Nearly 4,000 US industrial devices exposed to Iranian cyberattacks
2026-04-11T01:23:34Z•60cc88e2ba35c7b4ea2f800508f74f04cc9bf5b700c9536fe8fdb0f691d315bb
Adobe Acrobat ReaderBitcoin DepotCISA KEV analysis','vulnerability management','Google Gmail E2EECPU-ZCPUIDChipSoftHWMonitorICS/OTIranian-linkedJoomlaLucidRookPhaaSRockwell AutomationSmart SliderStorm-2755VENOMWordPressbackdoorcrypto-theftindustrial control systemspayroll fraudphishingransomwaresupply chainzero-day
What happened
Multiple active and emerging threats reported across critical infrastructure, supply chains, and enterprise environments. Iranian-linked actors targeted thousands of Internet-exposed Rockwell Automation PLCs, highlighting an ICS/OT exposure risk; a supply-chain compromise at CPUID delivered malware via CPU‑Z and HWMonitor installers; and Smart Slider 3 Pro update servers were hijacked to push backdoored WordPress/Joomla builds. Adobe Acrobat/Reader zero-day exploitation has been observed in the wild since at least December. Targeted campaigns and tooling include the new Lua-based LucidRook (NG
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 60cc88e2ba35c7b4ea2f800508f74f04cc9bf5b700c9536fe8fdb0f691d315bb
- Enrichment time
- 2026-04-11T01:23:34Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.