Search/unitronics
Vendor

unitronics

Known CVEs
0
Highest CVSS
In KEV
0
Vendor
samba 3.5 firmware
Connections
28 relationships
2026 World Cup: Discussing The World’s Biggest Game’s Attack Surface
The 2026 FIFA World Cup will be the largest sporting event ever staged. Across 39 days, 16 host cities in three nations will host 104 matches, an expanded 48-team tournament and an estimated five-to-six million in-venue spectators alongside a global broadcast audience approaching half the planet. The tournament opens at Estadio Azteca in Mexico City on June 11, 2026, and concludes at MetLife Stadium in East Rutherford, New Jersey, on July 19, 2026. This is the first World Cup to be jointly hosted by three nations. Each match runs on a temporary, multi-ring tournament network grafted onto pre-existing NFL, MLS, CFL and Liga MX stadium environments. It depends on a network of municipal services, including public transit, signalized traffic, water and wastewater treatment, regional power, airport operations and emergency services. Each of those touchpoints is in scope for an adversary. Based on a review of cyber operations against prior mega-events from 2016 through the Milano-Cortina 2026 Winter Games, this assessment finds that disruptive intrusions, criminal fraud at scale and politically motivated distributed denial-of-service (DDoS) and hack-and-leak operations are highly likely. The only meaningful questions are who, against which targets and at what severity. There are three drivers in the 2026 World Cup risk picture: Iran-nexus activity. The U.S.–Israel–Iran kinetic conflict that began on Feb. 28, 2026 has reordered the threat surface for any U.S.-hosted event. The Handala Hack Team, assessed by the U.S. Federal Bureau of Investigation (FBI) and multiple commercial threat intelligence firms to be a front for Iran's Ministry of Intelligence and Security (MOIS), executed significant wiper attacks in early 2026. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) published a joint advisory AA26-097A confirming an active, ongoing Iranian-affiliated campaign. The campaign targets internet-exposed Rockwell Automation and Allen-Bradley programmable logic controllers (PLCs) in U.S. critical infrastructure, as well as Islamic Revolutionary Guard Corps (IRGC) targeting of Israeli-made Unitronics Vision Series PLCs at U.S. water, energy and municipal targets. These are the same categories of infrastructure that World Cup host cities will be operating under tournament load. Russia-nexus hacktivism. Since 2022, NoName057(16) has conducted over 3,700 verified DDoS attacks against governments and critical sectors in NATO member states. Documented surges keyed to politically symbolic events including the NATO Summit, the Ukraine Peace Summit and claims of intent at the Paris 2022 Olympics and the Milano Cortina 2026 Winter Olympics. Operation Eastwood (July 2025) disrupted but did not eliminate the group. The UK NCSC confirmed continued operations into 2026. The U.S., Canada and Mexico are NATO partners or allies and the World Cup is a politically symbolic event of the highest order. Financially motivated cybercrime. Group-IB identified more than 16,000 fraudulent domains and 90 compromised Hayya fan-portal accounts during World Cup 2022 in Qatar. The 2023 Muddled Libra (operators of ALPHV aka BlackCat ransomware) campaign against entertainment organizations demonstrated that the hospitality stack is a target for ransomware operators. The stack includes reservations, digital keys, point-of-sale (PoS) machines and loyalty data. Ticket fraud, accommodation fraud, transportation QR-code fraud and FanID-equivalent account takeover are prime targets at scale across all three host nations. The Paris 2024 Olympics is a strong example of a recent precedent. French authorities (ANSSI) confirmed at least 140 cyber events during the Games, including 22 confirmed unauthorized intrusions and a ransomware attack against the Grand Palais venue. None succeeded in disrupting competition, but only because of preparation that began years earlier. Preparation included exercises against 500 Games-linked facilities, and support by sustained government-industry coordination. The 2026 tournament must clear the same bar across multiple jurisdictions, regulatory bodies and languages. The Bottom Line Defenders should plan against the possibility of all of the following: Cybercriminals targeting fans and the hospitality supply chain Iran-nexus disruptive operations against ancillary U.S. infrastructure during the tournament window Pro-Russian and pro-Iran hacktivist DDoS and defacement targeting of host-city, federation and ticketing services A wiper deployed against tournament IT during a high-visibility ceremony Previous Attacks Against Major International Sporting Events Table 1. Previous attacks against major sporting events. Cybercriminal Threats to Fans and the Tournament Supply Chain Financially motivated cybercrime is the highest-volume, highest-likelihood threat category for the 2026 FIFA World Cup Games. Ticket Fraud and FanID-equivalent Account Takeover Based on the Qatar 2022 Games, there are five categories of ticket-themed fraud: Lookalike resale sites Fake social-media reseller accounts Lottery/giveaway phishing Fake mobile applications on official app stores Credential-stuffing attacks against the official fan portal Hospitality and Accommodation Fraud Attacks against hospitality businesses and platforms, digital key infrastructure, point of sale (PoS) and identity providers and fake short-term rental properties are another potential area of risk. QR-Code, Transportation and PoS Fraud Tournament-specific QR-code fraud is the single fastest-growing variant. There have already been observed pre-tournament listing scams, and a high potential for fake shuttle passes, parking permits and official fan transport QR codes that fail when scanned. The geographic spread of the 2026 games in various cities multiplies opportunities for transit-themed fraud relative to single-host-city games. Phishing, Malware and Lure Themes Confirmed lure themes from prior tournaments include: Lottery winnings Ticket cancellations FIFA dispute-resolution decisions Accreditation problems FanID issues Free streaming Counterfeit merchandise Expect to see typosquatted FIFA domains, malicious mobile applications, infostealers sold on Telegram, and Telegram-based reseller channels moving money via peer-to-peer payment apps as seen in Table 2. Table 2. Cybercriminal techniques that are possible during the World Cup. Geopolitical Threats: Iran-Nexus and Disruptive Hacktivism The geopolitical context for the 2026 tournament is materially different from any prior World Cup. The U.S.-Israel-Iran conflict has produced a surge in Iran-nexus cyber operations against U.S. organizations. The Russia-Ukraine war and the resulting NATO alignment of all three host nations make pro-Russian hacktivism an additional, parallel risk. Iran-Nexus: The Handala Hack Team The Handala Hack Team (aka Banished Kitten, Storm-0842, Void Manticore and Cobalt Mystique) and Ababil of Minab, are just two of several front personas operated by Iran's MOIS directly responsible for wiper attacks, targeting high-level government officials, and doxxing employees of public companies. Iran-Nexus: CyberAv3ngers and OT Targeting CyberAv3ngers (aka Shahid Kaveh Group, Bauxite, Hydro Kitten, Storm-0784 and UNC5691) is the IRGC Cyber-Electronic Command's industrial-control-system arm. Its documented escalation curve is the single most important data point for defenders concerned with municipal infrastructure during the FIFA World Cup 2026. Every World Cup host city in the United States operates municipal water, wastewater and energy infrastructure inside this advisory's threat envelope. A 2024 CISA assessment found over 70% non-compliance with existing safety requirements at U.S. water utilities. Iran-Nexus: Other Personas and the Electronic Operations Room Beyond Handala and CyberAv3ngers, multiple Iran-aligned personas — DieNet, APTIran, Cyber Toufan, Cyber Support Front, Iranian Avenger, Cyb3r Drag0nz — have been observed operating through a team named the Electronic Operations Room of Islamic Resistance Axis. This team formed in late February 2026. DieNet has specifically claimed DDoS attacks against Bahrain and Saudi airports and Jordanian banks — transportation and finance targets directly relevant to fan-facing infrastructure. Russia-Nexus: NoName057(16) and Allied Hacktivists NoName057(16) has been the most operationally consistent pro-Russian hacktivist group since March 2022, with an attributed 3,700-plus targeted hosts to the group between July 2024 and July 2025. The UK NCSC, Eurojust and Europol issued co-sealed advisories in December 2025 and January 2026 regarding the hacktivist group. Operation Eastwood produced two arrests and seven arrest warrants but did not stop the group, which resumed activity within days. Three operational characteristics are directly relevant to 2026: Event-keying: DDoSia operations have repeatedly surged in the 24-72 hours surrounding politically symbolic events. Volunteer-driven scale: DDoSia rewards volunteer participants with cryptocurrency and runs on Windows, Linux, Android and Docker. OT expansion: A co-sealed advisory and subsequent UK NCSC alert specifically warns that pro-Russian hacktivists have moved beyond DDoS into operational technology (OT) targeting via exposed VNC and remote-access services. Information Operations Major global sporting events have proven fertile ground for state-sponsored information operations aimed at sowing distrust in institutions, embarrassing athletes or nations, and amplifying narratives conducive to strategic interests. Russian influence operations are well established with past reported activities surrounding leaked athlete data, AI-enabled deception and defaming, delegitimization of Ukraine and Ukrainian athletes, narratives of the West against Russia, and pro-Kremlin narratives. The current conflict in Iran opens the door for potential Iran-based narrative amplification, consistent with its observed hybrid offensive approach, specifically aimed at compounding the division of support for kinetic activity and targeting countries or athletes from Gulf states perceived as adversarial. People’s Republic of China-aligned Dragonbridge has increasingly experimented with and deployed generative AI tools — such as synthetic audio, AI-generated news hosts, avatars, and images — to scale its political influence operations across social media, though these efforts have ultimately failed to garner significant organic engagement from authentic viewers. Temporary Multi-City Tournament Infrastructure FIFA's published tournament structure presents a unique and historically large attack surface. Sixteen host cities span three host nations, four time zones and multiple regulatory regimes. Each match operates a layered, ring-based tournament network grafted onto a permanent stadium environment, depends on a temporary commercial supplier ecosystem and pulls on host-city public services that FIFA does not own. Table 3 lists these rings and the primary cyber risk to each. Table 3. Network rings and use cases. The 2026 supplier ecosystem will be vast. Each host city contracts independently for stadium operations, security, transit, hospitality, food service, signage, fan-zone production and last-mile network connectivity. The Pyeongchang 2018 