United States: Department of Homeland Security warns US institutions of ongoing Iranian cyber targeting

On Wednesday, the U.S. Department of Homeland Security warned U.S. entities of a persistent cyber threat from Iranian-affiliated actors and issued guidance to mitigate the risk.
In an advisory bulletin, the department’s Cybersecurity and Infrastructure Security Agency (CISA) stated that “Iranian-affiliated cyber actors are exploiting programmable logic controllers (PLCs) within critical U.S. infrastructure.”
The agency noted that it is “urgently warning U.S. entities of ongoing cyber targeting by Iranian-affiliated actors against operational technology devices connected to the internet, including programmable logic controllers.”
It explained that these cyber operations “have disrupted programmable logic controllers across multiple sectors of U.S. critical infrastructure through malicious interactions with project files and data manipulation on the user interface (UI) and supervisory control and data acquisition (SCADA) system screens, resulting in operational disruptions and financial losses.”
The bulletin included new guidance on “detecting malicious changes in reusable code exploited within programmable logic controller programs.”