Executive Gov
  • Home
  • Acquisition & Procurement
  • Agencies
    • Department of War
    • Intelligence
    • DHS
    • Civilian
    • Space
  • Cybersecurity
  • Technology
  • Awards
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news
No Result
View All Result
Executive Gov
  • Home
  • Acquisition & Procurement
  • Agencies
    • Department of War
    • Intelligence
    • DHS
    • Civilian
    • Space
  • Cybersecurity
  • Technology
  • Awards
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news
No Result
View All Result
Executive Gov
No Result
View All Result
Home Civilian

Federal Agencies Warn of Iranian Cyberthreats Targeting US Infrastructure

by Miles Jamison
April 8, 2026
in Civilian, Cybersecurity, News
Federal Agencies Warn of Iranian Cyberthreats Targeting US Infrastructure

Federal Agencies Warn of Iranian Cyberthreats Targeting US Infrastructure

The Cybersecurity and Infrastructure Security Agency and other U.S. federal agencies have issued an advisory warning that Iranian-affiliated cyber actors are actively targeting programmable logic controllers used across critical infrastructure sectors, causing operational disruptions in some cases.

Table of Contents

    • You might also like
    • Gen. Michael Guetlein: Golden Dome SBI Contenders Pass 1st Test
    • Presidential Memo Seeks to Expand Private Sector’s Role in Fighting Transnational Cybercrime
    • DEA Appoints Marc Kuzmicki as Deputy Chief of Intelligence
  • What Activity Have CISA & Other Agencies Observed? 
  • Which Devices Are Affected?  
  • How Are the Attacks Being Carried Out?
  • What Actions Are Recommended?

You might also like

Gen. Michael Guetlein: Golden Dome SBI Contenders Pass 1st Test

Presidential Memo Seeks to Expand Private Sector’s Role in Fighting Transnational Cybercrime

DEA Appoints Marc Kuzmicki as Deputy Chief of Intelligence

Federal Agencies Warn of Iranian Cyberthreats Targeting US InfrastructureDon’t miss the chance to connect with leaders strengthening defenses against evolving global threats at the Potomac Officers Club's 2026 Cyber Summit on May 21. Register today!

What Activity Have CISA & Other Agencies Observed? 

CISA said in the advisory released Tuesday that, along with the FBI, National Security Agency, Environmental Protection Agency, Department of Energy and U.S. Cyber Command – Cyber National Mission Force, it believes advanced persistent threat actors are exploiting internet-connected operational technology devices, including programmable logic controllers, or PLCs, developed by Rockwell Automation and Allen-Bradley. The agencies said malicious activity has involved unauthorized interaction with project files and manipulation of data displayed on supervisory control and data acquisition systems.

Which Devices Are Affected?  

The authoring agencies noted that attackers are targeting devices used across government services, water and wastewater, and energy sectors. Affected devices include CompactLogix and Micro850 PLCs, with traffic observed on ports 44818, 2222, 102, 22 and 502. The agencies also said the actors deployed Dropbear SSH software to gain remote access through port 22. Indicators of compromise include IP addresses originating from overseas hosting providers.

How Are the Attacks Being Carried Out?

Threat actors are using overseas-based infrastructure to access exposed devices and communicate through common industrial control system ports. In some instances, they deployed remote access tools to maintain control of compromised systems. Moreover, the activity has resulted in altered system data and disruption of industrial processes, with some organizations reporting financial impacts tied to the incidents.

What Actions Are Recommended?

To safeguard critical infrastructure, organizations must immediately disconnect PLCs from the public-facing internet and remove all inbound port exposure to prevent unauthorized external access. Remote connectivity should be strictly mediated through secure gateways or jump hosts, while cellular modems must be hardened with strong authentication, regular updates and active logging. For physical security, operators should set controller switches to the run position to block remote logic modifications and use software-based programming protections on devices such as Siemens S7. Finally, maintaining and testing offline backups of all PLC configurations is essential.

Organizations are urged to review tactics and techniques, and indicators of compromise outlined in the advisory and coordinate with federal and vendor support channels if suspicious activity is identified.

