TLP:CLEARAnalyst: Protos AI Threat Intelligence|Period: 2026-04-01 → 2026-04-07|Sectors: Energy · Telecommunications · Transportation
Executive Summary
ATTRIBUTEVALUERisk LevelHIGHConfidenceHIGHKey FindingIranian-affiliated actors exploited internet-exposed PLCs; CISA added Fortinet FortiClient EMS (CVE-2026-35616) to KEV — both require immediate OT owner action.Primary ActionInventory and isolate internet-accessible PLCs; execute telemetry hunts for advisory-provided observables; apply KEV remediation per BOD 22-01.
During 2026-04-01 → 2026-04-07, authoritative agency advisories converged on two urgent themes: (1) Iranian-affiliated actors exploiting internet-exposed PLCs with TTPs that include Dropbear SSH and project-file extraction; and (2) a CISA Known Exploited Vulnerabilities (KEV) addition (CVE-2026-35616) for Fortinet FortiClient EMS requiring mandatory remediation under BOD 22-01 for federal agencies.
→ Both items materially increase near-term operational risk to owners/operators of OT and widely deployed vendor products.
Investigation Scope & Methodology
SCOPE ITEMDETAILSFocusU.S.-based threats and advisories affecting Telecommunications, Energy, and Transportation sectorsTime Period2026-04-01 → 2026-04-07 UTCSourcesThreat intelligence feeds, government advisories, OSINT research, sector collection artifacts, vendor advisoriesMethodologyReviewed structured claims and synthesized analysis; validated findings against sector-specific collection artifacts and authoritative agency advisories
Key Findings
✓ HIGH CONFIDENCECorroborated by multiple authoritative sources
#FINDINGEVIDENCERISK1CISA added CVE-2026-35616 (Fortinet FortiClient EMS) to the KEV catalog on 2026-04-06, requiring mandatory remediation under BOD 22-01.CISA KEV advisory and cross-sector regulatory collectionHIGH2Joint Federal Advisory AA26-097A (FBI/CISA/NSA/DOE/EPA, 2026-04-07) documents Iranian-affiliated actors exploiting internet-exposed Rockwell/Allen-Bradley PLCs — TTPs include Dropbear SSH, remote engineering tool misuse, and project-file extraction.Joint federal advisory and energy collection artifactsHIGH3CISA revised ICS Advisory ICSA-25-037-02 for Schneider Electric EcoStruxure (CVE-2024-2658) on 2026-04-02, adding Transportation Systems as affected sectors.CISA ICS advisory (Schneider)MEDIUM4No confirmed U.S. telecommunications incidents identified during the 7-day window.Telecom collection and authoritative sourcesLOW5No confirmed U.S. transportation cyber-physical incidents; international GPS/AIS disruptions did not show authoritative U.S. impact.Transportation collection and advisory searchesLOW
⚠ MEDIUM CONFIDENCESingle authoritative source or partial corroboration
- Advisory-provided IPs (135.136.1[.]133 and 185.82.73[.]162–185.82.73[.]171) usable for telemetry correlation — investigative correlation required before blocking.
- KEV additions and BOD 22-01 remediation introduce cross-sector operational risk during coordinated patching windows.
- No new major telecom-vendor CVEs (Ericsson, Nokia, Cisco, Huawei) identified in-window; continued monitoring required.
- No authoritative reports showed large-scale BES impacts from PLC exploitation; impacts localized to water and other OT owners.
? LOW CONFIDENCERequires validation
Victim counts and scale of PLC intrusions remain unverified. Telemetry enrichment (netflow, firewall, VPN, EDR) and vendor PSIRT/CSIRT disclosures are required to strengthen confidence.
