The United States government has updated its cybersecurity advisory, warning that Iranian hackers are targeting industrial control systems produced by Siemens, Schneider Electric, and Rockwell Automation. Initially issued in April, the advisory detailed attacks on operational technology devices within critical sectors such as government services, energy, and water management. Hackers have compromised internet-exposed programmable logic controllers, using malicious project files that manipulate human-machine interfaces and supervisory control and data acquisition systems. The updated advisory now includes Schneider Electric and Siemens among the affected vendors and highlights that other companies' devices could also be at risk. In one U.S. case, FBI investigators found that the attackers used configuration software to install a harmful project file on a PLC. The file retained normal functions but altered specific instructions, compromising safety in the victim's environment. The attacks targeted specific ports and involved the use of programming software and third-party infrastructure. The hackers extracted, modified, and deleted PLC project files, disabling critical shutdown and alarm functions. This allowed systems to operate unsafely without alerting operators. The advisory now offers new guidance on detecting these threats and updated indicators of compromise. The Iranian government has used hacktivist personas for these attacks, with groups like CyberAv3ngers and Handala leading recent campaigns. Handala recently claimed to have breached California Water Service systems, although the utility found no evidence of such activity. These developments emphasize the need for robust, proactive defenses as hackers continue to advance their capabilities.