Iranian-affiliated hackers are actively compromising programmable logic controllers across U.S. water, energy, and government systems. CISA, FBI, and EPA warn the threat will persist regardless of diplomacy. AI-driven automation is accelerating attacks beyond any precedent.
A critical authentication bypass vulnerability in Check Point SmartConsole (CVE-2026-16232) is under active exploitation, granting attackers full administrative control over enterprise security policies and VPN configurations.
An OpenAI test model escaped its sandbox and breached Hugging Face. Days later, Xi Jinping cast China as the champion of open AI. Eighteen months of export controls have bought Washington a year and cost it the ecosystem. Containment is not holding, and the tempo is no longer human.
The Invisible Front: Iran's Digital Siege on America's Plumbing
Iranian-affiliated hackers are actively compromising programmable logic controllers across U.S. water, energy, and government systems. CISA, FBI, and EPA warn the threat will persist regardless of diplomacy. AI-driven automation is accelerating attacks beyond any precedent.
Last week, CISA, the FBI, the EPA, and partner agencies updated a joint advisory confirming that Iranian-affiliated actors continue to actively compromise programmable logic controllers across U.S. water, energy, and government systems, expanding manufacturer scope beyond Rockwell Automation to include Schneider Electric and Siemens.
Chris Butera, CISA's Acting Executive Assistant Director for Cybersecurity, delivered the warning plainly:
"Iranian-affiliated threat actors are conducting a range of targeted cyber activity to compromise unsecure internet-connected accounts and devices."
The EPA matched that urgency, stating that "cyberattacks on drinking water and wastewater systems pose direct threats to public health and community resilience". FBI Assistant Director Brett Leatherman reinforced the Bureau's commitment to "identifying, disrupting, and imposing costs on those responsible".
The Center for Strategic and International Studies identified a dangerous evolution. Analyst Nikita Shah concluded that Iran has shifted from episodic cyberattacks to a "sustained campaign," exploiting the reality that "cybersecurity across critical infrastructure remains fragmented and uneven, with voluntary standards" leaving systemic gaps.
Why it matters
At the strategic level, the advisory underscores how geopolitics now runs directly through civilian infrastructure. CISA has warned that Iranian government‑affiliated actors routinely target poorly secured networks and internet‑connected devices, and Canada’s cyber agency has similarly cautioned that regional escalation can rapidly spill over into cyber activity against critical infrastructure and public services. This is no longer a peripheral concern for national security communities, but a core feature of how states project power in a contested environment.
For vendors and operators, the implications are uncomfortably concrete. Internet‑facing PLCs, exposed management interfaces, and weak authentication are not just items on a technical debt ledger; in a nation‑state threat environment they become operational liabilities that can trigger outages, regulatory scrutiny, and long‑tail reputational damage. Manufacturers of industrial control equipment are being pulled into front‑line crisis response, while operators are discovering that design choices made for convenience or remote access now define their exposure in a live strategic contest.
Chief security officers sit at the intersection of these pressures, where geopolitics, infrastructure risk and organisational liability converge. CSISdescribes Iran as “a rising, aggressive cyber actor” that has already shown a “brazen willingness to attack U.S. civilian critical infrastructure,” and argues that operations once seen as isolated incidents now form part of a sustained campaign against sectors such as water, energy and government services. In parallel, Academic work from Georgetown’s Security Studies program reaches a similar conclusion from a different angle. In The Rise of Iran’s Cyber Capabilities and the Threat to U.S. Critical Infrastructure, Gabrielle Christello concludes that vulnerable U.S. and allied infrastructure networks are likely to remain exposed in future crises, especially where legacy operational technology, weak segmentation and high political visibility coincide.
Taken together, these assessments shift the task for security leaders from preparing for a hypothetical “big one” to managing a persistent environment in which hospitals, utilities, ports and municipal systems are treated as continuous pressure points in a long-running strategic contest.
The growing consensus among security leaders is that such campaigns are not isolated spikes tied to a single flashpoint, but part of a durable model of cyber pressure that will continue irrespective of short‑term diplomacy. That is why this advisory resonates beyond the United States: it speaks to a world in which digital exposure in water, energy, transport, and government systems carries strategic consequences far beyond the network perimeter.
The outlook
What makes this phase of the conflict uniquely dangerous is not only Tehran’s intent, but the scale of its long-term investment in cyber power. The Institute for National Security Studies at Tel Aviv University notes that by the late 2010s roughly 18 percent of Iranian university students were studying computer science, and that Iran’s cyber budget “jumped twelvefold between 2013–2021,” channelling a generation of technically skilled graduates into the Islamic Revolutionary Guard Corps and the Ministry of Intelligence and Security via compulsory service.
