High
April 7, 2026

Weekly U.S. Critical Infrastructure Threat Brief (2026-04-01 to 2026-04-07)

Iranian-affiliated actors exploited internet-exposed Rockwell PLCs across U.S. OT environments while CISA added Fortinet FortiClient EMS (CVE-2026-35616) to the Known Exploited Vulnerabilities catalog — both elevate near-term operational risk for Energy and federal IT sectors (2026-04-01 → 2026-04-07).

Affected Sectors:Energy, Telecommunications, Transportation
TLP:CLEARAnalyst: Protos AI Threat Intelligence|Period: 2026-04-01 → 2026-04-07|Sectors: Energy · Telecommunications · Transportation

Executive Summary

ATTRIBUTEVALUE
Risk LevelHIGH
ConfidenceHIGH
Key FindingIranian-affiliated actors exploited internet-exposed PLCs; CISA added Fortinet FortiClient EMS (CVE-2026-35616) to KEV — both require immediate OT owner action.
Primary ActionInventory and isolate internet-accessible PLCs; execute telemetry hunts for advisory-provided observables; apply KEV remediation per BOD 22-01.

During 2026-04-01 → 2026-04-07, authoritative agency advisories converged on two urgent themes: (1) Iranian-affiliated actors exploiting internet-exposed PLCs with TTPs that include Dropbear SSH and project-file extraction; and (2) a CISA Known Exploited Vulnerabilities (KEV) addition (CVE-2026-35616) for Fortinet FortiClient EMS requiring mandatory remediation under BOD 22-01 for federal agencies.

→ Both items materially increase near-term operational risk to owners/operators of OT and widely deployed vendor products.

Investigation Scope & Methodology

SCOPE ITEMDETAILS
FocusU.S.-based threats and advisories affecting Telecommunications, Energy, and Transportation sectors
Time Period2026-04-01 → 2026-04-07 UTC
SourcesThreat intelligence feeds, government advisories, OSINT research, sector collection artifacts, vendor advisories
MethodologyReviewed structured claims and synthesized analysis; validated findings against sector-specific collection artifacts and authoritative agency advisories

Key Findings

✓ HIGH CONFIDENCECorroborated by multiple authoritative sources
#FINDINGEVIDENCERISK
1CISA added CVE-2026-35616 (Fortinet FortiClient EMS) to the KEV catalog on 2026-04-06, requiring mandatory remediation under BOD 22-01.CISA KEV advisory and cross-sector regulatory collectionHIGH
2Joint Federal Advisory AA26-097A (FBI/CISA/NSA/DOE/EPA, 2026-04-07) documents Iranian-affiliated actors exploiting internet-exposed Rockwell/Allen-Bradley PLCs — TTPs include Dropbear SSH, remote engineering tool misuse, and project-file extraction.Joint federal advisory and energy collection artifactsHIGH
3CISA revised ICS Advisory ICSA-25-037-02 for Schneider Electric EcoStruxure (CVE-2024-2658) on 2026-04-02, adding Transportation Systems as affected sectors.CISA ICS advisory (Schneider)MEDIUM
4No confirmed U.S. telecommunications incidents identified during the 7-day window.Telecom collection and authoritative sourcesLOW
5No confirmed U.S. transportation cyber-physical incidents; international GPS/AIS disruptions did not show authoritative U.S. impact.Transportation collection and advisory searchesLOW
⚠ MEDIUM CONFIDENCESingle authoritative source or partial corroboration
  • Advisory-provided IPs (135.136.1[.]133 and 185.82.73[.]162–185.82.73[.]171) usable for telemetry correlation — investigative correlation required before blocking.
  • KEV additions and BOD 22-01 remediation introduce cross-sector operational risk during coordinated patching windows.
  • No new major telecom-vendor CVEs (Ericsson, Nokia, Cisco, Huawei) identified in-window; continued monitoring required.
  • No authoritative reports showed large-scale BES impacts from PLC exploitation; impacts localized to water and other OT owners.
? LOW CONFIDENCERequires validation

Victim counts and scale of PLC intrusions remain unverified. Telemetry enrichment (netflow, firewall, VPN, EDR) and vendor PSIRT/CSIRT disclosures are required to strengthen confidence.

