Latest Update27/08/2026

Threats Feed

  1. Public

    Cyber Exploitation of OT Devices Disrupts US Energy and Water Sectors

    Iranian-affiliated APT actors are actively exploiting internet-facing operational technology (OT) devices, specifically Rockwell Automation/Allen-Bradley programmable logic controllers (PLCs), across U.S. critical infrastructure. Targeting the Government Services and Facilities, Water and Wastewater Systems (WWS), and Energy sectors, these threat actors utilize leased infrastructure, Studio 5000 Logix Designer, and Dropbear SSH to establish unauthorized remote access. By maliciously interacting with extracted project files and manipulating data on HMI and SCADA displays, the attackers have successfully caused operational disruptions and tangible financial losses. Defenders must urgently secure vulnerable ports and monitor for associated indicators of compromise.

    read more about Cyber Exploitation of OT Devices Disrupts US Energy and Water Sectors
  2. Public

    CyberAv3ngers’ Malware Hits IoT/OT Systems in Fuel and Energy Sectors

    Team82's research details the IOCONTROL malware, a custom-built cyberweapon used by Iran-linked attackers, specifically the CyberAv3ngers group. The malware targets a range of industrial control systems (ICS) and Internet of Things (IoT) devices, notably impacting fuel management systems in Israel and the US. IOCONTROL's functionality includes communication via the MQTT protocol and features such as arbitrary code execution and self-deletion. The analysis reveals the malware's infrastructure, including its command-and-control server and the methods used to evade detection. The report concludes that IOCONTROL represents a significant threat to critical infrastructure, highlighting the ongoing geopolitical conflict.

    read more about CyberAv3ngers’ Malware Hits IoT/OT Systems in Fuel and Energy Sectors
  3. Public

    IRGC Cyber Campaigns Against U.S. and Israeli Critical Infrastructure

    Iranian IRGC-affiliated cyber actors, using the persona “CyberAv3ngers,” have been actively targeting and compromising Unitronics Vision Series programmable logic controllers (PLCs) used in the Water and Wastewater Systems (WWS) Sector across multiple U.S. states. These attacks, observed since at least November 2023, involve compromising default credentials and defacing the PLCs, potentially rendering them inoperative. The actors also targeted Israeli PLCs in various sectors like water, energy, and distribution. Additionally, they falsely claimed responsibility for cyberattacks on critical infrastructure in Israel and have connections to the Soldiers of Solomon group. The attacks leverage internet-facing applications and involve tactics like data destruction, resource hijacking, and potential use of ransomware.

    read more about IRGC Cyber Campaigns Against U.S. and Israeli Critical Infrastructure