
CyberWire Daily Water sector feels the pressure.
Mar 31, 2026
Sam Rubin, Senior VP at Palo Alto Networks Unit 42, an expert in Iranian threat tactics and incident response. He discusses Iran's shift to identity weaponization and how enterprise admin tools are being abused. Short takes cover supply-chain strategies, containment after outages, and why hardened identity controls matter. Quick, topical, and focused on active threats and defensive priorities.
AI Snips
Chapters
Transcript
Episode notes
Water Utilities Face Disproportionate Risk
- U.S. infrastructure like water utilities remain highly exposed due to aging systems and sparse cybersecurity resources.
- Named Iranian groups combine destructive intent with opportunistic activation, increasing risk to smaller utilities lacking federal support.
Iran's Internet Shutdown Hobbled Offense
- Iran's nationwide internet restrictions greatly curtailed its ability to conduct outbound offensive cyber operations.
- Unit 42 observed near-zero egress that limited Iranian actors' capability to launch attacks against external targets after connectivity was shut down.
Identity Weaponization Replaces Wipers
- Iranian attackers are shifting from deploying wiper malware to abusing legitimate enterprise admin tools to achieve destructive effects.
- Unit 42 found actors using EntraID/Intune and other admin software to perform wipes and disrupt logins without dropping external malware.

