← BACK TO FEED
TAG

iran5 articles

100+ Water Systems Hit in July Cyberattacks — CISA Finally Puts a Number On It

In July 2026, CISA identified cyberattacks targeting over 100 internet-exposed water and wastewater systems across at least 12 U.S. states, linked to Iranian threat actors who exploited programmable logic controllers (PLCs) connected directly to cellular modems. While the attacks caused no significant disruption, they have raised serious concerns about the vulnerability of critical infrastructure. In response, CISA has issued updated guidance urging organizations to reduce their internet attack surface by auditing exposed systems, enforcing strong authentication, applying security updates, and securing remote access through protected gateways.

27 Aug 2026

PLCs on the public internet are an open goal for attackers, says ex-NSA chief

Retired General and former NSA chief Paul Nakasone has warned that water system controllers should not be connected to the internet, following suspected Iranian cyberattacks on water facilities across at least 12 US states. Speaking at DEF CON, he highlighted the enormous attack surface posed by around 50,000 underfunded and understaffed water municipalities, calling for higher cybersecurity standards and a collaborative defence approach. While neither the FBI nor the Trump administration has officially attributed the attacks to Iran, security researchers and Nakasone himself consider Iranian involvement highly likely given the country's history and demonstrated capability in targeting such infrastructure.

8 Aug 2026

Iranian Hackers Suspected Behind Wave of Cyberattacks Hitting Minnesota Water Systems

Cyberattacks targeted over 30 water systems across Minnesota on Sunday and Monday, with authorities including the FBI investigating the source amid warnings that Iranian hackers have been actively targeting water and critical infrastructure systems. While some communities experienced brief disruptions, such as the city of Braham temporarily asking residents to conserve water, there were no reported impacts on water quality or service for residents. Investigators have noted similarities across the incidents in timing and technology targeted, but have not yet confirmed whether a single culprit was responsible or publicly attributed the attacks to Iran.

2 Aug 2026

Iran Claims It Hit AWS Bahrain Again. The Region Has Been Offline For Months Anyway.

Iran's Islamic Revolutionary Guard Corps (IRGC) claims to have struck AWS infrastructure in Bahrain again with cruise missiles, describing it as retaliation for a reported US attack on an Iranian nuclear facility under construction. AWS services in Bahrain have already been offline for months following earlier Iranian strikes in late February, making it difficult to verify whether a new attack actually occurred. Iran has also designated facilities linked to other major tech companies, including Google, Microsoft, and Oracle, as potential targets for future retaliatory strikes.

22 Jul 2026

Iran's MOIS-Linked Hackers Deploy Modular C2 Framework Against Israeli Targets

An Iranian hacking group called Cavern Manticore, linked to Iran's Ministry of Intelligence and Security, has been targeting Israeli IT providers and government organisations using a newly discovered modular command-and-control framework called Cavern. The framework exploits SysAid's software update feature to deploy a trojanised DLL, enabling capabilities such as file theft, database access, Active Directory reconnaissance, network scanning, and tunnelling, while using multiple .NET compilation formats to deliberately complicate reverse engineering and forensic analysis. The group has also been observed moving laterally through trusted IT supply chain relationships and abusing remote monitoring tools, with related Iranian threat actors simultaneously conducting broader reconnaissance and data exfiltration campaigns across the Middle East.

12 Jul 2026