threat-intel In Other News: Log4j RCE Scare, Minimus Shutdown, Iranian Hacker Sanctions Several cybersecurity events were highlighted this week, including a reassessment of the Log4j vulnerability as ‘non-finding,’ a ransomware attack against Paylogix exposing sensitive data, and US sanctions against Iranian cyber actors. Other notable developments included a credential leak study revealing thousands of a… SecurityWeek · 2d ago High IRSONElog4jcredential leakransomware
threat-intel US sanctions Iranian cyber actors as UK discloses power plant attack The U.S. has sanctioned several Iranian nationals linked to a hacking operation targeting U.S. critical infrastructure, following a recent cyberattack on a small power plant in the UK. This escalation highlights Iran's c… The Record · 6d ago High IRUNUKcyberattackcritical infrastructureiran
threat-intel Cavern C2 Uses DNS and Google Apps Script to Blend Into Legitimate Traffic The Cavern C2 framework, used by Iranian nation-state hackers linked to the Ministry of Intelligence and Security (MOIS) and associated with groups like MuddyWater and OilRig (Lyceum), is undergoing continuous evolution.… The Hacker News · Aug 17, 2026 High IRc2dnsgoogle
threat-intel Iran-Linked Hackers Using Modular C&C Framework in Cyberattacks An Iran-linked APT group, known as Cavern Manticore, is utilizing a sophisticated, AI-assisted modular command-and-control framework to target organizations in Israel, particularly government entities and IT providers. T… SecurityWeek · Jul 7, 2026 High ILaptcommand and controllateral movement
threat-intel Iran-Linked Hackers Use New Cavern C2 Framework to Target Israeli Organizations Iranian hackers, linked to Iran's Ministry of Intelligence and Security (MOIS) and operating under the moniker Cavern Manticore, are utilizing a new, modular command-and-control (C2) framework called ‘Cavern’ to target I… The Hacker News · Jul 6, 2026 High CVE-2025-52691CVE-2025-68613CVE-2025-9316ISIRc2command and controldotnet
threat-intel Iranian Cyber Group Handala Claims Cal Water Hack The Iranian cyber threat actor Handala has claimed responsibility for a data breach targeting California Water Service (Cal Water), resulting in the theft of 5GB of data including customer information and credentials. Th… SecurityWeek · Jun 12, 2026 High USIRirandata breachcyber espionage
apt Iranian intelligence service behind hack of LA transit system, researchers say Iranian intelligence service operatives, known as Ababil of Minab, were responsible for a significant cyberattack targeting the Los Angeles County Metropolitan Transportation Authority (LACMTA). The group, linked to the… The Record · May 27, 2026 High IRISTUirancyberattackcritical infrastructure
threat-intel MuddyWater Uses DLL Side-Loading in Espionage Campaign Targeting 9 Countries The MuddyWater hacking group, backed by Iran, has been conducting a sophisticated espionage campaign targeting organizations across nine countries on four continents during Q1 2026. The campaign utilizes DLL side-loading… The Hacker News · May 26, 2026 High KRSAAEdll-side-loadingcredential-stealingreconnaissance