US warns of active cyber threat targeting critical infrastructure
The Federal Transit Administration is urging public transit agencies and operational technology operators to review Cybersecurity and Infrastructure Security Agency (CISA) updates. This includes the new Gold Eagle AI Clearinghouse initiative launched by CISA and the Treasury. These warnings follow previous alerts regarding cyber threats from Russia, China, and Iran targeting water utility systems. The broader security environment remains tense following Iranian threats to Middle East energy infrastructure on September 7 and subsequent US strikes on Iranian assets.
What changed
The Federal Transit Administration has extended CISA security warnings and the Gold Eagle AI Clearinghouse initiative to the transportation sector.
Live updates
-
US expands cyber warnings to public transit agencies
The Federal Transit Administration is urging public transit agencies and operational technology operators to review Cybersecurity and Infrastructure Security Agency (CISA) updates. This includes the new Gold Eagle AI Clearinghouse initiative launched by CISA and the Treasury. These warnings follow previous alerts regarding cyber threats from Russia, China, and Iran targeting water utility systems. The broader security environment remains tense following Iranian threats to Middle East energy infrastructure on September 7 and subsequent US strikes on Iranian assets.
Why it matters
US critical infrastructure is under systemic pressure from multiple nation-state actors. CISA previously ordered operators to secure Siemens S7 PLCs to block attack paths. Geopolitical instability has already impacted markets, pushing Brent crude to US$97.31 a barrel.
What is confirmed
- The Federal Transit Administration is urging public transit agencies and operational technology operators to review updates from CISA.
- CISA and the Treasury launched the Gold Eagle AI Clearinghouse initiative.
What to watch next
- Implementation status of Gold Eagle AI Clearinghouse among transit agencies
- Further CISA directives for other critical infrastructure sectors
confidence 100%Sources used for this update (6)
- aptapassengertransport.com — Critical Cybersecurity Updates for Transportation Stakeholders
- jen.jiji.com — Fenerbahce-Roma, Gasperini demands three penalties: what happened in Champions
- jen.jiji.com — Blasphemy in the street, police hear it: 102 euro fine in Venice
- jen.jiji.com — 9/11: Trump: "We will never forget, it's why we fight today"
- thediplomat.com — Bangladesh and the Perils of Pax Silica
- jen.jiji.com — 'Arianna's Thread', the film about kidney cancer at the Venice exhibition (2)
-
US Infrastructure Faces Cyber Threats Amid Rising Middle East Tensions
US critical infrastructure faces cyber threats from Russia, China, and Iran, specifically targeting water utility systems. Simultaneously, the Cybersecurity and Infrastructure Security Agency has directed operators to harden Siemens S7 PLCs through firmware updates and communication limits to close attack paths. These digital risks coincide with geopolitical volatility as Iran threatened to attack Middle East energy infrastructure on September 7, 2026, following US strikes on Iranian assets. This escalation drove Brent crude to a six-week high of US$97.31 a barrel.
Why it matters
The convergence of state-sponsored cyberattacks and physical threats to energy assets creates a dual-risk environment for national security. Aging utility systems and unpatched hardware like Siemens PLCs provide entry points for adversaries. These vulnerabilities are exacerbated by active conflicts in the Middle East.
What is confirmed
- Brent crude settled at US$97.31 a barrel on September 7, 2026.
- Iranian Parliament Speaker Mohammad Baqer Qalibaf stated that if US assets are struck, Iran will strike back.
- CISA has instructed operators to harden Siemens S7 PLCs by updating firmware or limiting S7 communications.
Still unconfirmed
- Cyberattacks from Iran, China, and Russia are targeting American water critical infrastructure.
- Hundreds of vulnerable Exchange servers remain active in Australia.
- Goldman Sachs warns oil could reach US$120 if vessel attacks intensify.
What to watch next
- CISA updates on Siemens PLC vulnerability exploitation
- Further Iranian threats to Middle East energy infrastructure
- Evidence of successful breaches in US water utility systems
confidence 80%Sources used for this update (6)
- jen.jiji.com — Iran energy threats lift oil prices to six-week highs
- www.itnews.com.au — Hundreds of old, vulnerable Exchange servers remain in Australia
- www.foxnews.com — If hackers cripple America's water, the consequences could be catastrophic
- jen.jiji.com — Move to call VP Sara Duterte as witness ‘not expected,’ defense says
- www.cfr.org — Twenty-Five Years After 9/11, the United States Is Unprepared for Terrorism’s Next Wave
- www.csoonline.com — CISA tells operators to harden Siemens S7 PLCs. Here’s how to do it without disrupting production
-
Cyber Attackers Use Trusted Google Services and QR Codes to Steal Credentials
Attackers are leveraging trusted Google services and text-based QR codes to bypass security measures and steal corporate credentials. Current threats include phishing campaigns that install ScreenConnect via fake verification pages and supply chain attacks where trusted software sources deliver credential-stealing code. These activities coincide with active attacks on routers, browsers, and online stores. While the US continues to manage critical infrastructure vulnerabilities, educational institutions like the University of Bristol are expanding dedicated cyber security suites to address these evolving digital threats.