Olympic Destroyer destructive case is a clear historical warning: Recorded Future identified that Olympic Destroyer samples targeting the IT service provider were timestamped five minutes ahead of samples targeting the host. Impact on Municipal, State and Federal Infrastructure CISA AA26-097A identifies “Government Services and Facilities (to include local municipalities)” as one of three named target sectors of the active Iran-nexus PLC campaign. Analysis of CyberAv3ngers' targeting found that small municipal authorities are deliberately selected because they manage OT with consumer remote-access tools or expose PLC interfaces directly to the internet. A January 2024 Russian cyberattack on a municipality in Texas resulted in successfully overflowing a water tank after unsuccessful attempts in neighboring water systems. Ransomware attacks on water systems have also occurred. Pro-Russian hacktivist DDoS has already demonstrated the ability to take state and local government websites offline for hours. UK NCSC's January 2026 alert specifically called out persistent NoName057(16) targeting of UK local-government services. The U.S., Canadian and Mexican equivalents are inside the same threat envelope. Federal Layer Federal agencies have signaled awareness: CISA AA26-097A, the DOJ domain-seizure activity against Iranian cyber fronts and the U.S. State Department's $10 million reward offers indicate active coordination. Defenders should expect and request pre-tournament threat-sharing engagements with CISA, FBI, the Canadian Centre for Cyber Security and Mexico's CERT-MX, mirroring the model that ANSSI ran in advance of Paris 2024. Cascading-Risk Scenarios Two specific scenarios merit pre-tournament tabletop exercise. OT Disruption at Host-City Utility During Match Scenario: An Iran-nexus actor manipulates a wastewater PLC in a host city overnight before a knockout match, producing a service alert and a forced public-health advisory. Mitigation Pre-tournament audit of all internet-exposed PLCs per CISA AA26-097A Mandated migration off TeamViewer/AnyDesk for OT Default-credential audits 24/7 OT incident-response retainer Hospitality Ransomware in Final Week Scenario: A Muddled Libra-style social-engineering campaign against a major host-city hotel operator collapses room access, mobile check-in and PoS for 48-72 hours during the run-up to the July 19, 2026, final at MetLife Stadium. Mitigation Pre-tournament tabletop exercises with major hotel groups Explicit verification protocols on IT help desks Segregation of IdP trust from ESXi management Offline runbooks for the property-management system Prioritized Threat Matrix The following matrix in Table 4 consolidates the assessed likelihood and severity of each evidence-backed threat vector for the tournament window of June 11-July 19, 2026. Severity is conditioned on the potential impact to fans, host cities and the integrity of the competition. Table 4. Prioritized threat matrix of likely cyberattacks. Recommendations These recommendations are derived from the threat picture above and from public after-action reporting on Paris 2024 and Milan-Cortina 2026. They are prioritized by impact rather than by category. For the tournament organization and host-city committees Stand up a single, multi-jurisdictional cyber operations center with U.S. CISA, the Canadian Centre for Cyber Security, Mexico's CERT-MX, the FBI, the RCMP and Mexican federal cyber liaison co-located or fully integrated, replicating the ANSSI/Paris 2024 model. Inventory the full vendor and supplier graph for each host city and conduct credential-rotation, default-password and remote-access audits across that graph. Prioritize IT service providers and venue operations, which Recorded Future identified as Pyeongchang's primary breach vector. Mandate that no tournament network, at any ring, permits consumer remote-access tools on production infrastructure for the duration of the tournament window. Pre-position DDoS scrubbing capacity, content-delivery-network failover and rate-limiting on all fan-facing domains. NoName057(16) DDoS volumes during Paris 2024 peaked at 190,000 requests/second; defenders should plan for an order of magnitude above that. Run a destructive-malware tabletop. Validate that backups are isolated, immutable and recoverable inside a four-hour window. For host-city utilities and municipal operators Audit every internet-exposed PLC, HMI and SCADA component in water, wastewater, energy and transit operations. Apply CISA AA26-097A and AA23-335A guidance specifically: Change all default credentials, place PLCs behind segmented firewalls and eliminate direct internet exposure on ports 44818, 2222, 102, 22 and 502. Engage the FBI, CISA and EPA for sector-specific assessments before kickoff. Where budget is constrained, a single round of vulnerability scans focused on the AA26-097A indicator set is high value. Establish 24/7 OT incident response coverage through the entire tournament window. For hospitality and venue operators in host metros Treat the IT help desk as the first line of defense and the most likely point of compromise. Implement out-of-band caller-verification protocols; ban credential resets initiated by phone alone; assume that publicly identifiable employees are reconnaissance targets. Segregate identity-provider trust from VMware ESXi management. Previous compromises pivoted from Okta to ESXi to ransomware; that pivot path must be broken architecturally before the tournament, not during it. Maintain offline runbooks for property-management, PoS, digital-key and reservation systems. Confirm pen-and-paper fallback works under load. For sponsors, federations and broadcast partners Assume executive personal accounts are in scope for state-aligned hack-and-leak operations. Apply phishing-resistant MFA (FIDO2/WebAuthn) to all corporate, executive and high-visibility employee accounts before kickoff. SMS and TOTP MFA are insufficient against the demonstrated tradecraft of Scattered Spider and Handala. Pre-build communications response templates for hack-and-leak scenarios; do not draft them under live attack. For fans and the traveling public Buy tickets only on the official FIFA platform or a FIFA-authorised resale partner. Do not buy through Telegram, WhatsApp, social media DMs or peer-to-peer payment apps. Use a credit card with chargeback protection. Verify accommodation listings with major platforms; treat off-platform wire transfers and cryptocurrency requests as fraud. Cross-reference street view and listing photos. Treat any QR code presented in transit, parking or fan-zone contexts with skepticism. Cross-check with the host city's official transportation app or website before scanning. On public Wi-Fi, use a reputable VPN for any account-level activity; better still, use cellular data. Disable Wi-Fi auto-join; remove networks after use. Patch mobile devices. Avoid sideloading apps. Verify every FIFA app against the FIFA-published list of official applications. Final Thoughts The window for shifting from preparation to live response is closing fast. The 2026 FIFA World Cup conditions are different than at any previous tournament: three host nations, sixteen host cities, a 48-team field, an active U.S.-Israel-Iran kinetic conflict, an ongoing Russia-NATO confrontation and a cybercriminal ecosystem that has industrialized against the hospitality sector since 2023. The threat actors of greatest concern for 2026 — the Handala Hack Team, CyberAv3ngers, NoName057(16), Muddled Libra, ALPHV affiliates and the broader Iran- and Russia-aligned hacktivist ecosystem — have all demonstrated their capabilities within the last 24 months. This has been proven in public record by what these actors have already accomplished. Plan for incidents across the full supplier and host-city graph, exercise the response against realistic scenarios and coordinate across jurisdictions before kickoff rather than during the tournament. Where that posture has been adopted, the historical record shows that competition has not been disrupted. Where it has been weaker, adversaries have succeeded. The single most important defender posture for 2026 is to assume the attacks will come. Additional Resources Analysis of domains taking advantage of FIFA World Cup – Timely Threat Intelligence, Unit 42 on GitHub Understanding the Russian Cyberthreat to the 2026 Winter Olympics – Unit 42, Palo Alto Networks 2026 Unit 42 Global Incident Response Report – Unit 42, Palo Alto Networks
unit42.paloaltonetworks.comMay 28, 2026extracted
UK water company allowed hackers to lurk undetected for nearly two years, regulator finds
UK water company allowed hackers to lurk undetected for nearly two years, regulator finds A British utilities company supplying drinking water to 1.6 million people failed to discover hackers hidden inside its computer network for nearly two years before the intrusion came to light through an IT performance slowdown, the UK's data protection regulator has found. The Information Commissioner's Office (ICO) fined South Staffordshire Water £963,900 ($1.3 million) on Monday over an attack by the Cl0p ransomware group that led to the personal data of 633,887 customers and employees being published in August 2022. According to the penalty notice, the initial access occurred almost two years earlier in September 2020 when an employee opened a malicious email attachment, installing software that gave the attacker a foothold on the corporate network. The threat actor then remained hidden until May 2022 before beginning to move laterally across systems using a domain administrator account, the highest level of system access available. The company did not identify the intrusion until July 2022, when the IT performance issues prompted an internal investigation. Two weeks later the company discovered a ransom note the attacker had unsuccessfully attempted to distribute to certain members of staff. After the incident, South Staffordshire detected approximately 4.1 terabytes of data published on the dark web, including names, addresses, dates of birth, bank account numbers and sort codes, National Insurance numbers, and, for a small percentage of customers on the company's Priority Services Register, information from which disabilities could be inferred. The ICO's investigation identified four specific security failures, including implementing the principle of least privilege — a standard control that limits user access to only what is needed for their role — allowing the threat actor to move freely across the network using a domain administrator account. As of December 2021, more than a year after the attacker first gained access, an outsourced security operations center was monitoring just 5% of the company's IT environment. The third party was not identified in the ICO’s report, which said endpoint telemetry and logging were not integrated into the company's security monitoring platform. Some devices were also still running Windows Server 2003, an operating system whose extended support ended in July 2015. When asked by the ICO to provide records of any internal or external vulnerability scans conducted between September 2020 and May 2022, the company confirmed no such scans existed for either category. Two domain controllers also remained unpatched against a critical vulnerability known as ZeroLogon which allows rapid escalation of privileges and was first published in August 2020. The attacker successfully