Following President Donald Trump’s threats to bomb Iranian power plants and bridges, a group of federal security agencies warned Tuesday that affiliates of the Persian Gulf nation are targeting U.S. critical infrastructure. Water, wastewater and energy systems are all part of an ongoing cyber exploitation of internet-connected devices involved with industrial automation processes, according to a multi-agency cybersecurity advisory. “Iran-affiliated cyber actors are targeting operational technology devices across U.S. critical infrastructure, including programmable logic controllers,” the FBI Cyber Division wrote on X on Tuesday. The post urged municipalities and those in the water and energy sectors to review their tactics, techniques and procedures for detecting if their systems have been compromised and to apply recommended mitigations. Iranian-affiliated “targeting campaigns against U.S. organizations have recently escalated, likely in response to hostilities between Iran, and the United States and Israel,” according to the joint advisory from the FBI, Cybersecurity and Infrastructure Security Agency, National Security Agency, Environmental Protection Agency, Department of Energy and U.S. Cyber Command. The advisory said the agencies have observed threat actors affiliated with Iran using overseas-based IP addresses to access internet-enabled industrial computers to intentionally cause disruptions. They said the threat actors are exploiting leased computer controls and software systems made by Rockwell Automation and its subsidiary Allen-Bradley to extract the devices’ project files and alter data displays. To prevent attacks, the agencies recommend the devices be immediately disconnected from public-facing internet systems to ensure access is controlled and to take follow-up steps such as adding multifactor authentication and other firewalls to control access. On Tuesday, Microsoft also said a cybersecurity threat actor linked with the Russian military known as Forest Blizzard has been compromising home and small-office internet equipment, including routers. The tech giant said the threat actor modifies settings to turn equipment into malicious infrastructure that