[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fSsLlkFgj7OyCE-Gkz5hj5Un5nogFEVc_apeB25SKWF4":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":18,"created_at":19,"published_at":20,"article":21,"tags":25,"podcasts":38},"6122ba53-3210-40fb-867b-06cf700c2100","iranian-apt-groups-exploit-internet-exposed-industrial-control-systems","cf7190dd-e6f9-4b29-b486-db990d884971","Iranian APT Groups Exploit Internet-Exposed Industrial Control Systems","Nearly 4,000 U.S. industrial control systems were left exposed to the internet, enabling Iranian APT groups to access and manipulate critical infrastructure since March 2026. The attackers successfully extracted device project files and disrupted HMI\u002FSCADA displays by targeting improperly configured Rockwell Automation PLCs that should never have been directly accessible from the internet. This incident highlights the catastrophic risk of placing operational technology (OT) systems online without proper network isolation and security controls. The widespread exposure of these devices demonstrates a fundamental failure in industrial cybersecurity architecture that could enable adversaries to cause physical damage or operational shutdowns.","**Immediate actions:**\n- Inventory all internet-facing industrial control systems and immediately isolate them from direct internet access\n- Implement firewall rules to block unauthorized external connections to OT networks\n- Audit cellular modem configurations to ensure they don't bypass network security controls\n\n**Network architecture improvements:**\n- Establish air-gapped or DMZ networks to separate OT systems from corporate IT networks\n- Deploy industrial firewalls and VPN gateways for any required remote access to control systems\n- Configure network monitoring to detect unauthorized access attempts to industrial devices\n\n**Long-term security measures:**\n- Develop and enforce policies prohibiting direct internet connectivity for critical infrastructure devices\n- Implement zero-trust network architecture with strict access controls for industrial systems\n- Establish regular security assessments of OT network segmentation and access controls",[12,13,14,15,16,17],"CIS Control 12 (Network Infrastructure Management)","CIS Control 13 (Data Protection)","NIST SP 800-82 (Industrial Control Systems Security)","NIST CSF PR.AC-4 (Access Permissions)","IEC 62443-3-3 (Network Segmentation)","NERC CIP-005 (Electronic Security Perimeters)","published","2026-04-10T16:09:39.289731+00:00","2026-04-10T16:09:39.184+00:00",{"id":7,"url":22,"slug":23,"title":24},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fnearly-4-000-us-industrial-devices-exposed-to-iranian-cyberattacks\u002F","nearly-4-000-us-industrial-devices-exposed-to-iranian-cyberattacks-bdb849","Nearly 4,000 US industrial devices exposed to Iranian cyberattacks",[26,32],{"id":27,"name":28,"slug":29,"description":30,"color":31},"859cf0ad-a7e9-42bb-a75d-bac6511fa5d5","Configuration Management","configuration-management","Misconfigs, default credentials, exposed services","#eab308",{"id":33,"name":34,"slug":35,"description":36,"color":37},"f43a7f30-5046-4b10-9dba-1a704139821e","Network Segmentation","network-segmentation","Lateral movement, flat networks, missing firewalls","#06b6d4",[39],{"id":40,"date":41,"edition":42,"title":43,"audio_url":44},"993e8114-39e6-455e-9f63-e99184078da9","2026-04-11","morning","ThreatNoir Weekend Brief — April 11","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-04-11\u002Fthreatnoir-morning-brief-2026-04-11.mp3"]