WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home Community Partnerships CISA Alert: Iran-based Threat Actor Exploits VPN Vulnerabilities
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Directory
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

CISA Alert: Iran-based Threat Actor Exploits VPN Vulnerabilities

Author: Charles Egli

Created: Tuesday, September 15, 2020 - 16:48

Categories: Cybersecurity

The U.S. Department of Homeland Security Cybersecurity and Infrastructure Security Agency (CISA) has published a new alert about an Iran-based malicious cyber actor targeting several U.S. federal agencies and other U.S.-based networks. CISA developed the alert with contributions from the FBI. According to the alert, the threat actor was observed exploiting publicly known Common Vulnerabilities and Exposures (CVEs) dealing with Pulse Secure virtual private network (VPN), Citrix NetScaler, and F5 to gain initial access to targeted networks. Once inside a successfully exploited network, the actor’s goals appear to be maintaining access for several months using multiple means of persistence and exfiltrating data. The alert contains further technical details of the activity, including techniques categorized by the MITRE ATT&CK framework, as well as a list of mitigation measures. CISA has also issued a Malware Analysis Report (MAR-10297887-1.v1) that details some of the tools this threat actor used against some victims. CISA recommends that network administrators use the information in these products to identify a potential compromise of their network, reduce exposure to Iranian government malicious cyber activity and protect their organization from future attacks. Read the alert at CISA.

Related Resources

Members Only

(TLP:AMBER+STRICT) Situation Report: Heightened Threat Environment – Potential Retaliation by Iranian Threat Actors Following U.S. Strikes on Iran (Updated May 1, 2026)

May 1, 2026 in Cybersecurity, OT-ICS Security, Physical Security, Security Preparedness

Tip of the Week – April 30, 2026

Apr 30, 2026 in Cybersecurity, Security Preparedness

(TLP:CLEAR) Cyber Readiness Institute Joins WaterISAC as a Community Partner to Strengthen Cyber Readiness Across the Water Sector

Apr 30, 2026 in Cybersecurity, Security Preparedness

Become a Member
FAQs
About
Report Incident

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar