{"id":4644,"date":"2026-07-24T05:28:32","date_gmt":"2026-07-24T05:28:32","guid":{"rendered":"https:\/\/koshalsambada.in\/?p=4644"},"modified":"2026-07-24T05:28:32","modified_gmt":"2026-07-24T05:28:32","slug":"fbi-nsa-and-cisa-issue-urgent-warning-iranian-hackers-hit-critical-us-infrastructure-and-safety-systems","status":"publish","type":"post","link":"https:\/\/koshalsambada.in\/?p=4644","title":{"rendered":"FBI, NSA and CISA issue urgent warning: Iranian hackers hit critical US infrastructure and safety systems"},"content":{"rendered":"<p><br \/>\n<\/p>\n<div data-articlebody=\"1\"><video-embed value=\"false\"\/><\/p>\n<div class=\"ihgno clearfix  \">\n<div class=\"e9jwa\">\n<div class=\"vdo_embedd\">\n<div class=\"GfdvZ\">\n<section class=\"_bIDB  clearfix id-r-component leadmedia undefined undefined  E9tg9 \" style=\"top:0px\">\n<div class=\"_bIDB\" data-ua-type=\"1\" onclick=\"stpPgtnAndPrvntDefault(event)\">\n<div class=\"ypVvZ\">\n<div class=\"WGttI\"><img src=\"https:\/\/static.toiimg.com\/thumb\/msid-132595432,imgsize-55870,width-400,height-225,resizemode-4\/us-cybersecurity-agency-cisa.jpg\" alt=\"FBI, NSA and CISA issue urgent warning: Iranian hackers hit critical US infrastructure and safety systems\" title=\"FBI, NSA and CISA issued a joint warning\" decoding=\"async\" fetchpriority=\"high\"\/><\/div>\n<\/div>\n<\/div>\n<div class=\"Ta7d_ img_cptn\"><span title=\"FBI, NSA and CISA issued a joint warning\">FBI, NSA and CISA issued a joint warning<\/span><\/div>\n<\/section>\n<\/div><\/div>\n<\/div>\n<p>US federal cyber agencies have issued an urgent joint warning, claiming that Iranian state-backed hackers are actively breaching and tampering with industrial control systems at US water and energy providers.<!-- --> In an updated security advisory, the Federal Bureau of Investigation (FBI), the National Security Agency (NSA), the Cybersecurity and Infrastructure Security Agency (CISA), and the Department of Energy warned that \u201cpotentially all internet-exposed\u201d industrial control systems across critical US infrastructure could be vulnerable to attack.<span class=\"id-r-component br\" data-pos=\"3\"\/><\/p>\n<p><h2>\u2018Tampering with safety alarms and emergency shutdowns\u2019<br \/><\/h2>\n<\/p>\n<p><span class=\"id-r-component br\" data-pos=\"5\"\/>According to federal investigators, the Iranian-backed hackers are targeting programmable logic controllers, which are the specialised digital computers that govern physical machinery, valves, and power switches across utility networks.<span class=\"id-r-component br\" data-pos=\"9\"\/>As per the warning, by altering display data and programming logic, the attackers have forced systems into dangerous operational states without alerting human supervisors. CISA and partner agencies are calling on all critical infrastructure operators to immediately audit their operational technology, disconnect industrial control systems from the public internet, and enforce strict multi-factor authentication.<span class=\"id-r-component br\" data-pos=\"13\"\/><\/p>\n<p><h2>Read the updated warning by FBI, NSA and CISA<\/h2>\n<\/p>\n<p><span class=\"id-r-component br\" data-pos=\"15\"\/><span class=\"em\" data-ua-type=\"1\" onclick=\"stpPgtnAndPrvntDefault(event)\">The authoring agencies urgently warn U.S. organizations of ongoing Iranian-affiliated cyber targeting of internet-connected operational technology (OT) devices, including programmable logic controllers (PLCs). These actions disrupted PLCs across several U.S. critical infrastructure sectors through malicious project file interactions and manipulation of data on human machine interface (HMI) and supervisory control and data acquisition (SCADA) displays, resulting in operational disruption and financial loss.