Why it matters
These tactics represent a shift toward abusing trusted platforms to evade traditional email filters and image blocking. This follows previous reports of zero-day vulnerabilities in SonicWall hardware and reliance on foreign AI hardware. The persistence of these threats drives investment in specialized security infrastructure and academic research.
What is confirmed
- Phishers are using trusted Google services to install ScreenConnect and steal corporate credentials through fake verification pages.
- The University of Bristol opened the Sloane Robinson Building at its 500 million pound Temple Quarter Enterprise Campus, featuring cyber security suites.
- Attackers have used scannable QR codes built from text to bypass email image blocking.
Still unconfirmed
- A trusted software source delivered code that stole credentials.
- A network management protocol provided outsiders clues before login.
What to watch next
- Reports on the effectiveness of text-based QR code filters
- Updates on the exploitation of the SonicWall SMA1000 zero-day vulnerabilities
- Federal policy changes regarding Chinese hardware in US AI data centers
confidence 90%Sources used for this update (5)
- londonlovesbusiness.com — There is ‘zero chance of reaching an agreement’ as the Kremlin dictator wants Donetsk
- jen.jiji.com — SEPO maps ‘3+8’ overhaul of Thailand’s state enterprises
- thehackernews.com — ⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More
- cybersecuritynews.com — Hackers Abuse Trusted Google Services to Hide Credential-Stealing Phishing Attacks
- news.europawire.eu — University of Bristol Opens £500 Million Temple Quarter Enterprise Campus, Creating New Innovation Gateway for 4,500 Students, 650 Staff and Regional Industry Partners
-
US Critical Infrastructure Faces Active Cyber and Geopolitical Threats
United States critical infrastructure faces continuous exposure to active cyber threats and supply chain vulnerabilities, underscored by SonicWall reporting the active exploitation of two SMA1000 zero-day vulnerabilities, including a remote code execution flaw with a maximum severity rating of 10.0. This digital pressure compounds broader geopolitical risks as US AI data centers rely heavily on Chinese hardware despite federal restrictions, while regional conflicts expose physical vulnerabilities. Simultaneously, global technical and infrastructure policy measures expand, with international bodies and local policy committees grappling with the mounting demands and resource pressures driven by expanding data center developments.
Why it matters
Critical infrastructure protection remains a high-priority national security challenge as cyber intrusions target essential software and hardware systems. Geopolitical tensions, including recent missile exchanges involving Iran and the Strait of Hormuz, highlight the vulnerability of strategic assets. Meanwhile, policy advisers warn that massive technological expansions require rigorous regulation to manage national resource costs effectively.
What is confirmed
- SonicWall reported the active exploitation of two SMA1000 zero-day vulnerabilities, including a remote code execution flaw with a maximum severity rating of 10.0.
What to watch next
- Further official advisories regarding the remediation of the SonicWall SMA1000 zero-day vulnerabilities.
- Updates on federal enforcement rules concerning foreign bulk-power equipment in US AI data centers.
confidence 100%Sources used for this update (6)
- www.securityweek.com — In Other News: Microsoft’s Cloud Patches, Hacked Dropbox Accounts, Guardio’s $1.1B Valuation
- jen.jiji.com — Thailand must Weigh Data Centre Boom Against National Resource Costs
- jen.jiji.com — Thai Monarchs Dispatch Royal Relief Supplies to Flood-Stricken Nepal
- jen.jiji.com — Over 583,000 military, uniformed personnel to get 5% pay hike in 2027
- en.ara.cat — This is how the hybrid war that attacks us Europeans works
- jen.jiji.com — VP Duterte posts bail; arrest warrant lifted in QC grave threats case
-
US Infrastructure Risks Persist Amid Iranian Aggression and Hardware Gaps
US critical infrastructure faces a combined threat of geopolitical aggression and technical vulnerabilities. Iran recently launched missiles and drones at Kuwait in retaliation for US strikes on rocket launchers in the Strait of Hormuz. Simultaneously, US AI data centers remain dependent on Chinese transformers, batteries, and switchgear despite stricter federal rules on foreign bulk-power equipment. Cyber threats continue to evolve, with SonicWall reporting the active exploitation of two SMA1000 zero-day vulnerabilities, including one with a maximum severity rating of 10.0, allowing for remote code execution.
