Exchange and Fortinet Footholds Reach Industrial Control Networks

The risk is not the initial foothold. It is the jump from ordinary enterprise systems into industrial control networks, including PLCs tied to water and wastewater. A compromised Exchange or Fortinet asset can become the bridge into OT, so an IT-only view misses the real blast radius. The CRS report ties Iran-linked activity through 2025 to infrastructure targets across telecommunications, defense, energy, and critical infrastructure. It cites IRGC-affiliated CyberAveng3rs activity against ICS and PLCs, and says Iranian actors have used Microsoft Exchange and Fortinet flaws to access U.S. infrastructure organizations before moving into theft, ransomware, encryption, and extortion. That makes the threat more than credential theft or perimeter compromise. The concern is access to systems that can affect municipal services, and that capability appears to extend beyond isolated IT networks into operational environments.

Part of the PlainSec briefing for 2026-05-23

Sources