High
April 7, 2026

Weekly U.S. Critical Infrastructure Threat Brief (2026-04-01 to 2026-04-07)

Iranian-affiliated actors exploited internet-exposed Rockwell PLCs across U.S. OT environments while CISA added Fortinet FortiClient EMS (CVE-2026-35616) to the Known Exploited Vulnerabilities catalog — both elevate near-term operational risk for Energy and federal IT sectors (2026-04-01 → 2026-04-07).

Affected Sectors:Energy, Telecommunications, Transportation

TLP:CLEARAnalyst: Protos AI Threat Intelligence|Period: 2026-04-01 → 2026-04-07|Sectors: Energy · Telecommunications · Transportation

Executive Summary

ATTRIBUTEVALUERisk LevelHIGHConfidenceHIGHKey FindingIranian-affiliated actors exploited internet-exposed PLCs; CISA added Fortinet FortiClient EMS (CVE-2026-35616) to KEV — both require immediate OT owner action.Primary ActionInventory and isolate internet-accessible PLCs; execute telemetry hunts for advisory-provided observables; apply KEV remediation per BOD 22-01.

During 2026-04-01 → 2026-04-07, authoritative agency advisories converged on two urgent themes: (1) Iranian-affiliated actors exploiting internet-exposed PLCs with TTPs that include Dropbear SSH and project-file extraction; and (2) a CISA Known Exploited Vulnerabilities (KEV) addition (CVE-2026-35616) for Fortinet FortiClient EMS requiring mandatory remediation under BOD 22-01 for federal agencies.

→ Both items materially increase near-term operational risk to owners/operators of OT and widely deployed vendor products.

Investigation Scope & Methodology

SCOPE ITEMDETAILSFocusU.S.-based threats and advisories affecting Telecommunications, Energy, and Transportation sectorsTime Period2026-04-01 → 2026-04-07 UTCSourcesThreat intelligence feeds, government advisories, OSINT research, sector collection artifacts, vendor advisoriesMethodologyReviewed structured claims and synthesized analysis; validated findings against sector-specific collection artifacts and authoritative agency advisories

Key Findings

✓ HIGH CONFIDENCECorroborated by multiple authoritative sources

#FINDINGEVIDENCERISK1CISA added CVE-2026-35616 (Fortinet FortiClient EMS) to the KEV catalog on 2026-04-06, requiring mandatory remediation under BOD 22-01.CISA KEV advisory and cross-sector regulatory collectionHIGH2Joint Federal Advisory AA26-097A (FBI/CISA/NSA/DOE/EPA, 2026-04-07) documents Iranian-affiliated actors exploiting internet-exposed Rockwell/Allen-Bradley PLCs — TTPs include Dropbear SSH, remote engineering tool misuse, and project-file extraction.Joint federal advisory and energy collection artifactsHIGH3CISA revised ICS Advisory ICSA-25-037-02 for Schneider Electric EcoStruxure (CVE-2024-2658) on 2026-04-02, adding Transportation Systems as affected sectors.CISA ICS advisory (Schneider)MEDIUM4No confirmed U.S. telecommunications incidents identified during the 7-day window.Telecom collection and authoritative sourcesLOW5No confirmed U.S. transportation cyber-physical incidents; international GPS/AIS disruptions did not show authoritative U.S. impact.Transportation collection and advisory searchesLOW

⚠ MEDIUM CONFIDENCESingle authoritative source or partial corroboration

? LOW CONFIDENCERequires validation

Victim counts and scale of PLC intrusions remain unverified. Telemetry enrichment (netflow, firewall, VPN, EDR) and vendor PSIRT/CSIRT disclosures are required to strengthen confidence.

Technical Analysis

VULNERABILITY ASSESSMENT

CVECVSSAFFECTED PRODUCTEXPLOITATIONFIX / ACTIONCVE-2026-35616N/AFortinet FortiClient EMSAdded to CISA KEV 2026-04-06Follow BOD 22-01 timelines; coordinate testing for availability impactCVE-2021-22681N/ARockwell Automation Logic ControllersHistorically exploited in PLC intrusions per joint advisoryApply vendor mitigations and firmware updates where applicableCVE-2024-26587.8Schneider Electric EcoStruxureICS advisory revised 2026-04-02; Transportation affectedApply vendor mitigations/patch; validate operational continuity

⚠ INDICATORS OF COMPROMISE (DEFANGED)

TYPEINDICATORCONTEXTRISKIP135.136.1[.]133Advisory-provided example IP for log-hunting; correlate before blockingMEDIP Range185.82.73[.]162–185.82.73[.]171Advisory example cluster; correlate in telemetry before blockingMED

No validated malicious file hashes were published in-window by authoritative sources for U.S. incidents.

Sector Summaries

Telecommunications

Key point: No confirmed U.S. telecom incidents in-window. Salt Typhoon and other China-nexus campaigns remain relevant but were not observed in the 7-day period.

Impact: LOWConfidence: HIGH

Recommendation: Continue CVE monitoring for major vendors; plan coordinated remediation windows where Fortinet or other vendor updates are required.

Energy (OT/ICS Focus)

Key point: Joint Federal Advisory AA26-097A is actionable — internet-exposed Rockwell PLCs were exploited, enabling project-file exfiltration and HMI/SCADA manipulation.

Impact: HIGHConfidence: HIGH

Immediate Actions: Inventory internet-accessible PLCs, block direct internet access or place behind authenticated jump hosts, validate backups and physical mode switches, hunt logs for Dropbear SSH and advisory IPs.

Transportation

Key point: Transportation systems identified as affected by Schneider EcoStruxure (CVE-2024-2658). No confirmed U.S. cyber-physical incidents in-window.