Why it matters
These developments follow a July 2026 campaign that disrupted US water utility monitoring. The reliance on foreign power hardware creates a potential structural weakness in the AI sector. Ongoing Iranian hostilities increase the likelihood of the unexpected critical events previously warned by Iranian hackers.
What is confirmed
- Iran fired drones and missiles at Kuwait to retaliate for US strikes on Iranian rocket launchers in the Strait of Hormuz.
- US AI data centers depend on Chinese optics, batteries, switchgear, and transformers.
- SonicWall identified two SMA1000 zero-days being chained by attackers, one of which is a pre-auth SSRF flaw with a CVSS 10.0 rating.
What to watch next
- US government response to the kinetic attacks in Kuwait
- Implementation of new federal rules regarding foreign bulk-power equipment
- Reports of SMA1000 exploit activity in US infrastructure networks
confidence 100%Sources used for this update (4)
- www.briefs.co — U.S. AI Data Centers Lean on Chinese Power Gear as Washington Tightens the Screws
- www.foxnews.com — Iran retaliates against US by firing at Kuwait in 'blatant' aggression
- thehackernews.com — ThreatsDay: CEO Phishing Kits, 5K Dropbox Account Hacks, OAuth Traps + 17 More Stories
- thecyberexpress.com — SonicWall Warns of Two Actively Exploited SMA1000 Zero-Days, One Rated Maximum Severity
-
Iran targets US infrastructure as cyber threats expand to UK power plants
Iranian hackers have attempted multiple cyberattacks against a variety of US infrastructure targets. While these attempts were unsuccessful, an Iranian hacking group warned that American infrastructure will soon face unexpected and critical events. This threat coincides with a separate cyber attack in the UK that forced a power generator offline, highlighting vulnerabilities in connected energy infrastructure. These events follow a July 2026 campaign against US water utilities that disrupted remote monitoring and forced some facilities to switch to manual treatment processes.
Why it matters
Critical infrastructure security is under pressure as state-sponsored actors target industrial control systems. The US Cybersecurity and Infrastructure Security Agency previously warned water utilities to secure programmable logic controllers after over 100 systems were compromised. These incidents demonstrate a pattern of targeting essential utilities to cause operational disruptions.
Still unconfirmed
- Iranian hacking groups have attempted unsuccessful cyberattacks on a range of US infrastructure.
- An Iranian hacking group warned that American infrastructure would soon face unexpected and critical events.
- A cyber attack forced a UK power generator offline.
- The UK generator attack highlighted security risks associated with connected energy infrastructure.
What to watch next
- Official attribution of the UK power plant attack to a specific state actor.
- CISA updates regarding the success or failure of Iranian intrusion attempts.
- Evidence of new vulnerabilities in programmable logic controllers across other utility sectors.
confidence 70%Sources used for this update (7)
- jen.jiji.com — DOF risks ₱10-billion revenue loss from proposed power tax exemption
- sg.news.yahoo.com — Replay: UK PM Andy Burnham faces lawmakers for first time since taking office
- sg.news.yahoo.com — Retro Gaming's Most Electrifying Game Over
- www.nbcnews.com — Iran attempted cyberattacks on range of U.S. infrastructure, sources say
- jen.jiji.com — Suphachai calls for THB100bn university innovation drive
- jen.jiji.com — Toyota’s Vietnam expansion exposes Thailand’s EV-era investment challenge
- www.iotinsider.com — The hidden IoT risk behind the UK’s power plant cyber attack
-
CISA Warns Water Systems to Secure PLCs After July Cyberattacks
The Cybersecurity and Infrastructure Security Agency (CISA) has ordered US water utilities to secure programmable logic controllers (PLCs) and reduce internet exposure. This follows a July 2026 campaign that targeted over 100 internet-exposed systems, including municipal water authorities, rural water districts, and wastewater treatment facilities. While no unsafe drinking water reached the public, the attacks caused operational disruptions and forced some utilities to use manual treatment processes after losing remote monitoring capabilities. CISA issued a formal advisory on August 22 to prevent further compromises of critical infrastructure.
