Nearly 4,000 US industrial devices exposed to Iranian cyberattacks
2026-04-10T19:23:31Z•1611223f4a26c7a55812f86f4e5e63541807877809adf3192aa66f8c7cdeac04
PLCsacrobat-readerbitcoin-depotchipsoftcisa-kevcpu-zcpuidcrypto-theftdata-breacheurailhwmonitorindustrial-control-systemsiranian-linkedjoomlalucidrookphishingphishing-as-a-serviceransomwareremediation-gaps','chrome-dbsc','gmail-e2ee','session-cookie-therockwell-automationsmart-slidersupply-chain-attackvenomwordpresszero-day
What happened
Multiple high-impact security incidents and trends reported: Iranian-linked actors targeted U.S. critical infrastructure by scanning/exposing nearly 4,000 Internet-facing Rockwell Automation PLCs; a CPUID supply-chain compromise replaced CPU‑Z and HWMonitor downloads with malware; an Acrobat Reader zero‑day has been exploited since at least December; Smart Slider 3 Pro update infrastructure was hijacked to push backdoored WordPress/Joomla builds; new LucidRook Lua‑based malware is being used in targeted campaigns against NGOs and universities in Taiwan; a VENOM phishing‑as‑a‑service is siphons
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 1611223f4a26c7a55812f86f4e5e63541807877809adf3192aa66f8c7cdeac04
- Enrichment time
- 2026-04-10T19:23:31Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.