Stay connected via Google News
Follow us for the latest travel updates and guides.
Add as preferred source on Google
Share5Tweet19
Previous Post

Air Force Advances ARES Platform to Modernize Aircrew Management

Next Post

DOE's ARPA-E Selects 12 Projects to Accelerate AI-Driven Catalyst Innovation

Recommended For You

Lockheed Martin Wins $187.5M Contract to Build Small Satellite Mesh Network; Kay Sears Quoted

by Sarah Sybert
May 29, 2024
Kay Sears

Lockheed Martin has been awarded a  $187.5 million Tranche 0 contract of the Space Transport Layer from the Space Development Agency (SDA). Under the contract, Lockheed Martin will...

Read moreDetails

Raytheon, Red Hat Collaborating on DevSecOps Software Development Solution; John DeSimone, Paul Smith Quoted

by William McCormick
November 12, 2019
Raytheon, Red Hat Collaborating on DevSecOps Software Development Solution; John DeSimone, Paul Smith Quoted

Raytheon announced on Tuesday that the company is collaborating with Red Hat to develop a new, security-focused software development solution, known as DevSecOps, for enterprise environments.

Read moreDetails

Lawmakers Urge Senate Panel to Include Additional TMF Funding in Next COVID-19 Relief Package

by Jane Edwards
December 5, 2022
US Capitol

Six lawmakers have called on the leaders of the Senate Appropriations Committee to allot an additional $1 billion for the Technology Modernization Fund in the upcoming COVID-19 relief measure...

Read moreDetails

Kevin Cox: CDM Program Helps Pandemic Response Agencies Improve Network Visibility

by Jane Edwards
July 23, 2020
Kevin Cox

Kevin Cox, manager of the Continuous Diagnostics and Mitigation (CDM) program, said the program is working with the federal agencies involved in vaccine research and other COVID-19 pandemic response...

Read moreDetails

GAO Report Says Trusted Workforce 2.0 Caused Enhancements, Challenges

by Kristen Smith
May 12, 2025
GAO Report Says Trusted Workforce 2.0 Caused Enhancements, Challenges

Government agencies and contractors have experienced positive changes due to the Trusted Workforce 2.0, or TW 2.0, implementation, but pointed out several challenges, according to the Government Accountability...

Read moreDetails
Sign Up For Our Newsletter
Subscribe to our mailing list to receives daily updates direct to your inbox!
Invalid email address
Your privacy is guranteed.
Thanks for subscribing!

Sponsors

About ExecutiveGov

ExecutiveGov, published by Executive Mosaic, is a site dedicated to the news and headlines in the federal government. ExecutiveGov serves as a news source for the hot topics and issues facing federal government departments and agencies such as Gov 2.0, cybersecurity policy, health IT, green IT and national security. We also aim to spotlight various federal government employees and interview key government executives whose impact resonates beyond their agency.

CATEGORIES

  • Acquisition & Procurement
  • Announcements
  • Articles
  • Artificial Intelligence
  • Awards
  • Big Data & Analytics News
  • C4ISR
  • Civilian
  • Cloud
  • Contract Awards
  • Cybersecurity
  • Defense And Intelligence
  • Defense Security Cooperation
  • Department of War
  • DHS
  • Digital Assets
  • Digital Modernization
  • DoD
  • Events
  • Executive Moves
  • Executive Spotlights
  • Federal Civilian
  • Financial Reports
  • Foreign Military Sales
  • General News
  • GovCon Expert
  • Government Cloud
  • Government Technology
  • GSA
  • Healthcare IT
  • Industry News
  • Intelligence
  • Intelligence Community
  • Legislation
  • M&A Activity
  • National Security
  • News
  • Policy Updates
  • Press Releases
  • Profiles
  • Space
  • Technology
  • Videos
  • Wash100
Sign Up For Our Newsletter
Subscribe to our mailing list to receives daily updates direct to your inbox!
Invalid email address
Your privacy is guranteed.
Thanks for subscribing!

Copyright 2026 Executive Mosaic. All Rights Reserved. Site Archive

No Result
View All Result
  • Home
  • Acquisition & Procurement
  • Agencies
    • Department of War
    • Intelligence
    • DHS
    • Civilian
    • Space
  • Cybersecurity
  • Technology
  • Awards
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news

Copyright 2026 Executive Mosaic. All Rights Reserved. Site Archive

Get your free GovCon news!

Get your latest GovCon news and insights. Become a VIP and subscribe to the GovConWire Daily News.

Invalid email address
We promise not to spam you. You can unsubscribe at any time.
Thanks for subscribing!