Executive Gov
  • Home
  • Acquisition & Procurement
  • Agencies
    • Department of War
    • Intelligence
    • DHS
    • Civilian
    • Space
  • Cybersecurity
  • Technology
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news
No Result
View All Result
Executive Gov
  • Home
  • Acquisition & Procurement
  • Agencies
    • Department of War
    • Intelligence
    • DHS
    • Civilian
    • Space
  • Cybersecurity
  • Technology
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news
No Result
View All Result
Executive Gov
No Result
View All Result
Home Cybersecurity

Federal Agencies Update Warning on Iranian Cyber Actors Targeting PLCs

by Jane Edwards
July 23, 2026
in Cybersecurity, DHS, News
Cybersecurity. CISA and other federal agencies have issued an update to a cyber advisory warning of Iran cyber threat actors.

CISA, FBI, the Environmental Protection Agency and other U.S. government partners have issued an update to a joint cyber advisory warning of Iran-affiliated cyber actors exploiting programmable logic controllers across U.S. critical infrastructure.

  • CISA, FBI and EPA have updated a joint cybersecurity advisory on Iran-linked threat activity
  • New guidance targets malicious PLC code changes and expands the manufacturers covered
  • The 2026 Homeland Security Summit will examine AI, cyber defense and more

The Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency, FBI, the Environmental Protection Agency and other government partners have issued an update to a joint cybersecurity advisory warning of Iran-affiliated cyber actors exploiting programmable logic controllers, or PLCs, across U.S. critical infrastructure.

Table of Contents

    • You might also like
    • Fentanyl Free America & How DEA Intelligence Powers Fight Against Illegal Narcotics
    • Navy Seeks Prototype Proposals to Support Defense Industrial Base
    • Sonu Shankar Named DOW Principal Deputy CIO
  • What Does the Updated Advisory Cover?
  • What Has the Iran-Affiliated Activity Targeted?
  • What New Mitigations Are Recommended?
  • What Did Federal Officials Say About the Cyberthreat?
  • What Other Recent Actions Has CISA Taken?

You might also like

Fentanyl Free America & How DEA Intelligence Powers Fight Against Illegal Narcotics

Navy Seeks Prototype Proposals to Support Defense Industrial Base

Sonu Shankar Named DOW Principal Deputy CIO

Federal Agencies Update Warning on Iranian Cyber Actors Targeting PLCs

As threats to the nation’s critical infrastructure continue to evolve, government and industry leaders will gather at the Potomac Officers Club’s 2026 Homeland Security Summit on Nov. 12 to discuss AI, cyber defense, border security and operational capabilities at major DHS agencies. Register now to join the conversation shaping the future of homeland security.

CISA said Wednesday the update to the advisory issued in April responds to ongoing Iranian cyber activity aimed at internet-connected operational technology devices. The update includes new indicators of compromise, detection guidance and additional mitigation steps.

What Does the Updated Advisory Cover?

The updated cybersecurity advisory offers new guidance for detecting malicious changes in reusable code modules used in Rockwell Automation PLC programs. It also broadens the advisory’s scope beyond Rockwell Automation, noting that Schneider Electric and Siemens, along with other PLC manufacturers, have also been targeted. CISA said the wider scope highlights why operational technology owners and operators need to limit direct internet access and secure PLC deployment.

What Has the Iran-Affiliated Activity Targeted?

According to the advisory, threat actors have disrupted PLCs across U.S. critical infrastructure sectors, leading to operational disruptions and financial losses for affected organizations. The actors attempted to download malicious project files and alter data on human machine interfaces and supervisory control and data acquisition displays. Targeted sectors include water and wastewater systems, energy, local municipalities, and other government services and facilities.

What New Mitigations Are Recommended?

The updated advisory recommends that organizations take the following additional steps:

  • Consult PLC manufacturers’ existing guidance to help secure operational technology deployments
  • Tightly restrict network access to PLC devices
  • Check project files on PLCs for unauthorized modifications
  • Keep service providers informed of active threats aimed at internet-connected PLC devices

What Did Federal Officials Say About the Cyberthreat?

Chris Butera, CISA’s acting executive assistant director for cybersecurity, said the agency has repeatedly cautioned critical infrastructure stakeholders that threat actors linked to Iran are targeting poorly secured, internet-connected accounts and devices. He called on organizations to consult the updated advisory and put the recommended actions in place.

Brett Leatherman, assistant director of the FBI’s cyber division, said Iranian cyber actors remain focused on U.S. critical infrastructure and that the bureau continues working to identify and disrupt that activity. 

“This advisory provides network defenders with the information they need to identify malicious activity, strengthen their defenses, and reduce opportunities for Iranian cyber actors to disrupt the essential services Americans rely on,” Leatherman added.

Jess Kramer, EPA assistant administrator for water, said cyberthreats represent a significant risk to the nation’s drinking water and wastewater systems, given how many communities, businesses, hospitals and schools depend on them. She called on water systems to remain alert, stay current on emerging threats and put cybersecurity best practices into place.

What Other Recent Actions Has CISA Taken?

