US warns of Iranian hackers targeting critical infrastructure

2026-04-07T19:23:34Z8e1f7ee251d3118aa19e1157c0ab9a47eaa2c3a34c476209a323ffe1ebdc0859
apt28bluehammercisacritical-infrastructurecve-2025-59528cve-2026-35616dns-hijackflowiseforticlient-emsfortinetfrostarmadagpugpubreachiranian-aptmedusa-ransomwaremicrosoft-365-credential-theftmikrotikplcrcerevil-gandcrab-arrests','drift-crypto-theft','phishing-qr-scams'rockwell-allen-bradleyrowhammerstorm-1175tp-linkwindows-zero-day

What happened

Multiple high-impact incidents and active exploits reported: Iranian-linked operators are scanning and targeting internet-exposed Rockwell/Allen‑Bradley PLCs on U.S. critical‑infrastructure networks; a maximum‑severity RCE in Flowise (CVE-2025-59528) is being exploited in the wild; an APT28 campaign (FrostArmada) hijacked MikroTik/TP‑Link router DNS to steal Microsoft 365 credentials; and a critical FortiClient EMS vulnerability (CVE-2026-35616) is actively exploited, prompting emergency patches and a CISA order. Additional notable items include the GPUBreach GPU Rowhammer attack enabling full

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
8e1f7ee251d3118aa19e1157c0ab9a47eaa2c3a34c476209a323ffe1ebdc0859
Enrichment time
2026-04-07T19:23:34Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · US warns of Iranian hackers targeting critical infrastructure · Baitaphish