Impact: MEDIUMConfidence: HIGH

Recommendation: Apply vendor mitigations for CVE-2024-2658 and perform integrity checks on affected OT components.

Cross-Sector Cascading Risk

Shared exposure: Internet-exposed PLCs and widely deployed vendor management products are a cross-sector risk vector. Actor techniques (Dropbear SSH, remote engineering tool misuse, project-file extraction) are consistent across Energy, Water, and related OT environments.

Cascading risk: KEV-driven remediation and uncoordinated patching could produce availability impacts that ripple into telecom and transport operational channels. Coordinate maintenance windows to reduce risk.

Regulatory & Compliance Alerts

ALERTDATEACTION REQUIREDCISA KEV — CVE-2026-35616 (Fortinet FortiClient EMS)2026-04-06Federal agencies must follow BOD 22-01 timelines; non-federal owners/operators should inventory and plan remediation/testing.Joint Federal Advisory AA26-097A (PLC exploitation)2026-04-07Immediate OT hardening: remove internet exposure, validate backups, monitor failed ports, hunt for provided IP observables.CISA ICS Advisory ICSA-25-037-02 (Schneider EcoStruxure)2026-04-02Apply vendor mitigations for CVE-2024-2658 and validate operational continuity for transportation systems.

Recommendations & Mitigation

PRIORITY 1 — IMMEDIATE

1. Inventory and isolate internet-accessible PLCs and HMIs; block direct internet access or require authenticated jump hosts. — OT Engineering / Network Ops

2. Execute telemetry hunts for advisory-provided IPs and Dropbear SSH activity. — SOC / OT SOC

3. Apply KEV-mandated remediation for CVE-2026-35616 per BOD 22-01. — Patch Management / IT Ops

PRIORITY 2 — SHORT-TERM

1. Patch or apply vendor mitigations for Schneider EcoStruxure CVE-2024-2658 and validate system behavior.

2. Harden SSH and remote engineering endpoints: limit source IPs, enforce MFA, rotate keys, replace Dropbear where feasible.

PRIORITY 3 — LONG-TERM

DETECTION QUERIES

Evidence Gaps & Limitations

Sources & References

SOURCE TYPEDESCRIPTIONGov AdvisoryJoint Federal Advisory AA26-097A (FBI/CISA/NSA/DOE/EPA/US Cyber Command) — PLC exploitation (2026-04-07)CISA KEVCISA KEV entry for CVE-2026-35616 (Fortinet FortiClient EMS) — added 2026-04-06ICS AdvisoryCISA ICS Advisory ICSA-25-037-02 (Schneider EcoStruxure, CVE-2024-2658) — revised 2026-04-02OSINT / MediaCorroborating coverage and vendor notes included in sector collection artifacts

Citations

  1. CISA added CVE-2026-35616 (Fortinet FortiClient EMS) to the Known Exploited Vulnerabilities (KEV) catalog on 2026-04-06. HIGHCISA KEV Catalog
  2. A joint federal advisory (AA26-097A) published on 2026-04-07 reports Iranian-affiliated actors exploiting internet-exposed Rockwell/Allen-Bradley PLCs across U.S. critical infrastructure. HIGHJoint Federal Advisory AA26-097A
  3. The joint advisory cites CVE-2021-22681 (Rockwell Automation Logic Controllers) as a historically exploited vulnerability relevant to the reported PLC intrusions. HIGHJoint Federal Advisory AA26-097A
  4. Observed TTPs include use of leased overseas infrastructure, Dropbear SSH backdoors, remote engineering tools, extraction of .ACD project files, and targeting of ports 44818, 2222, 102, 22, and 502. HIGHJoint Federal Advisory AA26-097A / Energy Collection Notes
  5. No confirmed U.S. telecommunications incidents (outages, intrusions, or breaches) were identified during 2026-04-01 to 2026-04-07. HIGH — Telecom Collection Summary
  6. CISA published ICS advisory ICSA-25-037-02 (Schneider Electric EcoStruxure, CVE-2024-2658) listing Transportation Systems among affected sectors. HIGHCISA ICS Advisory ICSA-25-037-02
  7. No confirmed U.S. transportation cyber-physical incidents were identified in the 2026-04-01 to 2026-04-07 window, although international OPS/AIS disruptions were reported elsewhere. HIGH — Transportation Collection Summary
  8. Authoritative sources identified shared TTPs across Energy, Water, and other sectors: targeting internet-exposed OT devices, Dropbear SSH backdoors, remote engineering tools, and project file extraction. HIGH — Cross-Sector Regulatory Collection
  9. KEV additions for widely deployed vendor products (e.g., Fortinet) and BOD 22-01 remediation actions create cross-sector operational risk and potential availability impacts during coordinated remediation windows. MEDIUM — Cross-Sector Regulatory Collection
  10. The joint advisory published example IPs associated with actor infrastructure (e.g., 135[.]136[.]11[.]33 and ranges in 185[.]82[.]73[.]x) for log-hunting and investigative use. MEDIUMJoint Federal Advisory AA26-097A
  11. No new major telecom-vendor CVEs were identified in the 2026-04-01 to 2026-04-07 window for vendors such as Ericsson, Nokia, Cisco, or Huawei. MEDIUM — Telecom Collection Summary
  12. Within the 7-day window, no authoritative sources reported large-scale impacts to the U.S. bulk electric system attributable to the PLC exploitation activity; impacts were localized to water and other OT owners. MEDIUM — Energy Collection Summary

PROTOS AI THREAT INTELLIGENCE

Generated by Protos AI · TLP:CLEAR · Weekly Brief #20 · 2026-04-07

EXPERIENCE PROTOS AI

Investigate threats like this with Protos AI.

Protos AI automates CTI investigations using agentic AI — from OSINT collection to structured analysis. Speak to our team to see it in action.