Technical Analysis
VULNERABILITY ASSESSMENT
CVECVSSAFFECTED PRODUCTEXPLOITATIONFIX / ACTIONCVE-2026-35616N/AFortinet FortiClient EMSAdded to CISA KEV 2026-04-06Follow BOD 22-01 timelines; coordinate testing for availability impactCVE-2021-22681N/ARockwell Automation Logic ControllersHistorically exploited in PLC intrusions per joint advisoryApply vendor mitigations and firmware updates where applicableCVE-2024-26587.8Schneider Electric EcoStruxureICS advisory revised 2026-04-02; Transportation affectedApply vendor mitigations/patch; validate operational continuity
⚠ INDICATORS OF COMPROMISE (DEFANGED)
TYPEINDICATORCONTEXTRISKIP135.136.1[.]133Advisory-provided example IP for log-hunting; correlate before blockingMEDIP Range185.82.73[.]162–185.82.73[.]171Advisory example cluster; correlate in telemetry before blockingMED
No validated malicious file hashes were published in-window by authoritative sources for U.S. incidents.
Sector Summaries
Telecommunications
Key point: No confirmed U.S. telecom incidents in-window. Salt Typhoon and other China-nexus campaigns remain relevant but were not observed in the 7-day period.
Impact: LOWConfidence: HIGH
Recommendation: Continue CVE monitoring for major vendors; plan coordinated remediation windows where Fortinet or other vendor updates are required.
Energy (OT/ICS Focus)
Key point: Joint Federal Advisory AA26-097A is actionable — internet-exposed Rockwell PLCs were exploited, enabling project-file exfiltration and HMI/SCADA manipulation.
Impact: HIGHConfidence: HIGH
Immediate Actions: Inventory internet-accessible PLCs, block direct internet access or place behind authenticated jump hosts, validate backups and physical mode switches, hunt logs for Dropbear SSH and advisory IPs.
Transportation
Key point: Transportation systems identified as affected by Schneider EcoStruxure (CVE-2024-2658). No confirmed U.S. cyber-physical incidents in-window.
Impact: MEDIUMConfidence: HIGH
Recommendation: Apply vendor mitigations for CVE-2024-2658 and perform integrity checks on affected OT components.
Cross-Sector Cascading Risk
Shared exposure: Internet-exposed PLCs and widely deployed vendor management products are a cross-sector risk vector. Actor techniques (Dropbear SSH, remote engineering tool misuse, project-file extraction) are consistent across Energy, Water, and related OT environments.
Cascading risk: KEV-driven remediation and uncoordinated patching could produce availability impacts that ripple into telecom and transport operational channels. Coordinate maintenance windows to reduce risk.
Regulatory & Compliance Alerts
ALERTDATEACTION REQUIREDCISA KEV — CVE-2026-35616 (Fortinet FortiClient EMS)2026-04-06Federal agencies must follow BOD 22-01 timelines; non-federal owners/operators should inventory and plan remediation/testing.Joint Federal Advisory AA26-097A (PLC exploitation)2026-04-07Immediate OT hardening: remove internet exposure, validate backups, monitor failed ports, hunt for provided IP observables.CISA ICS Advisory ICSA-25-037-02 (Schneider EcoStruxure)2026-04-02Apply vendor mitigations for CVE-2024-2658 and validate operational continuity for transportation systems.
Recommendations & Mitigation
PRIORITY 1 — IMMEDIATE
1. Inventory and isolate internet-accessible PLCs and HMIs; block direct internet access or require authenticated jump hosts. — OT Engineering / Network Ops
2. Execute telemetry hunts for advisory-provided IPs and Dropbear SSH activity. — SOC / OT SOC
3. Apply KEV-mandated remediation for CVE-2026-35616 per BOD 22-01. — Patch Management / IT Ops
PRIORITY 2 — SHORT-TERM
1. Patch or apply vendor mitigations for Schneider EcoStruxure CVE-2024-2658 and validate system behavior.
2. Harden SSH and remote engineering endpoints: limit source IPs, enforce MFA, rotate keys, replace Dropbear where feasible.
PRIORITY 3 — LONG-TERM
- Implement network segmentation between IT and OT; enforce jump-host/bastion-centric access for engineering sessions.
- Maintain an asset inventory for OT devices and vendor software (Fortinet, Schneider, Rockwell) linked to patch status and maintenance windows.
DETECTION QUERIES
- Telemetry hunts: Search netflow/firewall/VPN/EDR for connections to 135.136.1[.]133 and 185.82.73[.]162–185.82.73[.]171 within the last 90 days.