<\/span><span class=\"id-r-component br\" data-pos=\"17\"\/><span class=\"em\" data-ua-type=\"1\" onclick=\"stpPgtnAndPrvntDefault(event)\">Last Update Description<\/span><span class=\"id-r-component br\" data-pos=\"19\"\/><span class=\"em\" data-ua-type=\"1\" onclick=\"stpPgtnAndPrvntDefault(event)\">This update adds new guidance on detecting malicious changes in reusable code modules exploited within Rockwell Automation PLC programs. It also expands scope to include observed targeting of <\/span><span class=\"em\" data-ua-type=\"1\" onclick=\"stpPgtnAndPrvntDefault(event)\">Schneider Electric<\/span><span class=\"em\" data-ua-type=\"1\" onclick=\"stpPgtnAndPrvntDefault(event)\">, Siemens, and potentially other branded\/manufactured PLCs, emphasizing the importance of restricting direct internet access and providing best practices for secure deployment.<\/span><span class=\"id-r-component br\" data-pos=\"23\"\/><span class=\"em\" data-ua-type=\"1\" onclick=\"stpPgtnAndPrvntDefault(event)\">Affected Products<\/span><span class=\"id-r-component br\" data-pos=\"25\"\/><span class=\"em\" data-ua-type=\"1\" onclick=\"stpPgtnAndPrvntDefault(event)\">Potentially all internet exposed PLCs, including Rockwell Automation\/Allen-Bradley, Schneider Electric, Siemens, and other branded\/manufactured PLCs.<\/span><span class=\"id-r-component br\" data-pos=\"27\"\/><span class=\"em\" data-ua-type=\"1\" onclick=\"stpPgtnAndPrvntDefault(event)\">Key Actions<\/span> <span class=\"id-r-component br\" data-pos=\"30\"\/><\/p>\n<div class=\"cdatainfo   id-r-component \" data-pos=\"31\">\n<ul>\n<li>Install PLCs consistent with manufacturers&#8217; guidelines and security best practices.<\/li>\n<\/ul>\n<\/div>\n<p><span class=\"id-r-component br\" data-pos=\"32\"\/><\/p>\n<div class=\"cdatainfo   id-r-component \" data-pos=\"33\">\n<ul>\n<li>Remove PLCs from direct internet exposure via secure gateway and firewall; work with IT\/OT team members and\/or integrators to perform this action.<\/li>\n<\/ul>\n<\/div>\n<p><span class=\"id-r-component br\" data-pos=\"34\"\/><\/p>\n<div class=\"cdatainfo   id-r-component \" data-pos=\"35\">\n<ul>\n<li>Query available logs for the provided indicators of compromise (IOCs) and check available logs for suspicious traffic on the ports associated with OT devices, including 44818, 2222, 102, and 502, especially traffic originating from foreign hosting providers.<\/li>\n<li>For Rockwell Automation devices, place the physical mode switch on the controller into run position. If you suspect your organization was targeted, including against other branded PLC devices, contact the authoring agencies and PLC manufacturer for guidance.<\/li>\n<\/ul>\n<\/div>\n<p><span class=\"id-r-component br\" data-pos=\"36\"\/><\/div>\n<\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/timesofindia.indiatimes.com\/technology\/tech-news\/fbi-nsa-and-cisa-issue-urgent-warning-iranian-hackers-hit-critical-us-infrastructure-and-safety-systems\/articleshow\/132595403.cms\" target=\"_blank\" rel=\"noopener\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>FBI, NSA and CISA issued a joint warning US federal cyber agencies have issued an urgent joint warning, claiming that Iranian state-backed hackers are actively breaching and tampering with industrial control systems at US water and energy providers. In an updated security advisory, the Federal Bureau of Investigation (FBI), the National Security Agency (NSA), the [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":4645,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[31],"tags":[],"class_list":["post-4644","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-31"],"magazineBlocksPostFeaturedMedia":{"thumbnail":"https:\/\/koshalsambada.in\/wp-content\/uploads\/2026\/07\/us-cybersecurity-agency-cisa.jpg","medium":"https:\/\/koshalsambada.in\/wp-content\/uploads\/2026\/07\/us-cybersecurity-agency-cisa.jpg","medium_large":"https:\/\/koshalsambada.in\/wp-content\/uploads\/2026\/07\/us-cybersecurity-agency-cisa.jpg","large":"https:\/\/koshalsambada.in\/wp-content\/uploads\/2026\/07\/us-cybersecurity-agency-cisa.jpg","1536x1536":"https:\/\/koshalsambada.in\/wp-content\/uploads\/2026\/07\/us-cybersecurity-agency-cisa.jpg","2048x2048":"https:\/\/koshalsambada.in\/wp-content\/uploads\/2026\/07\/us-cybersecurity-agency-cisa.jpg","blogsy-small":"https:\/\/koshalsambada.in\/wp-content\/uploads\/2026\/07\/us-cybersecurity-agency-cisa.jpg","blogsy-small-tall":"https:\/\/koshalsambada.in\/wp-content\/uploads\/2026\/07\/us-cybersecurity-agency-cisa.jpg","blogsy-small-square":"https:\/\/koshalsambada.in\/wp-content\/uploads\/2026\/07\/us-cybersecurity-agency-cisa.jpg","blogsy-small-masonry":"https:\/\/koshalsambada.in\/wp-content\/uploads\/2026\/07\/us-cybersecurity-agency-cisa.jpg","blogsy-medium":"https:\/\/koshalsambada.in\/wp-content\/uploads\/2026\/07\/us-cybersecurity-agency-cisa.jpg","blogsy-medium-masonry":"https:\/\/koshalsambada.in\/wp-content\/uploads\/2026\/07\/us-cybersecurity-agency-cisa.jpg","blogsy-large":"https:\/\/koshalsambada.in\/wp-content\/uploads\/2026\/07\/us-cybersecurity-agency-cisa.jpg","blogsy-wide":"https:\/\/koshalsambada.in\/wp-content\/uploads\/2026\/07\/us-cybersecurity-agency-cisa.jpg"},"magazineBlocksPostAuthor":{"name":"admin","avatar":"https:\/\/secure.gravatar.com\/avatar\/8709732a479614e7a8aa24d3eb1b239f30dc6d90c61464ed495001e7a469d856?s=96&d=mm&r=g"},"magazineBlocksPostCommentsNumber":"0","magazineBlocksPostExcerpt":"FBI, NSA and CISA issued a joint warning US federal cyber agencies have issued an urgent joint warning, claiming that Iranian state-backed hackers are actively breaching and tampering with industrial control systems at US water and energy providers. In an updated security advisory, the Federal Bureau of Investigation (FBI), the National Security Agency (NSA), the [&hellip;]","magazineBlocksPostCategories":["\u0b26\u0b47\u0b36 \u0b2c\u0b3f\u0b26\u0b47\u0b36"],"magazineBlocksPostViewCount":1,"magazineBlocksPostReadTime":3,"magazine_blocks_featured_image_url":{"full":["https:\/\/koshalsambada.in\/wp-content\/uploads\/2026\/07\/us-cybersecurity-agency-cisa.jpg",400,225,false],"medium":["https:\/\/koshalsambada.in\/wp-content\/uploads\/2026\/07\/us-cybersecurity-agency-cisa.jpg",300,169,false],"thumbnail":["https:\/\/koshalsambada.in\/wp-content\/uploads\/2026\/07\/us-cybersecurity-agency-cisa.jpg",150,84,false]},"magazine_blocks_author":{"display_name":"admin","author_link":"https:\/\/koshalsambada.in\/author\/admin"},"magazine_blocks_comment":0,"magazine_blocks_author_image":"https:\/\/secure.gravatar.com\/avatar\/8709732a479614e7a8aa24d3eb1b239f30dc6d90c61464ed495001e7a469d856?s=96&d=mm&r=g","magazine_blocks_category":"<a href=\"#\" class=\"category-link category-link-31\">\u0b26\u0b47\u0b36 \u0b2c\u0b3f\u0b26\u0b47\u0b36<\/a>","_links":{"self":[{"href":"https:\/\/koshalsambada.in\/index.php?rest_route=\/wp\/v2\/posts\/4644","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/koshalsambada.in\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/koshalsambada.in\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/koshalsambada.in\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/koshalsambada.in\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=4644"}],"version-history":[{"count":0,"href":"https:\/\/koshalsambada.in\/index.php?rest_route=\/wp\/v2\/posts\/4644\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/koshalsambada.in\/index.php?rest_route=\/wp\/v2\/media\/4645"}],"wp:attachment":[{"href":"https:\/\/koshalsambada.in\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=4644"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/koshalsambada.in\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=4644"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/koshalsambada.in\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=4644"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}