Foreign cyber actors breached two small Colorado water systems last month, tampering with pumps and disabling safety alarms before operators wrestled back control, the latest in a widening campaign targeting America's most basic infrastructure. Colorado state officials confirmed Thursday that hackers penetrated the computer networks of two unnamed water utilities, reaching past standard IT defenses […] The post Foreign hackers hit two Colorado water utilities, altered pumps and disabled alarms appeared first on American Almanac .
Foreign cyber actors breached two small Colorado water systems last month, tampering with pumps and disabling safety alarms before operators wrestled back control, the latest in a widening campaign targeting America's most basic infrastructure. Colorado state officials confirmed Thursday that hackers penetrated the computer networks of two unnamed water utilities, reaching past standard IT defenses and into the operational technology that controls physical equipment. The intruders changed pumping cycles, disabled remote-access capabilities, shut off alarms, and altered equipment settings. The two systems together serve roughly 400 people. Fox News Digital reported that operators eventually regained control, and Gov. Jared Polis' office…Open
Executive summary Note: This advisory relates to an active threat to Siemens S7 Series programmable logic controllers (PLCs). However, ongoing PLC targeting activity is broader than Siemens PLCs. All PLC owners and operators should apply relevant mitigations to reduce the risk to their devices and systems. The Siemens-specific content in this advisory should be understood and applied as one subset of the wider threat landscape. Top Mitigations - Inventory all Siemens S7 Series programmable logic controllers (PLCs) - Apply critical security patches - Ensure PLCs are not accessible from the Internet - Strengthen access controls - Monitor for unauthorized activity - Harden PLC services, protocols, and ladder logic…
This year's iteration of the War Department's longest-running unclassified cyber defense exercise, Cyber Shield 2026, is largely focused on operational technology, military cyber professionals said during a virtual media roundtable.
Advisory at a Glance Title Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure Original Publication April 7, 2026 Executive Summary Iran-affiliated advanced persistent threat (APT) actors are conducting exploitation activity targeting internet-facing operational technology (OT) devices, including programmable logic controllers (PLCs) manufactured by Rockwell Automation/Allen-Bradley. This activity has led to PLC disruptions across several U.S. critical infrastructure sectors through malicious interactions with the project file and manipulation of data on human machine interface (HMI) and supervisory control and data acquisition (SCADA) displays, resulting in operational disruption and…