Technical Analysis

VULNERABILITY ASSESSMENT

CVECVSSAFFECTED PRODUCTEXPLOITATIONFIX / ACTION
CVE-2026-35616N/AFortinet FortiClient EMSAdded to CISA KEV 2026-04-06Follow BOD 22-01 timelines; coordinate testing for availability impact
CVE-2021-22681N/ARockwell Automation Logic ControllersHistorically exploited in PLC intrusions per joint advisoryApply vendor mitigations and firmware updates where applicable
CVE-2024-26587.8Schneider Electric EcoStruxureICS advisory revised 2026-04-02; Transportation affectedApply vendor mitigations/patch; validate operational continuity

⚠ INDICATORS OF COMPROMISE (DEFANGED)

TYPEINDICATORCONTEXTRISK
IP135.136.1[.]133Advisory-provided example IP for log-hunting; correlate before blockingMED
IP Range185.82.73[.]162–185.82.73[.]171Advisory example cluster; correlate in telemetry before blockingMED

No validated malicious file hashes were published in-window by authoritative sources for U.S. incidents.

Sector Summaries

Telecommunications

Key point: No confirmed U.S. telecom incidents in-window. Salt Typhoon and other China-nexus campaigns remain relevant but were not observed in the 7-day period.

Impact: LOWConfidence: HIGH

Recommendation: Continue CVE monitoring for major vendors; plan coordinated remediation windows where Fortinet or other vendor updates are required.

Energy (OT/ICS Focus)

Key point: Joint Federal Advisory AA26-097A is actionable — internet-exposed Rockwell PLCs were exploited, enabling project-file exfiltration and HMI/SCADA manipulation.

Impact: HIGHConfidence: HIGH

Immediate Actions: Inventory internet-accessible PLCs, block direct internet access or place behind authenticated jump hosts, validate backups and physical mode switches, hunt logs for Dropbear SSH and advisory IPs.

Transportation

Key point: Transportation systems identified as affected by Schneider EcoStruxure (CVE-2024-2658). No confirmed U.S. cyber-physical incidents in-window.

Impact: MEDIUMConfidence: HIGH

Recommendation: Apply vendor mitigations for CVE-2024-2658 and perform integrity checks on affected OT components.

Cross-Sector Cascading Risk

Shared exposure: Internet-exposed PLCs and widely deployed vendor management products are a cross-sector risk vector. Actor techniques (Dropbear SSH, remote engineering tool misuse, project-file extraction) are consistent across Energy, Water, and related OT environments.

Cascading risk: KEV-driven remediation and uncoordinated patching could produce availability impacts that ripple into telecom and transport operational channels. Coordinate maintenance windows to reduce risk.

Regulatory & Compliance Alerts

ALERTDATEACTION REQUIRED
CISA KEV — CVE-2026-35616 (Fortinet FortiClient EMS)2026-04-06Federal agencies must follow BOD 22-01 timelines; non-federal owners/operators should inventory and plan remediation/testing.
Joint Federal Advisory AA26-097A (PLC exploitation)2026-04-07Immediate OT hardening: remove internet exposure, validate backups, monitor failed ports, hunt for provided IP observables.
CISA ICS Advisory ICSA-25-037-02 (Schneider EcoStruxure)2026-04-02Apply vendor mitigations for CVE-2024-2658 and validate operational continuity for transportation systems.

Recommendations & Mitigation

PRIORITY 1 — IMMEDIATE

1. Inventory and isolate internet-accessible PLCs and HMIs; block direct internet access or require authenticated jump hosts. — OT Engineering / Network Ops

2. Execute telemetry hunts for advisory-provided IPs and Dropbear SSH activity. — SOC / OT SOC

3. Apply KEV-mandated remediation for CVE-2026-35616 per BOD 22-01. — Patch Management / IT Ops

PRIORITY 2 — SHORT-TERM

1. Patch or apply vendor mitigations for Schneider EcoStruxure CVE-2024-2658 and validate system behavior.

2. Harden SSH and remote engineering endpoints: limit source IPs, enforce MFA, rotate keys, replace Dropbear where feasible.

PRIORITY 3 — LONG-TERM
  • Implement network segmentation between IT and OT; enforce jump-host/bastion-centric access for engineering sessions.
  • Maintain an asset inventory for OT devices and vendor software (Fortinet, Schneider, Rockwell) linked to patch status and maintenance windows.

