US Warns of Iranian Hackers Targeting Siemens, Schneider, and Rockwell ICS Devices

2026-07-23T07:24:05Z507ea31af6df4461930886787499bb8597f3820bc04d68b30cbbc11e25efb90c
AI-generated appsAdobe extensionCVE-2026-50522ICSIranian threat actorsOracle CPU July 2026PLCPaidworkRockwellSchneider ElectricSharePointSiemensSunoWhatsApp data theftactive exploitationauthorization flawsbrowser extensiondata breachdenial-of-servicesecrets exposurevibe-codedvulnerability management

What happened

Multiple SecurityWeek reports on July 22–23, 2026 describe several high-impact events: a U.S. advisory warns Iranian-linked hackers are targeting Siemens, Schneider, and Rockwell industrial control systems and programmable logic controllers with techniques to gain persistent access; Suno and Paidwork suffered large data breaches exposing names, emails, phones, passwords and financial data; a flaw in a widely installed Adobe browser extension (≈300M installs) allowed exfiltration of WhatsApp messages/contacts via a malicious website; AI-generated “vibe-coded” apps were found to contain hundreds

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityweek
Record identifier
507ea31af6df4461930886787499bb8597f3820bc04d68b30cbbc11e25efb90c
Enrichment time
2026-07-23T07:24:05Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · US Warns of Iranian Hackers Targeting Siemens, Schneider, and Rockwell ICS Devices · Baitaphish