News chronological

Showing 6 items before 1163039

Filters Applied:

CISA (CISA) - Defending Against an Active Threat to Siemens S7 Series PLCs

Executive summary Note: This advisory relates to an active threat to Siemens S7 Series programmable logic controllers (PLCs). However, ongoing PLC targeting activity is broader than Siemens PLCs. All PLC owners and operators should apply relevant mitigations to reduce the risk to their devices and systems. The Siemens-specific content in this advisory should be understood and applied as one subset of the wider threat landscape. Top Mitigations - Inventory all Siemens S7 Series programmable logic controllers (PLCs) - Apply critical security patches  - Ensure PLCs are not accessible from the Internet - Strengthen access controls - Monitor for unauthorized activity - Harden PLC services, protocols, and ladder logic…

What specific detection opportunities should organizations look for to identify a potential compromise?
Organizations should hunt for anomalies including: Anomalous S7comm behavior, such as unusual data block access patterns, write operations outside change windows, or connections from non-engineering workstations. Reconnaissance indicators, such as repeated connection attempts with varying parameters, enumeration of CPU properties, or sequential IP scanning on port 102. Tool artifacts, such as the use of the snap7.dll library outside of approved engineering workstations, unauthorized monitoring software installations, or Python scripts with S7comm functionality. Temporal anomalies, such as S7comm activity during off-hours, unexpected connection patterns consistent with automated scripting, or configuration changes without corresponding change tickets or work orders. Geographic anomalies, such as connections originating from unexpected IP ranges or countries not associated with vendors or integrators.
Q&A ID 9b7799a0-d96f-4d2e-a2d9-473a5eb813c1
What are the potential operational impacts if poorly protected Siemens S7 Series PLCs are exploited?
Exploitation could lead to: Disruption of critical industrial processes affecting production throughput, product quality, and public services. Safety incidents affecting personnel through the manipulation of process parameters, emergency shutdown systems, or safety interlocks. Equipment damage and extended operational downtime resulting from improper sequencing, process upsets, or forced equipment operation outside design parameters. Compromise of sensitive operational data, such as facility configurations, control strategies, and proprietary process recipes. Cascading impacts across interconnected systems, affecting integrated business operations, dependent facilities, and supply chains. Regulatory compliance violations and potential liability from failures in process safety management.
Q&A ID c1d5729d-5d8e-4451-bc66-5836d752ae5c
What open source industrial automation libraries are being used by threat actors to create custom tools?
Threat actors are leveraging open source industrial automation libraries, specifically snap7.dll and python-snap7, combined with AI-assisted scripting to create custom tools that mimic legitimate OT monitoring solutions.
Q&A ID 43cd898e-a1e0-4db6-ac6e-61c6f80101c3
Which specific Siemens S7 Series PLC models are currently being targeted by active threat actors?
Threat actors are actively targeting the following models: S7-200 Series (all CPU variants) S7-300 Series (all CPU variants, including 314, 315, and 317 models) S7-400 Series (all CPU variants) S7-1200 Series (CPU 1211C, 1212C, 1214C, 1215C, and 1217C variants) S7-1500 Series (all CPU variants, including F-series safety controllers).
Q&A ID e43f7706-d709-4bf7-b593-80fdb53cf47f

STONEZONE (Roger Stone) - FBI and EPA Warn of Cyberattacks Disrupting Water Systems in Seven States

Federal investigators are sounding the alarm after a wave of cyberattacks that hit water and wastewater systems in at least seven states, with some operations knocked offline or forced into manual mode. The FBI and Environmental Protection Agency issued a joint public service announcement on July 30 confirming that utility companies have been reporting incidents […] The post FBI and EPA Warn of Cyberattacks Disrupting Water Systems in Seven States appeared first on StoneZone .

Federal investigators are sounding the alarm after a wave of cyberattacks that hit water and wastewater systems in at least seven states, with some operations knocked offline or forced into manual mode. The FBI and Environmental Protection Agency issued a joint public service announcement on July 30 confirming that utility companies have been reporting incidents since July 27. In several cases the attacks degraded actual water operations: loss of pressure, flooding, and disruptions that in some instances prompted boil-water notices. According to assessments shared with U.S. and state officials, Iranian-affiliated actors are the leading working theory behind the activity. Investigators treat that assessment as fluid and remain alert to…Open

AMERICANALMANAC (Charles McAdams) - Cyberattack hits water systems in at least seven states as feds probe possible Iran connection

Malicious cyber activity forced water utilities in at least seven states to switch to manual operations this week, and federal investigators are now examining whether Iran is behind the breach, even as President Trump publicly disputes that theory. The FBI, the Cybersecurity and Infrastructure Security Agency, and the Environmental Protection Agency issued a joint warning […] The post Cyberattack hits water systems in at least seven states as feds probe possible Iran connection appeared first on American Almanac .

Malicious cyber activity forced water utilities in at least seven states to switch to manual operations this week, and federal investigators are now examining whether Iran is behind the breach, even as President Trump publicly disputes that theory. The FBI, the Cybersecurity and Infrastructure Security Agency, and the Environmental Protection Agency issued a joint warning Thursday that hackers are targeting internet-exposed industrial controllers used by water and wastewater systems across the country. More than 30 community water systems in Minnesota alone lost remote monitoring and control capability after attackers compromised programmable logic controllers, the small computers that automate pumps, valves, and chemical treatment at…Open

AMERICANGREATNESS (Patrick Cleburne) - Why the Southern Poverty Law Center Should Be Called the ‘$PLC’

Black people, POCs, now majority of $PLC board We at VDARE always followed the lead of our old friend Paul Craig Roberts in believing that the bank […] Source

CISA (CISA) - Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure

Advisory at a Glance Title Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure Original Publication April 7, 2026 Executive Summary Iran-affiliated advanced persistent threat (APT) actors are conducting exploitation activity targeting internet-facing operational technology (OT) devices, including programmable logic controllers (PLCs) manufactured by Rockwell Automation/Allen-Bradley. This activity has led to PLC disruptions across several U.S. critical infrastructure sectors through malicious interactions with the project file and manipulation of data on human machine interface (HMI) and supervisory control and data acquisition (SCADA) displays, resulting in operational disruption and…