Iran-linked hackers disrupt operations at US critical infrastructure sites
2026-04-11T08:51:54Z•c70068dab0f5c913efdac31d52dc2c9b3bb26a7c180f88bea32a734c69b138e7
CBP-data-leakDarkSwordGPU-RowhammerIP-KVMIranNvidiaOpenClawQ-DayRussiaStrykerTrivyagentic-AIcredential-theftcritical-infrastructureiPhone-exploitinvisible-unicodemalwarequantum-computingrouterssecurity-camerasstate-sponsoredsupply-chain-attackwiper-attack
What happened
Ars Technica's security feed from Mar–Apr 2026 documents a broad spike in high-impact cyber activity: state-linked operations (notably Iran- and Russia-associated) targeting US/Israeli critical infrastructure, consumer routers, security cameras, and border-control data; large-scale supply-chain compromises (Trivy, invisible-Unicode repo poisoning); and powerful new technical attack vectors (OpenClaw agent enabling unauthenticated admin access; GPU Rowhammer variants—GDDRHammer/GeForge/GPUBreach—allowing CPU takeover on Nvidia systems; and DarkSword iPhone exploits seen in the wild). Other high
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- arstechnica_security
- Record identifier
- c70068dab0f5c913efdac31d52dc2c9b3bb26a7c180f88bea32a734c69b138e7
- Enrichment time
- 2026-04-11T08:51:54Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.