Why it matters
Programmable logic controllers manage the physical processes of water treatment and distribution. Compromising these devices can lead to total loss of operational control. This campaign highlights the vulnerability of small and rural utilities to remote cyber threats.
What is confirmed
- CISA confirmed hackers targeted more than 100 internet-exposed US water systems in July 2026.
- The cyber campaign hit wastewater treatment facilities, rural water districts, and municipal water authorities.
- Operational disruptions included the loss of remote monitoring and a requirement for manual treatment processes.
- CISA issued an advisory on August 22 urging organizations to secure programmable logic controllers.
- No unsafe drinking water reached the public during the July attacks.
What to watch next
- Reports of further utility compromises following the August 22 advisory
- CISA updates on the origin or attribution of the July cyber campaign
confidence 100%Sources used for this update (5)
- www.foxbusiness.com — Cyber Security
- jen.jiji.com — Bangkok prepares to host Gastech 2026 amid rising Asian energy demand
- www.thestar.com.my — Hun Sen declares Thais used ‘scam excuse’ to invade Cambodia, warns of ‘collapse of world order’
- jen.jiji.com — Songkhla Lake Bridge contract set to boost southern travel and economy
- jen.jiji.com — Marcos keeping track of Pinoys amid widespread flooding, Palace says
-
CISA confirms over 100 US water systems targeted in July cyberattacks
The Cybersecurity and Infrastructure Security Agency (CISA) confirmed that hackers targeted more than 100 internet-exposed US water systems in July 2026. The campaign hit wastewater treatment facilities, rural water districts, and municipal water authorities. While no unsafe drinking water reached the public, some utilities suffered operational disruptions, including the loss of remote monitoring and the need for manual treatment processes. CISA issued an advisory on August 22 urging organizations to reduce their exposure and secure programmable logic controllers (PLCs) before attackers compromise them.
Why it matters
This escalation follows warnings about attackers using AI and scanning services to find vulnerable Siemens S7 Series PLCs. The vulnerability of these systems poses a risk of cascading failures across energy, manufacturing, and water sectors.
What is confirmed
- CISA confirmed over 100 internet-exposed US water systems were targeted in cyberattacks during July 2026.
- The July attacks affected rural water districts, municipal water authorities, and wastewater treatment facilities.
- Some utilities experienced operational disruptions, including the defacement of human-machine interfaces and forced manual operation of treatment processes.
- CISA issued an advisory on August 22 urging water utilities to secure internet-exposed PLCs.
- There is no evidence that the July attacks resulted in unsafe drinking water reaching the public.
Still unconfirmed
- The July water system attacks were Iran-backed.
- A Chinese hacking group targeted the DOJ, HHS, NIH, and NASA over several years.
- The President declared a national emergency to secure the United States bulk power system.
What to watch next
- Official attribution of the July water system attacks by the US government
- Evidence of physical equipment damage resulting from PLC exploits
- Updates on the implementation of the national emergency for the bulk power system
confidence 90%Sources used for this update (5)
- www.securityweek.com — CISA: Over 100 Internet-Exposed Water Systems Targeted in July Cyberattacks
- abcnews.com — FBI says Chinese hacking group targeted US government agencies for years
- www.whitehouse.gov — DECLARING A NATIONAL EMERGENCY TO SECURE
- www.androguider.com — CISA Confirms 100+ US Water Systems Hacked in July Amid Iran-Backed Cyberattacks
- securityaffairs.com — CISA Warns Water Utilities: Find Your Exposed PLCs Before Attackers Do
-
US warns of AI-driven cyberattacks on Siemens industrial controllers
The US government has identified an active threat targeting internet-exposed Siemens S7 Series programmable logic controllers (PLCs) used in water, energy, and manufacturing sectors. Attackers use AI to write exploit scripts and employ scanning services like ZoomEye and Censys to find vulnerable systems. This activity could lead to industrial process disruptions, equipment damage, safety incidents, and cascading failures across interconnected systems. The warning emphasizes that this is not a theoretical risk but a current operational threat to critical infrastructure.
Why it matters
The cyber threats emerge as the Trump administration prepares sweeping economic measures against Iran and its trading partners. This economic pressure coincides with threats from Tehran regarding Gulf oil disruptions and a standoff over the Strait of Hormuz.
What is confirmed
- The US government warned that AI-powered attacks on Siemens S7 Series PLCs are an active threat rather than a theoretical risk.
- Attackers use AI to write exploit scripts targeting critical infrastructure sectors including water, energy, and manufacturing.
