CISA hosts Cyber Storm X national cybersecurity exercise
Public Sector Action
Summary
Hide ▲
Show ▼
CISA hosted Cyber Storm X, a four-day national cybersecurity exercise that tested response readiness for critical infrastructure across the public and private sectors. The exercise drew 2,000 participants and marked the tenth Cyber Storm in the program’s 20-year history. It centered on a nation-state adversary scenario involving rail, ports, water, and wastewater systems. CISA plans to publish a public after-action report with lessons learned.
Related Happenings
CISA launches ANCHOR-CI critical infrastructure advisory framework
Public Sector Action
H score28
First: 01.07.2026 15:00
Last: 01.07.2026 15:00
Sources 1
About this happening:
CISA announced ANCHOR-CI, a new advisory-body framework that expands information sharing and public-private coordination for critical infrastructure security and r...
CISA launches ANCHOR-CI critical infrastructure advisory framework
Public Sector ActionAbout this happening: CISA announced ANCHOR-CI, a new advisory-body framework that expands information sharing and public-private coordination for critical infrastructure security and r...
CISA launches KEV Nomination Form
Public Sector Action
H score38
First: 21.05.2026 15:00
Last: 21.05.2026 15:00
Sources 1
About this happening:
CISA launched a new Nomination Form for the KEV catalog, giving researchers, vendors, and industry partners a direct way to report known exploited vulnerabilities....
CISA launches KEV Nomination Form
Public Sector ActionAbout this happening: CISA launched a new Nomination Form for the KEV catalog, giving researchers, vendors, and industry partners a direct way to report known exploited vulnerabilities....
CISA releases CI Fortify guidance for critical infrastructure resilience
Public Sector Action
H score29
First: 05.05.2026 15:00
Last: 05.05.2026 15:00
Sources 1
About this happening:
CISA released CI Fortify, guidance for critical infrastructure operators across sectors to help keep essential services running during cyberattack or crisis conditions. The framew...
CISA releases CI Fortify guidance for critical infrastructure resilience
Public Sector ActionAbout this happening: CISA released CI Fortify, guidance for critical infrastructure operators across sectors to help keep essential services running during cyberattack or crisis conditions. The framew...
Latest development: 06.05.2026 16:15
CISA launched CI Fortify on Tuesday as a planning framework for critical infrastructure operators in water, energy, transportation and communications to prepare for cyber disruption by disconnecting OT systems from third-party and business networks, maintaining essential services in degraded communications conditions, and recovering compromised systems through backups, component replacement, or a transition to manual operations.
Iranian-affiliated US CNI OT attack campaign
Campaign
H score33
First: 08.04.2026 11:15
Last: 08.04.2026 11:15
Sources 1
About this happening:
An Iranian-affiliated campaign is targeting internet-exposed industrial systems at US critical infrastructure organizations, with activity seen against Rockwell Auto...
Iranian-affiliated US CNI OT attack campaign
CampaignAbout this happening: An Iranian-affiliated campaign is targeting internet-exposed industrial systems at US critical infrastructure organizations, with activity seen against Rockwell Auto...
Iranian-linked PLC targeting campaign against U.S. critical infrastructure
Campaign
H score38
First: 07.04.2026 21:02
Last: 07.04.2026 21:02
Sources 1
About this happening:
Iran-affiliated cyber threat actors are targeting internet-exposed PLCs in U.S. critical infrastructure, with the campaign active since March 2026. A joint advis...
Iranian-linked PLC targeting campaign against U.S. critical infrastructure
CampaignAbout this happening: Iran-affiliated cyber threat actors are targeting internet-exposed PLCs in U.S. critical infrastructure, with the campaign active since March 2026. A joint advis...
Latest development: 19.08.2026 20:50
The NSA, CISA, FBI, Department of Energy, and Environmental Protection Agency issued a joint advisory about ongoing attacks against Siemens S7 Series programmable logic controllers (PLCs) in U.S. critical infrastructure. Threat actors are using Censys and ZoomEye to identify exposed Siemens PLCs and are generating Python exploitation scripts with snap7.dll and python-snap7 to communicate with Siemens S7 devices over S7comm, enabling read and write access to PLC memory, configuration data, and ladder logic programs; the activity is framed as persistent reconnaissance that could precede disruption, data theft, equipment damage, extended downtime, or safety incidents.
Timeline
-
18.09.2026 15:00 2 articles · 11h ago
CISA hosts Cyber Storm X national cybersecurity exercise
Industry Or Public Sector UpdateCISA hosted Cyber Storm X in Washington, DC, a four-day national cybersecurity exercise with 2,000 participants from public and private sectors to practice response to a major cyber incident affecting critical infrastructure. The scenario simulated a nation-state adversary targeting transportation systems, including rail and ports, and water and wastewater systems, and CISA said it will use the findings in a public after-action report.
Show sources
- CISA Hosts Cyber Storm X, Nationwide Cybersecurity Exercise to Strengthen Resilience — www.cisa.gov — 18.09.2026 15:00
- CISA Hosts Cyber Storm X, Nationwide Cybersecurity Exercise to Strengthen Resilience — www.cisa.gov — 18.09.2026 15:00