exploited this vulnerability during the incident. “Waiting for performance issues or a ransom note to discover a breach is not acceptable,” said Ian Hulme, the ICO's Interim Executive Director for Regulatory Supervision, adding that “proactive security is a legal requirement, not an optional extra.” Incidents and reactions The breach became public in August 2022 when, in a bungled extortion attempt, the Cl0p group claimed to have stolen data from a different water supplier, Thames Water that serves around 15 million people in and around London. At the time, the group claimed to have been capable of altering the chemical composition of the water supply, although this was disputed by South Staffordshire. The penalty notice makes no reference to any compromise of operational or water treatment systems. The ICO placed the infringements in the medium seriousness category and reduced the total fine due to South Staffordshire’s cooperation, early admission of liability and mitigation steps. A further discretionary reduction was applied, though the reasoning is redacted in the published notice. South Staffordshire entered a voluntary settlement earlier this year, securing a 40% discount, and has agreed not to appeal against the ICO’s decision. The fine comes as British water suppliers face a growing number of cyberattacks. Five incidents were reported to the Drinking Water Inspectorate between January 2024 and October 2025 — a record number in any two-year period, as reported by Recorded Future News, which obtained the figures under freedom of information laws in November 2025. Those reports were made voluntarily. Under the current NIS Regulations, water suppliers are only required to notify authorities of cyber incidents that cause actual disruption to supplies. South Staffordshire's breach, which became public in 2022, did not meet that threshold. The U.K. government’s Cyber Security and Resilience Bill, intended to expand mandatory reporting requirements and improve security standards for critical infrastructure operators, is expected to be introduced to Parliament this year. Although there have been ransomware attacks against the IT office systems used by water companies — including the companies who made the above reports in the U.K., and Aigües de Mataró in Spain — it is extremely rare for cyberattacks on water suppliers to actually disrupt services. In one rare case of a successful attack on an operational technology (OT) component, residents of a remote area on Ireland’s west coast were left without water for several days in December 2023 when a pro-Iran hacking group indiscriminately targeted facilities using a piece of equipment the hackers complained was made in Israel. The U.S. federal government had issued a warning about the exploitation of Unitronics programmable logic controllers (PLCs) used by many organizations in the water sector. Attacks on PLCs, core technology components in a lot of industrial control systems, are one of the main concerns of critical infrastructure defenders. Initiatives to improve the security of water systems in the United States faltered under the Biden administration when water industry groups partnered with Republican lawmakers to put a halt to the federal efforts, despite significant increases in the number of ransomware attacks and state-sponsored intrusions. Last year, Canadian authorities warned of an incident in which hacktivists changed the water pressure at one local utility among a spate of attacks interfering with industrial control systems. South Staffordshire’s chief executive, Charley Maher, said: “We accept the Information Commissioner’s Office’s decision relating to the cyber attack our Group experienced in 2022, and are sorry for the worry and concern it caused for customers and employees. We took immediate action to contain the incident, support those impacted and reduce the risk of recurrence. “We have invested significantly to further strengthen our cyber security resilience, governance and monitoring, and we continue to enhance our capabilities as the threat landscape evolves. Protecting customer and employee information is a responsibility we take extremely seriously, and we remain focused on learning from this incident and maintaining strong safeguards across the Group.” Alexander Martin is the UK Editor for Recorded Future News. He was previously a technology reporter for Sky News and a fellow at the European Cyber Conflict Research Initiative, now Virtual Routes. He can be reached securely using Signal on: AlexanderMartin.79
therecord.mediaMay 11, 2026extracted
Nearly 4,000 US industrial devices exposed to Iranian cyberattacks
The attack surface targeted by Iranian-linked hackers in cyberattacks against U.S. critical infrastructure networks includes thousands of Internet-exposed programmable logic controllers (PLCs) manufactured by Rockwell Automation. According to a joint advisory issued by multiple U.S. federal agencies on Tuesday, Iranian state-backed hacking groups have been targeting Rockwell Automation/Allen-Bradley PLC devices since March 2026, causing operational disruptions and financial losses. "Iranian-affiliated APT targeting campaigns against U.S. organizations have recently escalated, likely in response to hostilities between Iran, and the United States and Israel," the authoring agencies warned. "The FBI identified that this activity resulted in the extraction of the device's project file and data manipulation on HMI and SCADA displays." As cybersecurity firm Censys reported one day later, three-quarters of more than 5,200 such industrial control systems found exposed online globally are from the United States. "Censys data identifies 5,219 internet-exposed hosts globally responding to EtherNet/IP (EIP) and self-identifying as Rockwell Automation/Allen-Bradley devices," Censys said. "The United States accounts for 74.6% of global exposure (3,891 hosts), with a disproportionate share on cellular carrier ASNs indicative of field-deployed devices on cellular modems." To defend against these ongoing attacks, network defenders are advised to secure PLCs using a firewall or disconnect them from the Internet, scan logs for signs of malicious activity, and check for suspicious traffic on OT ports (especially when it originates from overseas hosting providers). Admins should also enforce multifactor authentication (MFA) for access to OT networks, keep all PLC devices up to date, and disable unused services and authentication methods. This ongoing campaign follows similar attacks from nearly three years ago, when a threat group affiliated with the Iranian Government's Islamic Revolutionary Guard Corps (IRGC) and tracked as CyberAv3ngers targeted vulnerabilities in U.S.-based Unitronics operational technology (OT) systems. CyberAv3ngers hackers compromised at least 75 Unitronics PLC devices in multiple waves of cyberattacks between November 2023 and January 2024, with half of those in Water and Wastewater Systems critical infrastructure networks across the United States. More recently, the Handala hacktivist group (linked to Iran's Ministry of Intelligence and Security) wiped approximately 80,000 devices from the network of U.S. medical giant Stryker, including employees' mobile devices and company-managed personal computers. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comApr 10, 2026extracted
Industry Reactions to Iran Hacking ICS in Critical Infrastructure: Feedback Friday
The US government warned this week that Iran-linked hackers have targeted critical infrastructure organizations, hacking industrial control systems (ICS) and other operational technology (OT). According to an advisory written by CISA, the FBI, and several other agencies, hackers have targeted programmable logic controllers (PLCs) made by Rockwell Automation, but devices from other vendors are also at risk. Both Rockwell and Siemens have published advisories to alert customers. The attacks caused operational disruption and financial loss through tampering with vulnerable human-machine interfaces (HMIs) and supervisory control and data acquisition (SCADA) systems. The threat actors targeted internet-exposed PLCs and abused legitimate programming software such as Rockwell’s Studio 5000 Logix Designer to achieve their goals. Targeted industries include government services and facilities, water, and energy. Industry professionals have shared thoughts on the advisory and provided recommendations for defenders. Markus Mueller, Field CISO, Nozomi Networks: “The advisory is not surprising. We have observed nation-state-aligned threat groups targeting publicly exposed operational technology (OT) devices in recent years whenever there’s increased geopolitical activity. The most high-profile of these campaigns was the 2023-24 operations carried out by CyberAv3ngers targeting Unitronics devices. In the current conflict, we have again observed a significant increase in such activity, such as what CISA recently reported. Industry groups, information sharing organizations, and vendors, including Rockwell, have been urging organizations to disconnect these devices from publicly accessible networks (Rockwell Advisory ID: SD1771, March 20th). Many of these devices are still online (in the case of Rockwell, more than 3K in North America), either because organizations are unaware they’re connected or because they underestimate the risk. The public exposure of these OT devices creates a vast attack surface that a motivated and capable adversary can exploit, which is especially relevant given the current conflict. Since the conflict began, threat groups have made hundreds of unverified claims that they have compromised OT devices worldwide, including in North America. However, no public disclosures from affected organizations have come out. It’s common for such groups to post screenshots of control systems, claiming compromise even when they have not actually gained access. The fact that we are not seeing more publicly disclosed incidents may be a function of the scope of threat activity, which is mostly focused on the region supporting each side’s kinetic activity, the type of activity, which is mostly DDoS and data leaks, or it could be because organizations don’t want to disclose breaches of this type. It could also be that these groups are in the discovery and initial access phases of their campaigns, as some of the observed activity indicates. As the conflict continues, we will likely see an increased tempo of events, including those targeting OT devices. This will likely continue even if there is a resolution to hostilities, as in past conflicts, when kinetic attacks stop, we see a focus on hybrid warfare, including cyber.” Denis Calderone, CTO, Suzu Labs: “[…] Today, we’re seeing the threat actors conducting fairly surgical operations, using Studio 5000 Logix Designer, which is Rockwell Automation’s own PLC programming software, to interact with CompactLogix and Micro850 controllers at the file object level. They’re extracting the programming logic that controls physical processes and manipulating data on HMI and SCADA displays. Think about what that means for a water treatment operator or a power plant engineer. If your display is showing you normal pressure, flow, or chemical dosing levels and the actual values are different, you’re making operational decisions based on false data. That’s how equipment damage and safety incidents happen. Now, the advisory specifically