- The Trump administration is preparing economic measures against Iran and its trade partners.
- Threat actors use scanning services such as Censys and ZoomEye to find internet-exposed PLCs.
Still unconfirmed
- Former White House adviser Jake Braun stated the US must prepare for attacks to increase in severity.
What to watch next
- Confirmation of specific industrial failures or safety incidents linked to Siemens PLC exploits
- Implementation of the proposed US economic measures against Iranian trade partners
- Official attribution of the Siemens PLC attacks to specific Iranian state actors
confidence 90%Sources used for this update (6)
- thehackernews.com — ⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and More
- www.foxbusiness.com — ‘Economic D-Day’ on Iran puts trading partners in crosshairs as Tehran threatens retaliation
- www.aljazeera.com — Iran war live: US slaps new sanctions on Iran, warns Tehran trade partners
- economictimes.indiatimes.com — Breaking News Live Updates: Doval, Wang hold bilateral talks ahead of Xi’s expected visit to India
- www.newsweek.com — Ex-White House Adviser Sounds Alarm Over Iran’s Growing Cyber War on US
- www.infosecurity-magazine.com — Australia Warns of Active Exploitation of Critical TeamCity Server Flaw
-
US warns of Iranian cyber threats to critical infrastructure
The US government has identified an active cyber threat from Iranian hackers targeting critical infrastructure, specifically sewage-treatment and water systems. These attackers use AI-generated scripts to disrupt industrial processes. The FBI and other agencies have detected these activities across multiple US states and issued alerts to warn operators. This digital aggression coincides with a broader geopolitical standoff between Washington and Tehran, particularly regarding the Strait of Hormuz.
Why it matters
Targeting water and sewage systems can lead to immediate public health crises or environmental disasters. The use of AI scripts indicates a shift toward automated, scalable attacks on industrial control systems. This activity occurs alongside escalating tensions in the Middle East.
Still unconfirmed
- The US and Iran are in an evolving war characterized by a standoff over the Strait of Hormuz.
What to watch next
- Reports of successful breaches or service disruptions in water treatment plants
- Official attribution statements from the FBI regarding specific AI scripts used
confidence 70%Sources used for this update (5)
- timesofindia.indiatimes.com — US Iran War News Live Updates: US Iran War | Iran says Gulf states hosting US bases backed attack, may pursue legal action
- jen.jiji.com — US hands over two Marine Protector-class patrol boats to PCG
- cyberpress.org — Weekly Cybersecurity Newsletter — Top 50 Cybersecurity Stories of the Week
- jen.jiji.com — Marcos admin warns companies of EPR obligations
- securityaffairs.com — Security Affairs newsletter Round 591 by Pierluigi Paganini – INTERNATIONAL EDITION
-
US warns of active cyber threat targeting critical infrastructure
The US has warned of an active cyber threat targeting critical infrastructure, including water and sewage-treatment systems. The threat is attributed to Iranian hackers and involves the use of AI-generated scripts to disrupt industrial processes. The FBI and other agencies have issued alerts about the threat, which has been detected in multiple states.
Why it matters
The threat is significant because it targets essential services that Americans rely on daily. A successful attack could have serious consequences, including disruptions to water and sewage services. The US has been working to improve its cybersecurity defenses, but the threat highlights the ongoing challenges in protecting critical infrastructure. The Iranian government has been accused of sponsoring cyberattacks in the past.
What is confirmed
- The US government has warned of an active cyber threat targeting critical infrastructure.
- The threat involves the use of AI-generated scripts to disrupt industrial processes.
- The FBI and other agencies have issued alerts about the threat.
- The threat has been detected in multiple states, including Washington.
Still unconfirmed
- The Iranian government has been accused of sponsoring the cyberattacks.
What to watch next
- Further alerts from US agencies about the threat
- Reports of successful attacks on critical infrastructure
- Iranian government response to the allegations
confidence 85%Sources used for this update (7)
- The Economist — Why the world’s richest country can’t defend vital infrastructure
- slate.com — So About That Iranian Cyberattack on Our Water Supply
- Fox Business — US warns of active cyber threat targeting critical infrastructure
- Industrial Cyber — CISA, NSA, FBI warn of Siemens S7 PLC exploitation using AI-generated scripts to disrupt critical industrial processes
- Bellingham Herald — WA officials issue alert about threat to water, sewage-treatment systems
- Yahoo — FBI warns of nationwide cyberattacks targeting water systems
- consent.yahoo.com — FBI warns of nationwide cyberattacks targeting water systems