threat-intel
Threat Brief: Escalation of Cyber Risk Related to Iran (Updated April 17)
High
Summary
This report from Palo Alto Unit 42 details a significant escalation of cyber risk originating from Iran following a 47-day internet outage. Iranian threat actors, identified as CL-STA-1128 (Cyber Av3ngers), are now aggressively targeting Rockwell Automation and Allen-Bradley OT/ICS equipment, including FactoryTalk software, alongside a widespread phishing campaign. The situation is further complicated by a recent joint U.S.-Israel offensive and subsequent retaliatory cyberattacks, with potential for broader disruption targeting U.S. military bases.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