Beyond the PLC advisory update, CISA has pursued several other initiatives to strengthen critical infrastructure security and government-industry collaboration. The agency and four international cybersecurity partners recently issued guidance to help software manufacturers and online service providers establish coordinated vulnerability disclosure programs that support collaboration with security researchers. 

CISA shared key lessons from a May cyber incident involving the unauthorized release of internal CISA Amazon Web Services GovCloud keys and other data to a public repository. The agency also established the Alliance of National Councils for Homeland Operational Resilience-Critical Infrastructure to expand information sharing and strengthen government-industry collaboration on critical infrastructure security. 

In May, CISA and the FBI also issued an alert on a Russian phishing campaign targeting users of a commercial messaging application.

Stay connected via Google News
Follow us for the latest travel updates and guides.
Add as preferred source on Google
Share5Tweet19
Previous Post

Office of Naval Research Unveils 2026 Science & Technology Strategy

Next Post

House FY2027 Intelligence Authorization Act Focuses on AI, Oversight and OSINT

Recommended For You

Census Bureau Deploying GEOINT-Based Canvassing System for 2020 Count

by Brenda Marie Rivers
August 13, 2019
Census Bureau Deploying GEOINT-Based Canvassing System for 2020 Count

The Census Bureau is implementing a new canvassing system that uses satellite imagery data to identify addresses for the 2020 population count, Federal News Network reported Monday. Steven...

Read moreDetails

Army Seeks Night-Vision Tech Improvements

by reynolitoresoor
January 14, 2019
Army Seeks Night-Vision Tech Improvements

The Department of Defense has placed priority on the development of close-combat lethality, with night-vision technology as a key element, National Defense Magazine reported Friday. The U.S. Army...

Read moreDetails

Curtiss-Wright Wins RBSL Contract for British Army Tank Turret Stabilization Upgrades; Lynn Bamford Quoted

by Charles Lyons-Burt
May 3, 2022
Curtiss-Wright Wins RBSL Contract for British Army Tank Turret Stabilization Upgrades; Lynn Bamford Quoted

Curtiss-Wright Corporation has secured a $25 million contract from Rheinmetall BAE Systems Land to equip a battle tank weapon system with its turret drive stabilization apparatus.The contract necessitates that...

Read moreDetails

Charles Verdon Nominated NNSA Deputy Administrator for Defense Programs

by Nichols Martin
October 10, 2018
Charles Verdon Nominated NNSA Deputy Administrator for Defense Programs

Charles Verdon President Donald Trump has nominated Charles Verdon, a principal associate director at Lawrence Livermore National Laboratory, as deputy administrator for defense programs at the Energy Department's National Nuclear...

Read moreDetails

CISA, Partners Warn Organizations of Akira Ransomware Attacks

by Naomi Cooper
April 19, 2024
Cybersecurity_272x270

The Cybersecurity and Infrastructure Security Agency and its U.S. and international partners have released a joint cybersecurity advisory, or CSA, warning organizations against the Akira ransomware that has...

Read moreDetails
Sign Up For Our Newsletter
Subscribe to our mailing list to receives daily updates direct to your inbox!
Invalid email address
Your privacy is guranteed.
Thanks for subscribing!

Sponsors

About ExecutiveGov

ExecutiveGov, published by Executive Mosaic, is a site dedicated to the news and headlines in the federal government. ExecutiveGov serves as a news source for the hot topics and issues facing federal government departments and agencies such as Gov 2.0, cybersecurity policy, health IT, green IT and national security. We also aim to spotlight various federal government employees and interview key government executives whose impact resonates beyond their agency.

CATEGORIES

  • Acquisition & Procurement
  • Announcements
  • Articles
  • Artificial Intelligence
  • Australia
  • Awards
  • Big Data & Analytics News
  • C4ISR
  • C5ISR
  • Civilian
  • Cloud
  • Contract Awards
  • Cybersecurity
  • Defense And Intelligence
  • Defense Security Cooperation
  • Department of War
  • DHS
  • Digital Assets
  • Digital Modernization
  • Events
  • Executive Moves
  • Executive Spotlights
  • Federal Civilian
  • Financial Reports
  • Foreign Military Sales
  • General News
  • GovCon Expert
  • Government Cloud
  • Government Technology
  • GSA
  • Healthcare IT
  • Industry News
  • Intelligence
  • Intelligence Community
  • Legislation
  • M&A Activity
  • Middle East
  • National Security
  • News
  • Policy Updates
  • Press Releases
  • Profiles
  • Space
  • Technology
  • Videos
  • Wash100
Sign Up For Our Newsletter
Subscribe to our mailing list to receives daily updates direct to your inbox!
Invalid email address
Your privacy is guranteed.
Thanks for subscribing!

Copyright 2026 Executive Mosaic. All Rights Reserved. Site Archive

No Result
View All Result
  • Home
  • Acquisition & Procurement
  • Agencies
    • Department of War
    • Intelligence
    • DHS
    • Civilian
    • Space
  • Cybersecurity
  • Technology
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news

Copyright 2026 Executive Mosaic. All Rights Reserved. Site Archive

Get your free GovCon news!

Get your latest GovCon news and insights. Become a VIP and subscribe to the GovConWire Daily News.

Invalid email address
We promise not to spam you. You can unsubscribe at any time.
Thanks for subscribing!