Iranian state-sponsored hackers are expanding their targeting of US critical infrastructure, with a growing focus on diverse industrial control systems. The US Cybersecurity and Infrastructure Security Agency (CISA) has updated its alert to reflect this broadened scope, warning of potential attacks on programmable logic controllers (PLCs) from multiple manufacturers, including Schneider Electric and Siemens, in addition to Rockwell Automation/Allen-Bradley1. This development suggests that Iranian-affiliated crews are adapting their tactics to compromise a wider range of industrial devices, potentially disrupting water and energy facilities. The ongoing conflict between the US and Iran has led to increased scrutiny of Iranian hacking activity, with authorities monitoring for signs of advanced persistence threats. So what matters to practitioners is that this trend indicates a heightened risk of disruption to critical infrastructure, underscoring the need for vigilance and proactive defense measures.