- SSH detection: Alert on Dropbear SSH fingerprints, unauthorized SSH keys, and unusual authentication patterns to PLC jump hosts.
Evidence Gaps & Limitations
- Victim counts & scope: Advisory text and open reporting do not provide a comprehensive, verified list of affected U.S. victim organizations within the 7-day window.
- Telemetry correlation: Internal network/EPP/EDR telemetry was not available; enrichment required to confirm advisory IPs map to active intrusions.
- Follow-up: Enrich advisory IPs against internal telemetry; request vendor PSIRTs for Fortinet, Rockwell, and Schneider.
Sources & References
SOURCE TYPEDESCRIPTIONGov AdvisoryJoint Federal Advisory AA26-097A (FBI/CISA/NSA/DOE/EPA/US Cyber Command) — PLC exploitation (2026-04-07)CISA KEVCISA KEV entry for CVE-2026-35616 (Fortinet FortiClient EMS) — added 2026-04-06ICS AdvisoryCISA ICS Advisory ICSA-25-037-02 (Schneider EcoStruxure, CVE-2024-2658) — revised 2026-04-02OSINT / MediaCorroborating coverage and vendor notes included in sector collection artifacts
Citations
- CISA added CVE-2026-35616 (Fortinet FortiClient EMS) to the Known Exploited Vulnerabilities (KEV) catalog on 2026-04-06. HIGH — CISA KEV Catalog
- A joint federal advisory (AA26-097A) published on 2026-04-07 reports Iranian-affiliated actors exploiting internet-exposed Rockwell/Allen-Bradley PLCs across U.S. critical infrastructure. HIGH — Joint Federal Advisory AA26-097A
- The joint advisory cites CVE-2021-22681 (Rockwell Automation Logic Controllers) as a historically exploited vulnerability relevant to the reported PLC intrusions. HIGH — Joint Federal Advisory AA26-097A
- Observed TTPs include use of leased overseas infrastructure, Dropbear SSH backdoors, remote engineering tools, extraction of
.ACD project files, and targeting of ports 44818, 2222, 102, 22, and 502. HIGH — Joint Federal Advisory AA26-097A / Energy Collection Notes - No confirmed U.S. telecommunications incidents (outages, intrusions, or breaches) were identified during 2026-04-01 to 2026-04-07. HIGH — Telecom Collection Summary
- CISA published ICS advisory ICSA-25-037-02 (Schneider Electric EcoStruxure, CVE-2024-2658) listing Transportation Systems among affected sectors. HIGH — CISA ICS Advisory ICSA-25-037-02
- No confirmed U.S. transportation cyber-physical incidents were identified in the 2026-04-01 to 2026-04-07 window, although international OPS/AIS disruptions were reported elsewhere. HIGH — Transportation Collection Summary
- Authoritative sources identified shared TTPs across Energy, Water, and other sectors: targeting internet-exposed OT devices, Dropbear SSH backdoors, remote engineering tools, and project file extraction. HIGH — Cross-Sector Regulatory Collection
- KEV additions for widely deployed vendor products (e.g., Fortinet) and BOD 22-01 remediation actions create cross-sector operational risk and potential availability impacts during coordinated remediation windows. MEDIUM — Cross-Sector Regulatory Collection
- The joint advisory published example IPs associated with actor infrastructure (e.g.,
135[.]136[.]11[.]33 and ranges in 185[.]82[.]73[.]x) for log-hunting and investigative use. MEDIUM — Joint Federal Advisory AA26-097A - No new major telecom-vendor CVEs were identified in the 2026-04-01 to 2026-04-07 window for vendors such as Ericsson, Nokia, Cisco, or Huawei. MEDIUM — Telecom Collection Summary
- Within the 7-day window, no authoritative sources reported large-scale impacts to the U.S. bulk electric system attributable to the PLC exploitation activity; impacts were localized to water and other OT owners. MEDIUM — Energy Collection Summary
PROTOS AI THREAT INTELLIGENCE
Generated by Protos AI · TLP:CLEAR · Weekly Brief #20 · 2026-04-07