WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home Posts CISA Alert: Iran-based Threat Actor Exploits VPN Vulnerabilities
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Community Partners
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

CISA Alert: Iran-based Threat Actor Exploits VPN Vulnerabilities

Author: Charles Egli

Created: Tuesday, September 15, 2020 - 16:48

Categories: Cybersecurity

The U.S. Department of Homeland Security Cybersecurity and Infrastructure Security Agency (CISA) has published a new alert about an Iran-based malicious cyber actor targeting several U.S. federal agencies and other U.S.-based networks. CISA developed the alert with contributions from the FBI. According to the alert, the threat actor was observed exploiting publicly known Common Vulnerabilities and Exposures (CVEs) dealing with Pulse Secure virtual private network (VPN), Citrix NetScaler, and F5 to gain initial access to targeted networks. Once inside a successfully exploited network, the actor’s goals appear to be maintaining access for several months using multiple means of persistence and exfiltrating data. The alert contains further technical details of the activity, including techniques categorized by the MITRE ATT&CK framework, as well as a list of mitigation measures. CISA has also issued a Malware Analysis Report (MAR-10297887-1.v1) that details some of the tools this threat actor used against some victims. CISA recommends that network administrators use the information in these products to identify a potential compromise of their network, reduce exposure to Iranian government malicious cyber activity and protect their organization from future attacks. Read the alert at CISA.

Related Resources

Members Only

(TLP:AMBER+STRICT) Situation Report: Heightened Threat Environment – Potential Retaliation by Iranian Threat Actors Following U.S. Strikes on Iran (Updated June 18, 2026)

Jun 18, 2026 in Cybersecurity, OT-ICS Security, Physical Security, Security Preparedness
Members Only

(TLP:AMBER) IOC Associated with Volt Typhoon Performed Network Enumeration on Utah Infrastructure

Jun 18, 2026 in Cybersecurity, Federal & State Resources, Security Preparedness

(TLP:CLEAR) Email Impersonation Remains a Persistent Risk for Water Utilities

Jun 18, 2026 in Cybersecurity, Security Preparedness

Become a Member
FAQs
About
Report Incident
Traffic Light Protocol (TLP)

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar