ics-ottrade-pressNewsThe Broadside1 min read

CISA broadens Iran-linked OT alert to HMI, SCADA displays

For OT teams, the live issue is not attribution; it is whether screens can still be trusted during process control.


TL;DR

CISA and partner agencies revised alert AA26-097A after observed Iran-affiliated activity against internet-facing operational technology included malicious project-file interactions and manipulation of human machine interface and supervisory control and data acquisition displays. State CISOs, municipal IT teams, contractors and managed service providers supporting water, energy, gas and manufacturing sites should review the advisory’s indicators and mitigations, including log checks and removing programmable logic controllers from direct internet exposure.

The Record reports that federal agencies expanded an April warning on Iran-linked operational technology attacks to cover manipulation of human machine interface and supervisory control and data acquisition displays. CISA’s advisory says the activity has targeted internet-facing programmable logic controllers, caused disruptions across U.S. critical infrastructure sectors, and produced operational disruption and financial loss. The practical issue for water, electric, gas and manufacturing operators is visibility: if the HMI or SCADA display can be falsified, the operator may lose the process data needed to spot a harmful command in time. State CISOs, municipal IT teams, contractors and MSPs should work from CISA AA26-097A, especially the recommendations to remove PLCs from direct internet exposure, check logs for listed indicators of compromise and suspicious traffic on OT ports including 44818, 2222, 102 and 502, and follow device-specific guidance where applicable: https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-097a


Published ·Deep Fathom