🟠 High  |  Source: The Register — Security


Iran-linked threat actors are actively scanning and probing internet-exposed industrial control systems (ICS) across US critical infrastructure, with CISA expanding its alert beyond Rockwell Automation controllers to cover a broader range of operational technology (OT) devices. The activity suggests reconnaissance that could precede destructive attacks or sabotage against energy, water, and manufacturing sectors. This is significant because OT environments often lack robust monitoring and patching cadences, making them attractive and vulnerable targets.

Security Architect’s Take: Audit your OT/ICS asset inventory immediately and ensure no industrial control devices are directly internet-facing — enforce strict network segmentation and place any remote access behind a hardened VPN or zero-trust gateway with MFA. Review CISA’s updated advisory for the specific device types now flagged and validate that asset owners have applied any available firmware updates or mitigating controls.

Original advisory: Iran-linked crews are probing more flavors of US industrial kit