calls out Rockwell Automation and Allen-Bradley, and that makes sense because Rockwell holds roughly 35 to 40 percent of the US PLC market. But don’t let the Rockwell focus distract you. The indicators of compromise in the advisory include traffic on port 102, which is S7comm, and that’s a Siemens protocol. The advisory itself says ‘potentially other branded PLCs’ are at risk. If you’re running Siemens, Schneider, or any other PLC platform and assuming this doesn’t apply to you, look at the port list again: 44818 for EtherNet/IP (Rockwell and others), 102 for S7comm (Siemens), 502 for Modbus (most PLCs). Those protocols are from multiple manufacturers, proving that this is more than just a Rockwell problem. The prescriptive advice here is straightforward. PLCs should never be directly accessible from the internet, period. The advisory confirms that the attackers are simply connecting to internet-exposed devices using overseas IP addresses. But internet isolation alone isn’t enough. Controllers and SCADA infrastructure should sit behind properly segmented OT network zones with monitored firewall boundaries between IT and OT environments.” Duncan Greatwood, CEO, Xage Security: “The active exploitation of our water and energy systems represents a sobering milestone in the weaponization of domestic infrastructure. This targeted campaign focuses on the core logic of our industrial processes, where the manipulation of control systems and human-machine interfaces can lead to direct operational failure. While emergency alerts provide critical guidance, the practice of disconnecting assets from the internet remains a temporary reaction to a systemic vulnerability. And even when infrastructure is disconnected, a technician’s malware-infected laptop can “walk” an attack inside the network boundary, as has happened hundreds of times in the past with the U.S. electrical grid. For our critical utilities, priority should be placed on establishing a resilient foundation that secures every interaction, rather than simply reacting to the threat of the day. CISA’s follow-up guidance to implement MFA is a positive step. However, its recommendation to enable remote access through a network proxy, gateway, firewall, and/or VPN in front of PLCs is problematic. VPNs are widely recognized as insecure forms of remote access, a point CISA itself has previously acknowledged. The recommendation to keep PLC devices updated with the latest manufacturer patches can also be misaligned with OT realities, where systems often cannot be patched frequently without risking operational disruption. Rather than relying solely on patching, operators need to strictly control access to the PLC, so the PLC can be protected when attacks are live on the network, even though the PLC itself may be insecure. To provide a durable foundation for resilience, organizations should adopt zero trust architectures, such as just-in-time access rights and microsegmentation to more effectively defend against advanced attacks and strengthen security posture.” Damon Small, Board of Directors, Xcape: “The targeted disruption of US water and energy utilities is the inevitable outcome of treating critical national infrastructure like a public Wi-Fi hotspot. By leveraging legitimate engineering tools like Rockwell’s Studio 5000 to manipulate project files, Iranian-linked actors have demonstrated that an Internet-exposed programmable logic controller (PLC) is not a poor technical design – it is a pre-staged kinetic weapon. Security leaders must acknowledge that these “nuisance” disruptions are live-fire exercises for more catastrophic escalations that exist entirely outside the bounds of diplomatic ceasefires. The primary business risk has shifted from simple uptime to the physical safety of the communities these utilities serve. Teams must immediately pull every PLC off the public Internet and isolate them behind a Zero Trust gateway or authenticated VPN. For Rockwell CompactLogix and Micro850 series devices, operators should physically set the controller mode switch to the RUN position to block remote logic changes. Organizations must audit for exposed industrial ports such as 44818 and 2222 and rotate all default credentials across the OT environment. Failing to remove these systems from public view is an open invitation for geopolitical adversaries to use your operational uptime as a diplomatic bargaining chip. In short, the cease-fire will not stop our adversaries from attacking the United States’ critical infrastructure, and this will lead to the unavailability of these services, or worse, to incidents that lead to loss of life and limb. If your water treatment plant or refinery is searchable on the Internet, you are not running a utility; you are hosting a digital sandbox for the IRGC.” Lieutenant General Ross Coffman (US Army, Ret.), President, Forward Edge-AI: “Iran using cyberattacks to probe and impact American utilities should come as no surprise. Iran is using its long-range targeting tools to fight in every domain possible. We must continue to harden our cyber defenses and remind employees that they are the first line of defense. Our government’s cyber professionals are the best in the world, so Iran is probing daily to find an exposed flank.” David Sequino, Co-Founder & CEO, OmniTrust: “Iranian-affiliated actors aren’t just probing for data within our critical infrastructure; they are threatening the physical systems at the foundation of our daily lives. Without reliable sources of drinking water, many in our country wouldn’t survive. For far too long, industrial Controllers have ‘bolted on security’ or Operators of OT networks focused on the outer edge of our OT (operational technologies) networks through porous firewalls leaving the industrial controllers and sensors open to attack. When an adversary can manipulate a project file or a Human-Machine Interface (HMI) to the control panels and dashboards that allow operators to interact with physical machinery — they effectively hijack the physical source of truth causing physical consequences. While this advisory focuses on specific PLC hardware, the methodology exposes a broader industry-wide need to move beyond the ‘Bolt on’ and ‘patch-and-pray’ model and adopt Trust Lifecycle Management (TLM) during the outset of any design cycle for any element in our critical infrastructure. True resilience requires every device to maintain a verifiable, cryptographic identity from design, development, to the factory floor to decommissioning. In 2026, if any piece of hardware, firmware, software, user or site can’t prove its own integrity it’s a liability. Operators can no longer just lock the door; they must be able to protect the keys across the entire lifecycle of any and all devices that make up our critical infrastructure.” Ross Filipek, CISO, Corsica Technologies: “The developments outlined in the advisory didn’t happen in a vacuum. Years of high profile infrastructure incidents have shown the world two things. First, that many operational technology environments still have internet reachable interfaces and remote access paths that were never meant to be permanent. Second, that even limited disruptions can create outsized chaos, from emergency response strain to financial loss and reputational damage. Each successful or even partially successful campaign lowers the barrier for the next one, and emboldens actors to move from nuisance level defacement into real operational interference. The fallout is not contained by borders. If a municipal utility goes down, suppliers, hospitals, and regional partners feel it. If an energy operator has to throttle operations, downstream manufacturing and logistics take a hit. Globally, allied partners watching these campaigns have to assume the same playbook will be reused similarly abroad, especially where vendors, integrators, and remote maintenance channels overlap. The most important mitigation steps aren’t glamorous, but they’re essential. Agencies need to know exactly which OT assets they control, remove direct internet exposure, and segment OT from business networks so one compromise doesn’t trigger a ripple effect. From there, invest in continuous monitoring that understands both IT and OT signals, and pair it with incident response muscle memory through tested playbooks and tabletop exercises. The organizations that fare best are the ones that treat resilience as an always on capability, not a scramble after an alert.” Steve Povolny, Vice President of AI Strategy & Security Research, Exabeam: “The latest advisory from CISA reinforces what years of researching industrial control systems and IoT exploitation have already made clear to me firsthand. Industrial control environments across the United States remain structurally fragile targets. Programmable logic controllers and supporting HMI stacks are often deployed on aging hardware, run outdated firmware for years at a time, and sit inside operational networks that were never designed with adversarial persistence in mind. In many cases, these systems remain directly reachable from external networks or indirectly exposed through poorly segmented enterprise integrations, despite having no operational requirement to be internet accessible at all. From a strategic perspective, this matters because compromising ICS can directly disrupt critical infrastructure and create real-world consequences beyond traditional cyber incidents. Water treatment plants, electrical distribution systems, pipeline operations, and manufacturing control layers are uniquely asymmetric targets. They allow adversaries to generate disruption, fear, and economic pressure without triggering the kind of response normally associated with physical conflict. That reality makes PLC-focused campaigns especially concerning right now, and this advisory is describing an operational playbook already being exercised against live infrastructure. Organizations operating SCADA, ICS, and broader OT environments should assume increased reconnaissance, credential harvesting, and opportunistic exploitation attempts during this period of heightened tension. Visibility gaps between IT and OT telemetry remain one of the most persistent weaknesses I see across critical infrastructure operators. Teams should prioritize passive network monitoring for control protocols, enforce strict segmentation between enterprise and control zones, validate remote access pathways, and confirm that engineering workstations and vendor maintenance channels are tightly controlled and logged. Just as important, incident response plans must explicitly account for loss of control system integrity, not just loss of data confidentiality. However, I fear it may be too late for much of this to have short-term impact.” Süleyman Özarslan, Co-Founder, Picus Security: “The most notable aspect of this campaign is the attackers’ skill. They use the same engineering software and trusted connections that OT teams use daily, making it difficult to spot malicious activity. For defenders, the main problem is exposure. If PLCs can be accessed from the internet, attackers have a straightforward way into operational systems. An even greater concern is that this shows a weakness in how systems are designed. If segmentation, access controls, and hardening are not strong enough, attackers can blend in with normal OT workflows, stay in the system, and disrupt industrial operations in ways that are harder to spot.”
