Nearly 4,000 US industrial devices exposed to Iranian cyberattacks

2026-04-11T01:23:34Z60cc88e2ba35c7b4ea2f800508f74f04cc9bf5b700c9536fe8fdb0f691d315bb
Adobe Acrobat ReaderBitcoin DepotCISA KEV analysis','vulnerability management','Google Gmail E2EECPU-ZCPUIDChipSoftHWMonitorICS/OTIranian-linkedJoomlaLucidRookPhaaSRockwell AutomationSmart SliderStorm-2755VENOMWordPressbackdoorcrypto-theftindustrial control systemspayroll fraudphishingransomwaresupply chainzero-day

What happened

Multiple active and emerging threats reported across critical infrastructure, supply chains, and enterprise environments. Iranian-linked actors targeted thousands of Internet-exposed Rockwell Automation PLCs, highlighting an ICS/OT exposure risk; a supply-chain compromise at CPUID delivered malware via CPU‑Z and HWMonitor installers; and Smart Slider 3 Pro update servers were hijacked to push backdoored WordPress/Joomla builds. Adobe Acrobat/Reader zero-day exploitation has been observed in the wild since at least December. Targeted campaigns and tooling include the new Lua-based LucidRook (NG

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
60cc88e2ba35c7b4ea2f800508f74f04cc9bf5b700c9536fe8fdb0f691d315bb
Enrichment time
2026-04-11T01:23:34Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.