“This advisory provides network defenders with the information they need to identify malicious activity, strengthen their defenses, and reduce opportunities for Iranian cyber actors to disrupt the essential services Americans rely on,” Leatherman added.

Jess Kramer, EPA assistant administrator for water, said cyberthreats represent a significant risk to the nation’s drinking water and wastewater systems, given how many communities, businesses, hospitals and schools depend on them. She called on water systems to remain alert, stay current on emerging threats and put cybersecurity best practices into place.

What Other Recent Actions Has CISA Taken?

Beyond the PLC advisory update, CISA has pursued several other initiatives to strengthen critical infrastructure security and government-industry collaboration. The agency and four international cybersecurity partners recently issued guidance to help software manufacturers and online service providers establish coordinated vulnerability disclosure programs that support collaboration with security researchers. 

CISA shared key lessons from a May cyber incident involving the unauthorized release of internal CISA Amazon Web Services GovCloud keys and other data to a public repository. The agency also established the Alliance of National Councils for Homeland Operational Resilience-Critical Infrastructure to expand information sharing and strengthen government-industry collaboration on critical infrastructure security. 

In May, CISA and the FBI also issued an alert on a Russian phishing campaign targeting users of a commercial messaging application.

Stay connected via Google News
Follow us for the latest travel updates and guides.
Add as preferred source on Google
Share5Tweet19
Previous Post

Office of Naval Research Unveils 2026 Science & Technology Strategy

Next Post

House FY2027 Intelligence Authorization Act Focuses on AI, Oversight and OSINT

Recommended For You

NCTC Provides Mobile App to Help Partners Access Counterterrorism Intelligence; Director Christy Abizaid Quoted

by Nichols Martin
February 9, 2022
NCTC Provides Mobile App to Help Partners Access Counterterrorism Intelligence; Director Christy Abizaid Quoted

The National Counterterrorism Center has released its new mobile app designed to disseminate documents, resources and alerts based on unclassified counterterrorism intelligence.The aCTknowledge app combines analysis, training and...

Read moreDetails

Air Force Using Nellis AFB Facilities to Support Advanced Battle Management System Development; Lt. Col. Kelii Chock Quoted

by Christine Thropp
April 15, 2021
ABMS Development

The U.S. Air Force has started developing and integrating joint all-domain command and control approaches and Advanced Battle Management System (ABMS) technology into the red flag exercises, weapons...

Read moreDetails

4th Space Operations Squadron Secures Access of AEHF-4 Satellite

by Matthew Nelson
May 13, 2019
4th Space Operations Squadron Secures Access of AEHF-4 Satellite

The Space and Missile Systems Center handed control of a satellite unit to the 4th Space Operations Squadron during a ceremony on May 3. Built by Lockheed Martin, the Advanced...

Read moreDetails

NTIA’s Charles Cooper Provides Updates on National Spectrum Strategy Implementation

by Naomi Cooper
April 26, 2024
Charles-Cooper_272x270.webp

Charles Cooper, associate administrator of the National Telecommunications and Information Administration's Office of Spectrum Management, said the agency is initiating technical studies of spectrum bands as part of...

Read moreDetails

Senate Panel’s Defense Spending Bill to Raise Pentagon’s FY 2022 Budget by $24B

by Jane Edwards
December 5, 2022
Senate Panel’s Defense Spending Bill to Raise Pentagon’s FY 2022 Budget by $24B

The Senate Appropriations Committee has proposed a bill that would increase the Department of Defense’s budget by $24 billion for fiscal year 2022 to advance artificial intelligence, machine...

Read moreDetails
Sign Up For Our Newsletter
Subscribe to our mailing list to receives daily updates direct to your inbox!
Invalid email address
Your privacy is guranteed.
Thanks for subscribing!

Sponsors

About ExecutiveGov

ExecutiveGov, published by Executive Mosaic, is a site dedicated to the news and headlines in the federal government. ExecutiveGov serves as a news source for the hot topics and issues facing federal government departments and agencies such as Gov 2.0, cybersecurity policy, health IT, green IT and national security. We also aim to spotlight various federal government employees and interview key government executives whose impact resonates beyond their agency.

CATEGORIES

  • Acquisition & Procurement
  • Announcements
  • Articles
  • Artificial Intelligence
  • Awards
  • Big Data & Analytics News
  • C4ISR
  • C5ISR
  • Civilian
  • Cloud
  • Contract Awards
  • Cybersecurity
  • Defense And Intelligence
  • Defense Security Cooperation
  • Department of War
  • DHS
  • Digital Assets
  • Digital Modernization
  • DoD
  • Events
  • Executive Moves
  • Executive Spotlights
  • Federal Civilian
  • Financial Reports
  • Foreign Military Sales
  • General News
  • GovCon Expert
  • Government Cloud
  • Government Technology
  • GSA
  • Healthcare IT
  • Industry News
  • Intelligence
  • Intelligence Community
  • Legislation
  • M&A Activity
  • National Security
  • News
  • Policy Updates
  • Press Releases
  • Profiles
  • Space
  • Technology
  • Videos
  • Wash100
Sign Up For Our Newsletter
Subscribe to our mailing list to receives daily updates direct to your inbox!
Invalid email address
Your privacy is guranteed.
Thanks for subscribing!

Copyright 2026 Executive Mosaic. All Rights Reserved. Site Archive

No Result
View All Result
  • Home
  • Acquisition & Procurement
  • Agencies
    • Department of War
    • Intelligence
    • DHS
    • Civilian
    • Space
  • Cybersecurity
  • Technology
  • Awards
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news

Copyright 2026 Executive Mosaic. All Rights Reserved. Site Archive

Get your free GovCon news!

Get your latest GovCon news and insights. Become a VIP and subscribe to the GovConWire Daily News.

Invalid email address
We promise not to spam you. You can unsubscribe at any time.
Thanks for subscribing!