securityweek.comApr 10, 2026extracted
Iran‑Backed Threat Actors Hit US CNI Providers via Internet‑Facing OT Assets
Iranian-affiliated hackers have been attacking US critical national infrastructure (CNI) providers since last month, causing operational disruption and financial loss, the US government has revealed. A Cybersecurity and Infrastructure Security Agency (CISA) advisory on April 7 said the threat actors were targeting internet-facing operational technology (OT) assets including programmable logic controllers (PLCs) manufactured by Rockwell Automation/Allen-Bradley. So far, the sectors targeted have been government services and facilities (including local municipalities), water and wastewater systems (WWS), and energy. “Due to the widespread use of these PLCs and the potential for additional targeting of other branded OT devices across critical infrastructure, the authoring agencies recommend US organizations urgently review the tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs) in this advisory for indications of current or historical activity on their networks, and apply the recommendations listed in the mitigations section to reduce the risk of compromise,” the advisory noted. The advanced persistent threat (APT) group has been observed “maliciously interacting with project files, and manipulating data displayed on HMI and SCADA displays,” according to CISA. The PLCs apparently manage a wide variety of industrial processes. They are using “configuration software” such as Rockwell Automation’s Studio 5000 Logix Designer to create an “accepted connection” to targeted PLCs, via overseas IP addresses and third-party hosted infrastructure. Inbound malicious traffic may come on ports 44818, 2222, 102, 22, or 502, with port 22 attacks involving the deployment of Dropbear Secure Shell (SSH) software on victim endpoints for remote access. Actions For CNI Firms to Take The advisory urged US CNI providers to: Use secure gateways and firewalls to protect PLCs from direct internet exposure Query available logs for the IOCs provided in the advisory Check available logs for suspicious traffic on the ports associated with OT devices, especially if they originate overseas Place the physical mode switch on the controller of Rockwell Automation devices into the run position. And contact the FBI, CISA, NSA or other authoring agencies for guidance if the organization has already been targeted The campaign follows a Handala attack on US medtech firm Stryker in March which wiped tens of thousands of devices. It also follows a similar campaign in 2023 when Iran’s Islamic Revolutionary Guard Corps (IRGC) struck US water plants running PLCs manufactured by Israeli firm Unitronics. Experts Weigh In Ross Filipek, CISO at Corsica Technologies, argued that the new campaign didn’t happen in a vacuum. “Years of high-profile infrastructure incidents have shown the world two things. First, that many operational technology environments still have internet reachable interfaces and remote access paths that were never meant to be permanent,” he continued. “Second, that even limited disruptions can create outsized chaos, from emergency response strain to financial loss and reputational damage. Each successful or even partially successful campaign lowers the barrier for the next one, and emboldens actors to move from nuisance level defacement into real operational interference.” Exabeam VP of AI strategy and security research, Steve Povolny, said CNI firms operating OT should assume increased reconnaissance, credential harvesting and opportunistic attempts to exploit systems during the US campaign in Iran. “Visibility gaps between IT and OT telemetry remain one of the most persistent weaknesses I see across critical infrastructure operators. Teams should prioritize passive network monitoring for control protocols, enforce strict segmentation between enterprise and control zones, validate remote access pathways, and confirm that engineering workstations and vendor maintenance channels are tightly controlled and logged,” he added. “Just as important, incident response plans must explicitly account for loss of control system integrity, not just loss of data confidentiality. However, I fear it may be too late for much of this to have short-term impact.”
infosecurity-magazine.comApr 8, 2026extracted
FBI, Pentagon warn of Iran hacking groups targeting operational technology
FBI, Pentagon warn of Iran hacking groups targeting operational technology Hackers affiliated with the government of Iran are attacking internet-facing operational technology (OT) devices and causing disruptions across multiple U.S. critical infrastructure sectors. The attacks have led to “operational disruption and financial loss,” according to a new advisory from the Defense Department, FBI, National Security Agency (NSA) and other federal agencies. Officials believe the attacks escalated in response to the current military conflict between the U.S. and Iran. Iranian-affiliated threat actors are specifically targeting internet-connected OT devices including Rockwell Automation or Allen-Bradley-manufactured programmable logic controllers (PLC). Other devices from Siemens may also be included in the campaign. “As a result of this activity, organizations from multiple U.S. critical infrastructure sectors experienced disruptions through malicious interactions with the project files and the manipulation of data displayed on human machine interface (HMI) and supervisory control and data acquisition (SCADA) displays,” the agencies said. “Since at least March 2026, the authoring agencies identified (through engagements with victim organizations) an Iranian-affiliated APT-group that disrupted the function of PLCs.” The advisory said Iranian actors are targeting local municipal governments, water and wastewater systems and the energy sector. It comes one week after a water treatment plant in Minot, North Dakota reported a ransomware attack. A Minot city official told Recorded Future News that they called the incident a ransomware attack but said there was no direct ask for money and there was no direct interaction “beyond a letter on a screen.” The FBI confirmed to Recorded Future News that it is involved in the investigations into the attack on Minot and another separate attack on a county government in Indiana. Water companies and other critical infrastructure organizations use PLCs to control and monitor various stages and processes, including turning on and off pumps at a pump station to fill tanks, reservoirs and more. The FBI advisory specifically highlights CVE-2021-22681 — a vulnerability affecting Rockwell operational technology products. The Cybersecurity and Infrastructure Security Agency (CISA) said the bug was being exploited one month ago and ordered all federal agencies to patch it by March 26. Organizations are urged to remove PLCs and other operational technology from direct internet exposure and check logs for any suspicious traffic. The agencies compared the activity to an Iranian campaign in 2023 and 2024 where hackers linked to Iran’s Islamic Revolutionary Guard Corps (IRGC) targeted PLCs made by Israeli company Unitronics. In Tuesday’s advisory, U.S. officials revealed for the first time that Iran’s 2023 campaign involved at least 75 devices that were compromised. While the incidents were largely defacements of utility technology, federal officials warned at the time that the attackers may use their access to the devices as a way to gain deeper network level access that would allow them to cause physical damage to equipment or worse. Since the 2023 campaign, cyber defenders said Iranian actors continued to target U.S. critical infrastructure. Dragos CEO Rob Lee told reporters in February that the same group behind the 2023 attacks continued to focus on energy utilities, oil and gas, railways and the water sector. Lee said the group showed “a consistent ability to get a better and better understanding of control loops and physical processes, not just defacing human interfaces.” The State Department issued $10 million rewards for information on the Iranians behind the 2023 attacks, explicitly naming six security officials allegedly linked to IRGC hacking groups. One of the men named, Hamid Reza Lashgarian, is head of the IRGC’s Cyber-Electronic Command (CEC). The kinetic conflict between the U.S., Israel and Iran has had cybersecurity consequences since it began at the end of February. A prominent medical device firm had 200,000 company devices wiped and other attacks have been reported. Cybersecurity experts said there are also dozens of Iran-linked attacks that have not been publicized. Jonathan Greig is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.
