US warns of Iranian hackers targeting critical infrastructure
2026-04-07T19:23:34Z•8e1f7ee251d3118aa19e1157c0ab9a47eaa2c3a34c476209a323ffe1ebdc0859
apt28bluehammercisacritical-infrastructurecve-2025-59528cve-2026-35616dns-hijackflowiseforticlient-emsfortinetfrostarmadagpugpubreachiranian-aptmedusa-ransomwaremicrosoft-365-credential-theftmikrotikplcrcerevil-gandcrab-arrests','drift-crypto-theft','phishing-qr-scams'rockwell-allen-bradleyrowhammerstorm-1175tp-linkwindows-zero-day
What happened
Multiple high-impact incidents and active exploits reported: Iranian-linked operators are scanning and targeting internet-exposed Rockwell/Allen‑Bradley PLCs on U.S. critical‑infrastructure networks; a maximum‑severity RCE in Flowise (CVE-2025-59528) is being exploited in the wild; an APT28 campaign (FrostArmada) hijacked MikroTik/TP‑Link router DNS to steal Microsoft 365 credentials; and a critical FortiClient EMS vulnerability (CVE-2026-35616) is actively exploited, prompting emergency patches and a CISA order. Additional notable items include the GPUBreach GPU Rowhammer attack enabling full
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 8e1f7ee251d3118aa19e1157c0ab9a47eaa2c3a34c476209a323ffe1ebdc0859
- Enrichment time
- 2026-04-07T19:23:34Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.