Iran-linked hackers disrupt operations at US critical infrastructure sites

2026-04-09T08:51:46Zcc2991baf097e7238669aa5637808769eb978a856dad81457dfb5dfdd5560b9e
consumer-routerscredentialscritical-infrastructuredata-leakgit-repo-tamperinggpu-exploitiotip-kvmiphoneiranmalwaremobile-zero-daynvidia-gpuopenclawqdayquantum-cryptographyroutersrowhammerrussiasecurity-camerasstate-sponsoredsupply-chainsupply-chain-attacktrivywiper

What happened

A series of high-impact security stories from March–April 2026: state-linked (Iranian and Russian) actors have stepped up attacks on US and allied infrastructure, consumer routers, security cameras, and critical facilities; widespread supply-chain compromises hit tooling and repositories (Trivy, GitHub invisible/unicode attacks); new offensive techniques and exploits are emerging — a powerful iPhone 0-day (DarkSword) in the wild, OpenClaw allowing silent unauthenticated admin access, GPU Rowhammer variants (GDDRHammer/GeForge/GPUBreach) enabling full machine takeover, and IP-KVM and other BIOS

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
arstechnica_security
Record identifier
cc2991baf097e7238669aa5637808769eb978a856dad81457dfb5dfdd5560b9e
Enrichment time
2026-04-09T08:51:46Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.