therecord.mediaApr 7, 2026extracted
US warns of Iranian hackers targeting critical infrastructure
Iranian-linked hackers are targeting Internet-exposed Rockwell/Allen-Bradley programmable logic controllers (PLCs) on the networks of U.S. critical infrastructure organizations. The warning came earlier today in the form of a joint advisory authored by the FBI, CISA, NSA, the Environmental Protection Agency (EPA), Department of Energy (DOE), and the United States Cyber Command – Cyber National Mission Force (CNMF). The authoring agencies said that these ongoing attacks have targeted organizations across multiple U.S. critical infrastructure sectors (including Government Services and Facilities, Water and Wastewater Systems, and Energy), and have resulted in financial losses and operational disruptions since March 2026. "The FBI assesses a group of Iranian-affiliated APT actors are targeting internet-exposed PLCs with the intent to cause disruptions—including maliciously interacting with project files, and manipulating data displayed on HMI and SCADA displays—to U.S. critical infrastructure organizations," the advisory warns. "Iranian-affiliated APT targeting campaigns against U.S. organizations have recently escalated, likely in response to hostilities between Iran, and the United States and Israel." "The FBI identified that this activity resulted in the extraction of the device's project file and data manipulation on HMI and SCADA displays," the U.S. agencies added. A similar advisory issued in November 2023 warned that the CyberAv3ngers threat group, affiliated with the Iranian Government Islamic Revolutionary Guard Corps (IRGC), had been exploiting vulnerabilities in U.S.-based Unitronics operational technology (OT) systems. Between November 2023 and January 2024, CyberAv3ngers hackers compromised at least 75 Unitronics PLC devices across multiple waves of cyberattacks, half of which were in WWS critical infrastructure networks. To defend against such attacks, network defenders are advised to disconnect PLCs from the Internet or secure them using a firewall, scan logs for indicators of compromise shared in today's joint advisory, and check for suspicious traffic on OT ports (especially traffic originating from overseas hosting providers). They should also implement multifactor authentication (MFA) for access to the OT network, keep PLCs up to date with the latest available firmware, disable all unused services and authentication methods (such as default authentication keys), and monitor network traffic for suspicious activity. Last month, the Iranian-linked and pro-Palestinian Handala hacktivist group wiped approximately 80,000 devices on the network of U.S. medical giant Stryker, including employees' mobile devices and personal computers managed by the company. The FBI also warned that Iranian hackers linked to the country's Ministry of Intelligence and Security (MOIS) are using Telegram in malware attacks. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comApr 7, 2026extracted
Threat Brief: March 2026 Escalation of Cyber Risk Related to Iran
As of April 17, 2026, Iran has begun restoring limited access to the internet after disconnecting from it for the past 47 days. Iran is limiting domestic access to only websites and applications mirrored on its National Information Network. In late March 2026, Unit 42 discovered a new cluster of threat activity we are tracking as CL-STA-1128 (aka Cyber Av3ngers, Storm-0784). The attacker behind this activity targeted operational technology and industrial control systems (OT/ICS) equipment manufactured by Rockwell Automation. This activity represents a shift from the cluster’s historic focus on internet-connected Unitronics programmable logic controllers (PLCs). Unit 42 assesses with moderate confidence that the attacker behind the CL-STA-1128 activity installed Rockwell Automation's FactoryTalk software on virtual private server (VPS) infrastructure to enable their exploitation efforts. FactoryTalk is a suite of industrial automation tools and manufacturing operations management software. Our assessment is based on a review of the unique port combinations observed across all of the hosts and their correlation to known static mappings for the FactoryTalk software. Since April 1, Cortex Xpanse scanning has observed Rockwell Automation or Allen-Bradley SCADA devices, including FactoryTalk services and various PLCs, on 5,600 IP addresses globally. On April 7, the U.S. Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency (CISA) released an advisory mirroring our findings. In particular, CISA noted that Cyber Av3ngers was also exploiting PLCs manufactured by Allen-Bradley. Since April 8, Xpanse has observed approximately 300,000 services daily in Iranian IP space, up from approximately 20,000 since February 25. Though still an order of magnitude less than peak activity observed in early- and mid-February, the increased activity is consistent with reports of limited restored access in the country. We have added more information about the timing of destructive attacks conducted by Iranian threat actors to the Appendix. Unit 42 conducted an in-depth investigation into conflict-themed phishing lures identifying 7,381 related phishing URLs spanning 1,881 unique hostnames. Recent threat activity demonstrates a widespread wave of financial fraud, credential harvesting and illicit content distribution targeting both enterprise and consumer sectors. Threat actors are heavily relying on the impersonation of highly trusted entities including major telecommunications providers, national airlines, law enforcement and critical energy corporations, to deceive victims. The operations leverage agile evasion tactics, including top-level domain rotation, subdomain chaining and purpose-built infrastructure designed to mimic official corporate portals and government payment workflows. Furthermore, attackers are opportunistically exploiting current geopolitical events with conflict-themed lures to facilitate widespread donation and cryptocurrency scams. Ultimately, this activity highlights a sophisticated, multi-pronged approach to exploiting regional brand trust for financial and data theft. We discuss these details in more detail in the section Current Scope of the Attacks – March 2026. On Feb. 28, 2026, the United States and Israel launched a significant joint offensive code named Operation Epic Fury (U.S.) and Operation Roaring Lion (Israel). In the hours following the initial strikes, Iran began a multi-vector retaliatory campaign, which has evolved into a significant transregional conflict. Unit 42 has observed an escalation in cyberattacks from activists outside the country. While threat activity from nation-state groups based within the country was likely stalled for hours to days, we assess with high confidence these groups likely shifted to using very-small-aperture terminal (VSAT) services through Starlink and possibly other providers to resume their operational tempo. As of April 17, 2026, Iran began restoring access to the internet to limited segments of its population, ending a 47-day near-complete internet outage. For Iran-aligned threat actors based outside of the region, we continue to assess that hacktivist groups will target organizations perceived as adversaries but their impact is likely to be of low to medium significance. Other nation-state-aligned threat actors may attempt to exploit the situation to activate cyberattacks to further their own interests. Geographically dispersed operators and affiliated cyber proxies may also target governments in regions hosting U.S. military bases to disrupt logistics. In the near term, these activities are expected to consist of low-to-medium sophistication disruptions (for example, distributed denial of service and hack and leak campaigns). For details on Unit 42’s previous observations of cyber activity linked to Iran-backed groups and hacktivists, see the Threat Brief: Escalation of Cyber Risk Related to Iran (Updated June 30). That report details Iran-backed groups and hacktivists expanding their global cyber operations using website defacement, distributed-denial-of-service (DDoS) attacks, and data exfiltration and wiper attacks. The primary objectives of Iran-aligned nation-state actors frequently include espionage and disruption. Techniques include using AI-enhanced targeted spear-phishing campaigns, the exploitation of known vulnerabilities, and the use of covert infrastructure for espionage. Palo Alto Networks customers can receive protections from and mitigations for relevant threat actor activity through the following products and services: Next-Generation Firewalls with Advanced Threat Prevention Advanced URL Filtering and Advanced DNS Security identify known URLs and domains associated with this activity as malicious Cortex XDR, XSIAM and Cortex Cloud Cortex Xpanse Device Security The Unit 42 Incident Response team can also be engaged to help with a compromise or to provide a proactive assessment to lower your risk. Attackers have registered new conflict-themed domains, numbering in the thousands. They are being used for malicious purposes, including creating fake storefronts, running donation scams and hosting phishing portals. Screenshots of these domains are shown in Figures 1 and 2. Palo Alto Networks has identified two separate malicious campaigns targeting people in the United Arab Emirates (UAE). One campaign involves financial fraud exploiting brands with “Emirates” in the name. The second consists of crypto and investment scams using domains branded with the word “Dubai,” which leverage lures related to high-value real estate and luxury lifestyles. Figures 3 and 4 below show examples of scam domains for asset management and banking. We’ve observed two campaigns targeting a regional telecommunication brand corporate portal with impersonation, using a fake dialing-code prefix to replicate the company’s enterprise portal. We also identified a billing fraud campaign masquerading as the same company. These attackers registered the same domain concept across multiple top-level domains, rotating as each is blocked. We are tracking a wave of targeted attacks against leading organizations in Saudi Arabia. The attackers are deploying a dual-pronged strategy: Highly tailored enterprise credential phishing that mimics major enterprise resource planning (ERP) brands to trick employees Widespread financial fraud These broader schemes are designed to trap both employees and consumers using the following: Malicious utility billing portals Corporate-branded investment scams Misspelled banking sites leveraging Outlook subdomain chaining to deceive victims (Figure 5 shows an example of this type of scheme) Attackers are luring users to fraudulent payment pages that mimic legitimate package delivery services to steal credit card credentials. These malicious sites are characterized by using newly registered domains and generic hosting domains, frequently incorporating Emirates Post within the subdomain. A key technical detail is attackers using the cdn-cgi/phish-bypass path on certain domains, such as traz[.]top. This path indicates a specific tactic designed to exploit and circumvent security challenges. Figure 6 below shows an example. In another financially motivated campaign, attackers impersonated legitimate government entities for credit card theft. Specifically, we discovered the path payment-system/card-process?amount=125 on a domain designed to mimic a fine payment flow, as shown in Figure 7. Attackers are impersonating Iranian banks to manipulate victims into supplying banking credentials. We identified three domains impersonating Iranian banking brands. One domain uses an unconventional gambling top-level domain (TLD), suggesting difficulty in registering a traditional country code TLD (ccTLD). Another domain directly exposes a payment form via the /payment-form/ path. We identified a campaign misusing