<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[CISA is claiming that #Iran is once again targeting Programmable Logic Controllers (PLCs), similar to efforts in 2024.]]></title><description><![CDATA[<p>CISA is claiming that <a href="https://infosec.exchange/tags/Iran" rel="tag">#<span>Iran</span></a> is once again targeting Programmable Logic Controllers (PLCs), similar to efforts in 2024. Has anyone seen recent evidence of this? None was provided from CISA, and we'd love independent confirmation.</p>]]></description><link>https://board.circlewithadot.net/topic/6bd41c3f-5db5-473e-a1d8-bcd0f4c69259/cisa-is-claiming-that-iran-is-once-again-targeting-programmable-logic-controllers-plcs-similar-to-efforts-in-2024.</link><generator>RSS for Node</generator><lastBuildDate>Thu, 30 Apr 2026 12:12:27 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/6bd41c3f-5db5-473e-a1d8-bcd0f4c69259.rss" rel="self" type="application/rss+xml"/><pubDate>Mon, 13 Apr 2026 19:21:03 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to CISA is claiming that #Iran is once again targeting Programmable Logic Controllers (PLCs), similar to efforts in 2024. on Mon, 13 Apr 2026 20:48:03 GMT]]></title><description><![CDATA[<p>For the record, we <em>have</em> received independent confirmation of this activity.</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/ap/users/115741367687413652/statuses/116399360140502101</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/ap/users/115741367687413652/statuses/116399360140502101</guid><dc:creator><![CDATA[ifin@infosec.exchange]]></dc:creator><pubDate>Mon, 13 Apr 2026 20:48:03 GMT</pubDate></item><item><title><![CDATA[Reply to CISA is claiming that #Iran is once again targeting Programmable Logic Controllers (PLCs), similar to efforts in 2024. on Mon, 13 Apr 2026 19:57:07 GMT]]></title><description><![CDATA[<p><span><a href="/user/ifin%40infosec.exchange">@<span>ifin</span></a></span> <span><a href="/user/nopatience%40swecyb.com">@<span>nopatience</span></a></span> I no longer work there, but USEPA may have corroborating information; as I understand it, the PLC targets are in drinking wand waste water systems; hence EPA’s potential involvement.</p>]]></description><link>https://board.circlewithadot.net/post/https://puget.social/ap/users/115709310722216374/statuses/116399159882958743</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://puget.social/ap/users/115709310722216374/statuses/116399159882958743</guid><dc:creator><![CDATA[tahomasoft@puget.social]]></dc:creator><pubDate>Mon, 13 Apr 2026 19:57:07 GMT</pubDate></item><item><title><![CDATA[Reply to CISA is claiming that #Iran is once again targeting Programmable Logic Controllers (PLCs), similar to efforts in 2024. on Mon, 13 Apr 2026 19:32:10 GMT]]></title><description><![CDATA[<p><span><a href="/user/nopatience%40swecyb.com" rel="nofollow noopener">@<span>nopatience</span></a></span> Thank you for these!</p><p>The first is a measurement of exposure of OT of types previously attacked, not a report of current exploitation. The second is a report about a new attack tool available for sale. These are useful, but neither are confirmation of CISA's claim that:</p><blockquote><p>Iran-affiliated advanced persistent threat (APT) actors are conducting exploitation activity targeting internet-facing operational technology (OT) devices, including programmable logic controllers (PLCs) manufactured by Rockwell Automation/Allen-Bradley. </p></blockquote><p>Note the present tense, as of 2026-04-07.</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/ap/users/115741367687413652/statuses/116399061784914089</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/ap/users/115741367687413652/statuses/116399061784914089</guid><dc:creator><![CDATA[ifin@infosec.exchange]]></dc:creator><pubDate>Mon, 13 Apr 2026 19:32:10 GMT</pubDate></item><item><title><![CDATA[Reply to CISA is claiming that #Iran is once again targeting Programmable Logic Controllers (PLCs), similar to efforts in 2024. on Mon, 13 Apr 2026 19:29:19 GMT]]></title><description><![CDATA[<p><span><a href="https://infosec.exchange/@kiddcutty">@<span>kiddcutty</span></a></span> That's exactly the report we're trying to verify.</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/ap/users/115741367687413652/statuses/116399050529828548</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/ap/users/115741367687413652/statuses/116399050529828548</guid><dc:creator><![CDATA[ifin@infosec.exchange]]></dc:creator><pubDate>Mon, 13 Apr 2026 19:29:19 GMT</pubDate></item><item><title><![CDATA[Reply to CISA is claiming that #Iran is once again targeting Programmable Logic Controllers (PLCs), similar to efforts in 2024. on Mon, 13 Apr 2026 19:28:01 GMT]]></title><description><![CDATA[<p><span><a href="/user/ifin%40infosec.exchange">@<span>ifin</span></a></span> There appears to have been some articles preceding the CISA advisory, and when viewed together may paint some sort of "capability" picture.</p><p>2026-01-28: <a href="https://lab52.io/blog/black-industry-irgc-linked-offensive-ot-framework/" rel="nofollow noopener"><span>https://</span><span>lab52.io/blog/black-industry-i</span><span>rgc-linked-offensive-ot-framework/</span></a></p><p>2026-03-30: <a href="https://censys.com/blog/ics-iran-part-2-revisiting-exposure-of-previously-targeted-ics-devices/" rel="nofollow noopener"><span>https://</span><span>censys.com/blog/ics-iran-part-</span><span>2-revisiting-exposure-of-previously-targeted-ics-devices/</span></a></p><p>And a few more. I have not spent a significant amount of time exploring these in depth, but just some quick references to potentially relevant articles.</p>]]></description><link>https://board.circlewithadot.net/post/https://swecyb.com/users/nopatience/statuses/116399045442501678</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://swecyb.com/users/nopatience/statuses/116399045442501678</guid><dc:creator><![CDATA[nopatience@swecyb.com]]></dc:creator><pubDate>Mon, 13 Apr 2026 19:28:01 GMT</pubDate></item><item><title><![CDATA[Reply to CISA is claiming that #Iran is once again targeting Programmable Logic Controllers (PLCs), similar to efforts in 2024. on Mon, 13 Apr 2026 19:23:38 GMT]]></title><description><![CDATA[<p><span><a href="/user/ifin%40infosec.exchange">@<span>ifin</span></a></span> </p><p>This was put out by CISA on April 7th. Attacks against Rockwell/Allen Bradley PLCs.</p><p><div class="card col-md-9 col-lg-6 position-relative link-preview p-0">

<div class="card-body">
<h5 class="card-title">
<a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-097a">
Access Denied
</a>
</h5>
<p class="card-text line-clamp-3"></p>
</div>
<a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-097a" class="card-footer text-body-secondary small d-flex gap-2 align-items-center lh-2">



<img src="https://www.cisa.gov/favicon.ico" alt="favicon" class="not-responsive overflow-hiddden" style="max-width: 21px; max-height: 21px;" />



<p class="d-inline-block text-truncate mb-0"> <span class="text-secondary">(www.cisa.gov)</span></p>
</a>
</div></p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/kiddcutty/statuses/116399028179474335</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/kiddcutty/statuses/116399028179474335</guid><dc:creator><![CDATA[kiddcutty@infosec.exchange]]></dc:creator><pubDate>Mon, 13 Apr 2026 19:23:38 GMT</pubDate></item></channel></rss>