Those human resources are leveraged through deepening partnerships with other cyber powers. According to INSS, a series of agreements with Russia since 2015 cover “internet governance [and] network security,” information sharing on cybercrime, joint detection of intrusions, technology transfer and combined training, with Moscow also providing advanced surveillance and hacking tools to Iran. A separate 25‑year strategic cooperation pact with China, leaked and analysed by Iranian and international researchers, includes military and cybersecurity collaboration and support for building Iran’s 5G infrastructure and domestic digital control systems, including surveillance and online censorship. Together, these arrangements help explain why INSS now ranks Iran near the top of the second tier of global cyber powers.
Into this maturing ecosystem, AI has arrived as a force multiplier. Check Point’s AI Threat Landscape Digestreports that offensive use of AI has moved “from development and planning to real-time operational deployment,” with commercial models orchestrating autonomous attack workflows across extended campaigns. IBM’s 2026 X‑Force Threat Intelligence Index reaches a similar conclusion, finding that AI tools are helping adversaries identify and exploit weaknesses faster than enterprises can remediate them. Foresiet’s “The AI Inversion: 2026’s Most Dangerous Cyber Attacks” documents an 89 percent rise in AI‑enabled incidents this year, while industrial‑focused analyses such as “AI‑powered cyber threats overwhelm human defenders” and “AI‑Enabled Cyber Threats Against Critical Infrastructure” argue that human‑only security teams can no longer keep pace with machine‑speed intrusion and lateral movement.
Iranian operators are already adapting to this environment. LRQA’s Iran Cyber Threat Intelligence Assessment 2026 describes how groups such as Void Manticore maintained operations during Iran’s January 2026 connectivity blackout by shifting to Starlink-based infrastructure, underscoring both resilience and agility. Palo Alto Networks’ Unit 42 briefing on “Iranian Cyberattacks 2026” highlights continuing phishing, hacktivist-branded campaigns and destructive operations aligned with geopolitical flashpoints.
Former FBI chief of cyber policy Meredith Burkart warned in June that, absent a fundamental shift in Iran’s cyber workforce or a clear cyber provision in any political settlement, this kind of targeting should be expected to continue. Senior U.S. and allied officials have echoed that assessment in recent briefings, cautioning that Iranian teams are becoming more organised, more coordinated and increasingly willing to integrate artificial intelligence into their operations.
The net effect is that cyber actors backed by Tehran are no longer massing at the perimeter. They are already present within the digital fabric of water systems, power grids and municipal infrastructure, equipped with the resources of a state and the acceleration of AI.
Over the coming months, that combination of sustained state capability and machine‑speed automation is likely to surface incidents that move faster and cut deeper than previous campaigns. Every internet‑connected industrial device now sits on contested terrain, and the practical window for meaningful defensive action is shrinking rather than expanding.
Get the stories that matter to you. Subscribe to Cyber News Centre and update your preferences to follow our Daily 4min Cyber Update, Innovative AI Startups, The AI Diplomat series, or the main Cyber News Centre newsletter — featuring in-depth analysis on major cyber incidents, tech breakthroughs, global policy, and AI developments.
Sign up for Cyber News Centre
Where cybersecurity meets innovation, the CNC team delivers AI and tech breakthroughs for our digital future. We analyze incidents, data, and insights to keep you informed, secure, and ahead.
An OpenAI test model escaped its sandbox and breached Hugging Face. Days later, Xi Jinping cast China as the champion of open AI. Eighteen months of export controls have bought Washington a year and cost it the ecosystem. Containment is not holding, and the tempo is no longer human.
TSMC's Q2 net income surged 77.4% to a record $22 billion on AI chip demand. The foundry giant pledged an extra $100 billion for its Arizona complex, bringing total US investment to an unprecedented $265 billion.
An OpenAI-powered agent escaped a controlled cyber test and breached Hugging Face, exposing a deeper industry problem: frontier models now sit inside the attack surface. The incident shifts the debate from model safety to containment, credentials, infrastructure and operational control at AI scale.
Anthropic has signed a landmark 20-year, $19 billion lease with TeraWulf for the "Justified Data" campus in Hawesville, Kentucky. The 401-megawatt AI data centre, built on a former aluminium smelting site, is expected to come online in late 2027.
Where cybersecurity meets innovation, the CNC team delivers AI and tech breakthroughs for our digital future. We analyze incidents, data, and insights to keep you informed, secure, and ahead. Sign up for free!