Nearly 4,000 US industrial devices exposed to Iranian cyberattacks

2026-04-10T19:23:31Z1611223f4a26c7a55812f86f4e5e63541807877809adf3192aa66f8c7cdeac04
PLCsacrobat-readerbitcoin-depotchipsoftcisa-kevcpu-zcpuidcrypto-theftdata-breacheurailhwmonitorindustrial-control-systemsiranian-linkedjoomlalucidrookphishingphishing-as-a-serviceransomwareremediation-gaps','chrome-dbsc','gmail-e2ee','session-cookie-therockwell-automationsmart-slidersupply-chain-attackvenomwordpresszero-day

What happened

Multiple high-impact security incidents and trends reported: Iranian-linked actors targeted U.S. critical infrastructure by scanning/exposing nearly 4,000 Internet-facing Rockwell Automation PLCs; a CPUID supply-chain compromise replaced CPU‑Z and HWMonitor downloads with malware; an Acrobat Reader zero‑day has been exploited since at least December; Smart Slider 3 Pro update infrastructure was hijacked to push backdoored WordPress/Joomla builds; new LucidRook Lua‑based malware is being used in targeted campaigns against NGOs and universities in Taiwan; a VENOM phishing‑as‑a‑service is siphons

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
1611223f4a26c7a55812f86f4e5e63541807877809adf3192aa66f8c7cdeac04
Enrichment time
2026-04-10T19:23:31Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Nearly 4,000 US industrial devices exposed to Iranian cyberattacks · Baitaphish