<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"><channel><title>News Agent — Energy &amp; Utilities</title><link>/industries/energy-utilities/</link><description>Cyber threat intelligence for the Energy &amp; Utilities industry — daily-brief items tagged to this slice.</description><item><title>Iran continues broadening US infrastructure attack surface as Handala/CyberAv3ngers escalation carries into September; the pattern is delibe</title><link>/briefings/2026/09/04/2026-09-04/</link><guid isPermaLink="false">2026-09-04-Iran continues broadening US infrastructure attack surface a</guid><pubDate>Fri, 04 Sep 2026 06:00:00 +0000</pubDate><description>Iran continues broadening US infrastructure attack surface as Handala/CyberAv3ngers escalation carries into September; the pattern is deliberate coercion calibration, not escalation toward kinetic response. No material new Handala operation in the Sep 3–4 window, but the operational baseline from prior weeks continues: water, energy, and telecom intrusion attempts documented at a sustained pace. Iran&#x27;s strategic posture — keep attacks disruptive enough to signal resolve without triggering a formal US cyber-war declaration — is consistent with coercion theory: the goal is not to cause catastrophic failure but to impose ongoing friction costs that accumulate without reaching the threshold requiring a proportionate US response. The Sep 2 joint assessment from The National summarizing FBI/IC reporting is the clearest statement of this calculus to date. The National · Unit 42 [🌍 GEOPOLITICS]</description></item><item><title>Iran OT/ICS threat: EPA, FBI, CISA, NSA joint advisory on Iranian-affiliated PLC exploitation remains active; attacks escalating in Septembe</title><link>/briefings/2026/09/03/2026-09-03/</link><guid isPermaLink="false">2026-09-03-Iran OT/ICS threat: EPA, FBI, CISA, NSA joint advisory on Ir</guid><pubDate>Thu, 03 Sep 2026 06:00:00 +0000</pubDate><description>Iran OT/ICS threat: EPA, FBI, CISA, NSA joint advisory on Iranian-affiliated PLC exploitation remains active; attacks escalating in September — The joint advisory (CISA/FBI/EPA/NSA on Iranian-affiliated cyber actors targeting US PLCs and HMIs in water and energy sectors) published earlier in 2026 remains current; Iranian-linked cyber activity against US critical infrastructure has escalated in September following continued US/Israeli military strikes on IRGC targets. The FBI has observed ICS intrusion attempts specifically aimed at causing operational disruption rather than data theft. Water, energy, and telecom operators should verify that any internet-facing OT/ICS components are firewalled from production networks. CISA Advisory aa26-097a · TechCrunch [🚨 INTELLIGENCE AGENCY ALERTS &amp; POLICY]</description></item><item><title>Iran-nexus Handala</title><link>/briefings/2026/09/03/2026-09-03/</link><guid isPermaLink="false">2026-09-03-Iran-nexus Handala</guid><pubDate>Thu, 03 Sep 2026 06:00:00 +0000</pubDate><description>Iran-nexus Handala — escalating destructive operations against US and allied infrastructure in September; attacks on water, energy, and telecom confirmed; cyber dimension of the Iran-US military conflict — In direct response to US and Israeli strikes on IRGC targets since February 2026, Iran-linked hacktivist group Handala (assessed MOIS-affiliated) has intensified attacks on US critical infrastructure through August-September 2026. Recent confirmed or claimed operations include: California Water Service data exfiltration claim (5GB database and GPS network files); coordinated OT/PLC disruption at 30+ Minnesota water utilities (Jul 26, attributed to CyberAv3ngers/IRGC CEC, already in database); Stryker Corporation MDM wiper attack (Mar 11, 200,000+ devices wiped via Microsoft Intune abuse, 56,000 employees idled in 61 countries). As of Sep 2, reporting indicates Iranian actors have broadened targeting to US telecom and energy infrastructure. No new named victim disclosed in the Sep 2–3 window beyond prior runs. The National · NBC News [🌐 THREAT ACTOR &amp; CAMPAIGN ACTIVITY]</description></item><item><title>Iran has opened the broadest cyber offensive against US infrastructure since the 2026 war began, targeting water, energy, and telecom simult</title><link>/briefings/2026/09/03/2026-09-03/</link><guid isPermaLink="false">2026-09-03-Iran has opened the broadest cyber offensive against US infr</guid><pubDate>Thu, 03 Sep 2026 06:00:00 +0000</pubDate><description>Iran has opened the broadest cyber offensive against US infrastructure since the 2026 war began, targeting water, energy, and telecom simultaneously — a deliberate expansion from targeted harassment to systemic disruption. The Feb-Sep 2026 escalation arc runs from FBI Director Patel&#x27;s personal email compromise (March) through Stryker&#x27;s MDM wiper (March, 200K devices), California Water Service exfiltration (June), and now multi-sector infrastructure disruption. Handala and CyberAv3ngers are not independent hacktivist groups — both are assessed as proxies for MOIS and the IRGC Cyber Electronic Command respectively. The strategic logic is coercion symmetry: US/Israeli kinetic strikes on IRGC targets are being answered with non-kinetic disruption of American critical infrastructure at a tempo calibrated to stay below the threshold of a formal cyber-war declaration. The National · CSIS [🌍 GEOPOLITICS]</description></item><item><title>Iran&#x27;s pre-positioning in Qatari LNG infrastructure, flagged in August 31 briefing, should be read alongside the PaperCut and ServiceNow vul</title><link>/briefings/2026/09/02/2026-09-02/</link><guid isPermaLink="false">2026-09-02-Iran&#x27;s pre-positioning in Qatari LNG infrastructure, flagged</guid><pubDate>Wed, 02 Sep 2026 06:00:00 +0000</pubDate><description>Iran&#x27;s pre-positioning in Qatari LNG infrastructure, flagged in August 31 briefing, should be read alongside the PaperCut and ServiceNow vulnerability windows: a threat actor with pre-positioned access to OT adjacent networks in LNG terminals would exploit a print-management or ITSM zero-day as a lateral-movement vector, not as a primary target. PaperCut and ServiceNow are both deployed at energy companies and OT-adjacent corporate environments; unpatched instances in those sectors this week represent potential stepping-stone access paths into operational technology networks, not just data-exfiltration risks. CSIS · Canadian Centre for Cyber Security [🌍 GEOPOLITICS]</description></item></channel></rss>