the name of Iran's largest mobile operator as the registrable domain, then embedding a convincing Microsoft URL chain in the subdomain labels to impersonate a Microsoft account recovery page. Two identified domains use a technique that embeds globally recognized and trusted brands as subdomains within a Middle East-branded malicious registrable domain. This exploits a user's left-to-right reading pattern, presenting the legitimate brand name first. This method is effective as it doesn't require typosquatting, because the real brand name is used exactly. Our analysis of reported StealC infrastructure revealed additional infrastructure and suggests that the attackers are using a numbered-increment pattern across identical top-level domains. This is likely an evasion tactic, where attackers register a new, incremented domain whenever the previous one is blocked. The attack flow involves a malicious JavaScript that redirects victims to a file-hosting page, which then delivers the StealC payload within a password-protected ZIP archive. Additional examples of these file-hosting pages are shown below in Figures 8 and 9. Unit 42 encourages organizations to remain vigilant for emerging threats related to this conflict. With the confirmed use of wipers, we strongly encourage organizations to test and validate their data backup and recovery procedures, as well as to harden their identity and privilege account management systems. Unit 42 has identified an active phishing campaign using a malicious replica of the Israeli Home Front Command RedAlert application. This campaign weaponizes a legitimate-looking Android package (APK) to deliver mobile surveillance and data-exfiltrating malware (Figure 10). We have also observed a surge in hacktivist activity, with some estimates of 60 individual groups active, including pro-Russian groups as of March 2, 2026. Multiple Iranian state-aligned personas and collectives have claimed responsibility for a range of disruptive operations, several of which are associated with the recently established “Electronic Operations Room” formed on Feb. 28, 2026. Key observed entities include: Handala Hack, a hacktivist persona linked to Iran's Ministry of Intelligence and Security (MOIS), is the most prominent Iranian persona. The persona blends data exfiltration with cyber operations against the Israeli political and defense establishment. APT Iran, a pro-Iranian hacktivist collective that has gained notoriety for its hack-and-leak operations The Cyber Islamic Resistance, a pro-Iranian umbrella collective that coordinates multiple hacktivist teams — including groups like RipperSec and Cyb3rDrag0nzz — to launch synchronized DDoS attacks, data-wiping operations and website defacements against Israeli and Western infrastructure Dark Storm Team (also known as DarkStorm or MRHELL112) is a pro-Palestinian and pro-Iranian collective that specializes in large-scale DDoS and ransomware - Claimed to have targeted several Israeli websites, including an Israeli bank in DDoS attacks The FAD Team (often referred to in reports as the Fatimiyoun Cyber Team or Fatimion) is composed of pro-regime actors who focus on wiper malware and permanent data destruction - Claimed responsibility via their public Telegram board for gaining unauthorized access to multiple SCADA/PLC systems in Israel and other countries - Claimed responsibility via their public Telegram board for gaining unauthorized access to control systems associated with more than 24 private devices belonging to an Israeli security services company - Conducted an attack against a Turkish media outlet Evil Markhors is a pro-Iranian group typically specializing in credential harvesting and identifying unpatched critical systems - Claimed responsibility via their public Telegram board for targeting an Israeli bank website Sylhet Gang (often cited as Sylhet Gang-SG) acts as a message amplifier and recruitment engine for the pro-Iranian hacktivist front and participates in DDoS attacks - Claimed responsibility via their public Telegram board for targeting the Saudi Ministry of Home Affair's HCM and Internal Management Systems 313 Team (Islamic Cyber Resistance in Iraq), is an active pro-Iranian hacktivist cell DieNet is a pro-Iran hacktivist group conducting DDoS attacks on various organizations across the Middle East - Claimed responsibility for attacking an airport in Bahrain - Claimed responsibility for attacking Sharjeh Airport in Saudi Arabia - Claimed responsibility for targeting Riyadh Bank website - Claimed responsibility via their public Telegram board for targeting the Bank of Jordan - Claimed responsibility via their public Telegram board for targeting an airport in the United Arab Emirates The group Handala Hack also reportedly targeted an Iranian-American and Iranian-Canadian influencer with direct death threats via email (shown in Figure 11), claiming to have leaked their home addresses to physical operatives in their respective home locations. This type of action represents an escalation of threatening cyber activity directed toward perceived critics of Iran. Cybercriminals are reportedly capitalizing on the conflict by targeting individuals in the United Arab Emirates via a social engineering vishing scam to steal credentials. The threat actors call potential victims impersonating the Ministry of Interior, claiming to be confirming receipt of a national alert and prompting for the victim’s Emirates Identification Number (EID) for verification. The ransomware-as-a-service (RaaS) group Tarnished Scorpius (aka INC Ransomware) has listed on its leak site an Israeli industrial machinery company, and replaced the company logo with a swastika. Cardinal, a pro-Russian hacktivist group, claimed to target Israel Defense Forces (IDF) systems via their public Telegram board. The group is assessed to be state-aligned but likely operates independently of direct state funding. The group claims to have infiltrated IDF networks referencing a purportedly confidential document related to “Magen Tsafoni” (Northern Shield). The posted document includes operational movement details, command approvals and contact information. The pro-Russian hacktivist group NoName057(16) has claimed multiple Israeli targets including disruptive operations against a range of Israeli municipal, political, telecom and defense-related entities. The pro-Russian hacktivist collective “Russian Legion,” claimed to have access to Israel’s Iron Dome missile defense system. In their post, they claimed to be controlling radars, intercepting targets and monitoring in real-time, with reported system paralysis and loss of interception control. The group also claimed a new cyber operation it says compromised closed IDF servers. Unit 42 tracks various Iranian state-sponsored actors under the constellation name Serpens. These groups could increase or escalate activity in the coming weeks. State-sponsored Iranian cyber capabilities are often used to project and amplify political messaging (often using destructive and psychological tactics). These efforts are likely to focus on regional targets (e.g., Israel) as well as what they deem high-value targets (e.g., politicians, key decision-makers and other directly involved entities). State-sponsored campaigns might target their victim’s supply-chains, critical infrastructure, vendors or providers. Given the rapidly changing nature of this situation, a multi-layered defense is most effective as no single tool can provide complete protection. We recommend focusing on foundational security hygiene, a proven approach that provides resilient protection against a wide range of tactics. We recommend taking the following precautions to help mitigate the impact from possible attacks. These recommendations are consistent with previous guidance provided. Ensure at least one copy of critical data is stored offline (air-gapped) to mitigate against encryption or deleting backups stored on the network Implement strict “out-of-band” verification for incoming requests via media, verifying through a separate trusted corporate channel Increase response to any threat signals where possible, especially those associated with internet-facing assets such as websites, virtual private network (VPN) gateways and cloud assets Ensure internet-facing infrastructure is up to date with security patches and other hardening best practices Train employees on phishing and social engineering tactics and continuously monitor for suspicious activity Consider implementing geographic IP address blocking from specific high-risk regions where legitimate business is not conducted Have a robust communications plan ready to address unauthorized access versus system compromise, as hacktivist groups often exaggerate their reach. Scoping and quickly verifying the potential compromise can prevent public panic. Continue to check for updates from trusted cyber agencies such as the UK National Cyber Security Center and the U.S. Cybersecurity and Infrastructure Security Agency (CISA) Iran Threat Overview and Advisories page Begin or update business continuity plans for any staff or assets that digital or physical attacks could disrupt Prepare to validate and respond to claims of breaches or data leaks - Threat actors might use claims (even if they’re untrue) to embarrass or harass victims, or to disseminate political narratives As activity is likely to continue to intensify throughout the duration of these events, it’s important to remain vigilant to potential attacks. Hacktivists and state-supported threat actors have been opportunistic, leading to potentially unexpected sources being targeted. We will update this threat brief as more relevant information becomes available. Palo Alto Networks customers can leverage a variety of product protections and updates to identify and defend against threats related to aspects of these events. If you think you might have been compromised or have an urgent matter, get in touch with the Unit 42 Incident Response team or call: North America: Toll Free: +1 (866) 486-4842 (866.4.UNIT42) UK: +44.20.3743.3660 Europe and Middle East: +31.20.299.3130 Asia: +65.6983.8730 Japan: +81.50.1790.0200 Australia: +61.2.4062.7950 India: 000 800 050 45107 South Korea: +82.080.467.8774 Advanced Threat Prevention has an inbuilt machine learning-based detection that can detect exploits in real time. Advanced URL Filtering and Advanced DNS Security identify known URLs and domains associated with this activity as malicious. Cortex XDR, XSIAM and Cortex Cloud are designed to prevent the execution of known malicious malware. It is also designed to prevent the execution of unknown malware and other malicious activities using Behavioral Threat Protection and machine learning based on the Local Analysis module. Cortex Xpanse has the ability to identify exposed Rockwell Automation or Allen-Bradley devices on the public internet and escalate these findings to defenders. Customers can enable alerting on this risk by ensuring that the relevant Attack Surface Rule is enabled. Identified findings can either be viewed in the Threat Response Center or in the incident view of Expander. These findings are also available for Cortex XSIAM customers who have purchased the ASM module. Device Security can detect and alert when anomalous program download activities or mode changes are observed from a work station to a programmable logic controller (PLC) using the CIP-IP protocol. It can help identify and alert on internet-exposed Rockwell/Allen-Bradley PLCs. Device Security can also help identify instances of FactoryTalk software installed on workstations. Device Security continuously monitors industrial networks to provide visibility to all asset behaviors. The solution can help identify assets using any FactoryTalk App-ID. Additionally, alerts and risks can be used to trigger orchestration via SOAR/SIEM solutions to quarantine or isolation actions via NGFW and integrated network access controls (NACs). Iranian Cyber Threat Evolution: From MBR Wipers to Identity Weaponization – Unit 42, Palo Alto Networks Insights: Increased Risk of Wiper Attacks – Unit 42, Palo Alto Networks Boggy Serpens Threat Assessment – Unit 42, Palo Alto Networks Intelligence-Driven Active Defense Report 2026 Securing Operational Technology Environments – Whitepaper, Palo Alto Networks hxxps[:]www[.]shirideitch[.]com/wp-content/uploads/2022/06/RedAlert[.]apk hxxps[:]//api[.]ra-backup[.]com/analytics/submit.php hxxps[:]//bit[.]ly/4tWJhQh media.megafilehost2[.]sbs cache3.filehost36[.]sbs alpha.filehost36[.]sbs srv2.filehost37[.]sbs arch2.megadatahost3[.]homes media.hyperfilevault2[.]mom hyperfilevault2[.]mom www.hyperfilevault2[.]mom arch2.maxdatahost1[.]cyou hyperfilevault1[.]xyz hyperfilevault3[.]mom hyperfilevault3[.]pics pnd.86c.mytemp[.]website d1g.ccd.mytemp[.]website s0u.210.mytemp[.]website 2pd.f22.mytemp[.]website eg3.db1.mytemp[.]website f43.c76.mytemp[.]website kzw.ce3.mytemp[.]website c45.94b.mytemp[.]website kmd.8cd.mytemp[.]website c1y.bf3.mytemp[.]website m1w.4a0.mytemp[.]website njb.551.mytemp[.]website 2b1.916.mytemp[.]website 92j.130.mytemp[.]website b1z.0f6.mytemp[.]website b0p.c0d.mytemp[.]website nxj.e57.mytemp[.]website pro.iranpanel[.]life www.iran2026[.]org iranpaye[.]com www.forever-iran[.]net irandonation[.]org irancross[.]shop aramcoamericainvest[.]com trumpvsirancoin[.]xyz iran[.]drproxy[.]pro iran2[.]drproxy[.]pro iran11[.]drproxy[.]pro iran14[.]drproxy[.]pro iran15[.]drproxy[.]pro iran16[.]drproxy[.]pro iran18[.]drproxy[.]pro iran19[.]drproxy[.]pro tehran[.]t2.drproxy[.]pro emiratesinvestunion[.]com buydubaipropertywithcrypto[.]com cryptocurrencies-offers[.]com the-dubai-lifestyleapp.cryptocurrencies-offers[.]com emiratescryptobank[.]com secretemirates[.]com emiratespost-pay[.]com ae-payapp[.]com www.emirates-post[.]ae-payapp[.]com traz[.]top emiratespost[.]traz[.]top/cdn-cgi/phish-bypass?atok= emirates-post[.]racunari-bl[.]com/en/card.php myemiratespost[.]click emirates-ae[.]pack-541202699[.]azmtrust[.]com portal[.]sapb-aramco[.]com cnmaestro[.]sapb-aramco[.]com saudi-bill-pay[.]com saudidigtalbank[.]com outlook[.]outlook[.]saudidigtalbank[.]com aramcoamericainvest[.]com dubaicustonms[.]top dubai-custboms[.]top dubai-custbims[.]top dubai-customs[.]top dubaicustoms[.]top dubaicuctoms[.]com dubaiicuctoms[.]com gov-tollbillba[.]life com-govauv[.]top dubaipolice[.]gov-tollbillba[.]life govauv[.]top portal[.]0111etisalat[.]com www[.]portal[.]0111etisalat[.]com superset[.]0111etisalat[.]com www[.]superset[.]0111etisalat[.]com yoshi[.]0111etisalat[.]com _dmarc[.]www[.]portal[.]0111etisalat[.]com etisalatquickpay[.]com etisalataccountquickpayae[.]top etisalataccount-quickpayae[.]click cover[.]www[.]microsoft[.]com[.]irancell[.]courses recovery[.]cover[.]www[.]microsoft.com[.]irancell[.]courses bankofamerica[.]com[.]oidscreen[.]gorequestlocale[.]emiratesbankgroup[.]info appleid[.]apple[.]com-update[.]required[.]kontol[.]emiratesbankgroup[.]info store[.]appleid-apple[.]com-confirmation[.]verif[.]emiratesbankgroup[.]info bankiran[.]bet irandargah[.]com iransupports[.]cyou iransupporttyst[.]cyou iransupasdports[.]cyou iransusdpportsdf[.]cyou firansupport[.]cyou kiransupport[.]cyou trdfiransupport[.]cyou airansupasdports[.]cyou biransupasdports[.]cyou kiransupportsdf[.]cyou fkiransusdpportsdf[.]cyou sffifdsfsransupasdports[.]cyou portal.0111etisalat[.]com superset[.]0111etisalat[.]com yoshi[.]0111etisalat[.]com _dmarc[.]www[.]portal[.]0111etisalat[.]com etisalatquickpay[.]com etisalataccountquickpayae[.]top etisalataccount-quickpayae[.]click Unit 42 is tracking an increased risk of wiper attacks related to the conflict with Iran. Iranian actors have a history dating back to 2012 of conducting destructive attacks against high priority targets, highlighting a pattern of capability and intent. They also have a history of disruptive attacks dating back as far as 2011. Table 1 shows the three phases of Iran's use of destructive cyber operations. Table 1. The three phases of Iran's use of destructive cyber operations. Updated March 23, 2026, at 3:30 p.m. PT to add Additional Resources section. Updated March 26, 2026, at 2:00 p.m. PT to add information on conflict-themed phishing lures. Updated March 30, 2026, at 3:15 p.m. PT to edit list of indicators. Updated April 17, 2026 at 3:35 p.m. PT to add additional observations related to Cyber Av3ngers. Added an Appendix section. Added product protection information for Device Security and Cortex Xpanse.
unit42.paloaltonetworks.comMar 3, 2026extracted
Iran's cyberwar has begun
Iranian hackers have launched spying expeditions, digital probes, and distributed denial of service (DDoS) attacks in the wake of the US and Israel launching missile strikes over the weekend, and security researchers urge organizations to expect more cyber intrusions as the war continues. Most of the cyber activity so far has targeted Israel and Persian Gulf countries - and some of this began well before military campaigns - but threat intel analysts tell The Register that digital attacks against American organizations are inevitable. Mobile app security firm Approov noted a "significant surge in highly sophisticated probing attacks against APIs and mobile applications that provide critical communication links for regional governments," according to company CEO Ted Miracco. "We have analytical indications that the presumed Iranian actors were scouting and gauging regional infrastructure vulnerabilities." These probes began in early February, he told The Register, and while Approov can't comment on the specific apps or countries targeted, "we can state that it is in the direct region of conflict," Miracco said. The probes stopped on February 27, he added, which may be linked to the internet blackout across all of Iran at the start of the war. Iran also appeared to be "in the process of staging malware to target entities in Israel and the Middle East" prior to the air and sea strikes, according to Binary Defense Director of Threat Intelligence JP Castellanos. "This is pretty common for threat actors to stage their tools before executing." DDoS, disinfo, and ransomware Check Point researchers said that, in the months leading up to the conflict, they observed digital intrusions deploying malware linked to an Iranian threat group it tracks as Cotton Sandstorm (aka Haywire Kitten), affiliated with the Islamic Revolutionary Guard Corps (IRGC). "The actors routinely use WezRat, a custom modular infostealer delivered via spearphishing campaigns that masquerade as urgent software updates," the researcher wrote in an Sunday advisory. "In some cases, intrusions were followed by deploying WhiteLock ransomware specifically against Israeli targets, though there is nothing that prevents them from expanding this activity to other countries." Iran's government-backed crews have a history of working with ransomware gangs, and we saw state-sponsored ransomware attempts reemerge during the summer 2025 conflict, offering big bucks for infections against US and Israeli orgs. Also over the weekend, Check Point says Cotton Sandstorm revived its cyber persona, Altoufan Team, after a year of silence, to claim new alleged targets in Bahrain. "This reflects the reactive nature of the actor's campaigns and a high probability of their further involvement in intrusions across the Middle East amid the conflict," the security shop wrote. In addition to Cotton Sandworm, multiple pro-Iran threat groups claim to have compromised industrial control systems in Israel, Poland, Turkey, Jordan, and other Gulf countries. "For example, APT IRAN has claimed a cyber-sabotage operation against Jordan's critical infrastructure," Castellanos said. "Cyber Islamic Resistance has also claimed access to Israel-based internet routers." And while Binary Defense hasn't independently verified the attackers' claims, "this type of activity is consistent with Iran's well-documented use of information operations and influence campaigns," he added. "This is important context because many of these groups are engaging in significant disinformation." Be especially cautious about claims of attacks circulating on social media as a significant portion of what you'll see is disinformation designed to amplify fear and uncertainty, which is itself part of Iran's playbook Iran has a history of spreading disinformation and fake news via social media posts to manipulate public opinion, and this type of activity tends to get louder during times of conflict, such as the air strikes launched by the US and Israel last year intended to destroy Iran's nuclear capabilities. "Be especially cautious about claims of attacks circulating on social media as a significant portion of what you'll see is disinformation designed to amplify fear and uncertainty, which is itself part of Iran's playbook," Castellanos said. While Binary Defense hasn't seen any confirmed targeting of US organizations at this point in the conflict, "threat posture strongly suggests US-linked organizations should be treating this as a when, not an if," Castellanos noted. "The organizations we'd consider highest risk are those with direct connections to the US military, such as defense contractors and government suppliers," he said. "Similarly, organizations with ties to Israel through partnerships, subsidiaries, or shared infrastructure should be on heightened alert." He also urges critical infrastructure and other high-value targets to keep a close eye on their supply chains. "Companies using Israeli-made operational technology or industrial equipment could become indirect targets," Castellanos said. "We've seen this playbook before, where the equipment's origin became a factor in targeting decisions such as the 2023 campaign by CyberAv3ngers which targeted Unitronics PLCs and HMIs because they were Israeli-made." In 2023, Iran's CyberAv3ngers carried intrusions across multiple US water systems, relying on default passwords for internet-accessible programmable logic controllers. In a second round of attack in 2024, the Islamic Revolutionary Guard Corps-linked crew used custom malware to remotely control US and Israel-based water and fuel management systems. But aside from posting videos bragging about the intrusions on their Telegram sites, the attackers didn't really do anything with the access they gained to these critical systems. "Iran has historically had mixed results with disruptive cyberattacks, and they frequently fabricate and exaggerate their effects in an effort to boost their psychological impact," John Hultquist, Google Threat Intelligence Group chief analyst, told The Register. "Though they can have serious impacts on individual enterprises, it's important to take their claims with a grain of salt." Still, Hultquist said he does expect Iran to target US, Israel, and Gulf Cooperation Council countries using "disruptive cyberattacks, focusing on targets of opportunity and critical infrastructure." These attacks will likely resemble Iran's cyber operations during the Israel-Hamas war, with intel-gathering, limited disruption, and mass phishing campaigns ongoing before the bombing began, followed by data-wiping malware and other disruptive attacks to aid kinetic warfighters. "In many cases, their operations will be functionally similar to ransomware," Hultquist said. And while Google documented a "brief lull" in Iranian cyberespionage during the initial military strikes, the digital snoops have already resumed their activities, he added. Plus "hacktivist fronts with ties to the IRGC are making claims and threats about disruptive attacks in the region," Hultquist said. As the war continues, on the ground and in cyberspace, organizations can "expect elevated activity for the foreseeable future," Castellanos said. "Organizations should ensure all critical systems are fully patched and use this moment to reinforce security awareness training with staff." ®
go.theregister.comMar 2, 2026extracted