DETECTION QUERIES

  • Telemetry hunts: Search netflow/firewall/VPN/EDR for connections to 135.136.1[.]133 and 185.82.73[.]162–185.82.73[.]171 within the last 90 days.
  • SSH detection: Alert on Dropbear SSH fingerprints, unauthorized SSH keys, and unusual authentication patterns to PLC jump hosts.

Evidence Gaps & Limitations

  • Victim counts & scope: Advisory text and open reporting do not provide a comprehensive, verified list of affected U.S. victim organizations within the 7-day window.
  • Telemetry correlation: Internal network/EPP/EDR telemetry was not available; enrichment required to confirm advisory IPs map to active intrusions.
  • Follow-up: Enrich advisory IPs against internal telemetry; request vendor PSIRTs for Fortinet, Rockwell, and Schneider.

Sources & References

SOURCE TYPEDESCRIPTION
Gov AdvisoryJoint Federal Advisory AA26-097A (FBI/CISA/NSA/DOE/EPA/US Cyber Command) — PLC exploitation (2026-04-07)
CISA KEVCISA KEV entry for CVE-2026-35616 (Fortinet FortiClient EMS) — added 2026-04-06
ICS AdvisoryCISA ICS Advisory ICSA-25-037-02 (Schneider EcoStruxure, CVE-2024-2658) — revised 2026-04-02
OSINT / MediaCorroborating coverage and vendor notes included in sector collection artifacts

Citations

  1. CISA added CVE-2026-35616 (Fortinet FortiClient EMS) to the Known Exploited Vulnerabilities (KEV) catalog on 2026-04-06. HIGHCISA KEV Catalog
  2. A joint federal advisory (AA26-097A) published on 2026-04-07 reports Iranian-affiliated actors exploiting internet-exposed Rockwell/Allen-Bradley PLCs across U.S. critical infrastructure. HIGHJoint Federal Advisory AA26-097A
  3. The joint advisory cites CVE-2021-22681 (Rockwell Automation Logic Controllers) as a historically exploited vulnerability relevant to the reported PLC intrusions. HIGHJoint Federal Advisory AA26-097A
  4. Observed TTPs include use of leased overseas infrastructure, Dropbear SSH backdoors, remote engineering tools, extraction of .ACD project files, and targeting of ports 44818, 2222, 102, 22, and 502. HIGHJoint Federal Advisory AA26-097A / Energy Collection Notes
  5. No confirmed U.S. telecommunications incidents (outages, intrusions, or breaches) were identified during 2026-04-01 to 2026-04-07. HIGH — Telecom Collection Summary
  6. CISA published ICS advisory ICSA-25-037-02 (Schneider Electric EcoStruxure, CVE-2024-2658) listing Transportation Systems among affected sectors. HIGHCISA ICS Advisory ICSA-25-037-02
  7. No confirmed U.S. transportation cyber-physical incidents were identified in the 2026-04-01 to 2026-04-07 window, although international OPS/AIS disruptions were reported elsewhere. HIGH — Transportation Collection Summary
  8. Authoritative sources identified shared TTPs across Energy, Water, and other sectors: targeting internet-exposed OT devices, Dropbear SSH backdoors, remote engineering tools, and project file extraction. HIGH — Cross-Sector Regulatory Collection
  9. KEV additions for widely deployed vendor products (e.g., Fortinet) and BOD 22-01 remediation actions create cross-sector operational risk and potential availability impacts during coordinated remediation windows. MEDIUM — Cross-Sector Regulatory Collection
  10. The joint advisory published example IPs associated with actor infrastructure (e.g., 135[.]136[.]11[.]33 and ranges in 185[.]82[.]73[.]x) for log-hunting and investigative use. MEDIUMJoint Federal Advisory AA26-097A
  11. No new major telecom-vendor CVEs were identified in the 2026-04-01 to 2026-04-07 window for vendors such as Ericsson, Nokia, Cisco, or Huawei. MEDIUM — Telecom Collection Summary
  12. Within the 7-day window, no authoritative sources reported large-scale impacts to the U.S. bulk electric system attributable to the PLC exploitation activity; impacts were localized to water and other OT owners. MEDIUM — Energy Collection Summary
PROTOS AI THREAT INTELLIGENCE

Generated by Protos AI · TLP:CLEAR · Weekly Brief #20 · 2026-04-07

EXPERIENCE PROTOS AI

Investigate threats like this with Protos AI.

Protos AI automates CTI investigations using agentic AI — from OSINT collection to structured analysis. Speak to our team to see it in action.