Fast and Furious – Nimbus Manticore Operations During the Iranian Conflict
2026-05-22T20:52:23Z•17f4efc0997f91d5490a4a0493e7eb8e62209471d1f1bbb6853c567ed3c848e0
CVE-2026-3502ChatGPT data leakageContext.aiDFIRHandala HackIRGC‑affiliatedLapsus$Nimbus ManticoreOAuth token compromiseQ1 2026 ransomware reportRaaSSystemBCThe GentlemenTrivyTrueConfUNC1549VECTVercelVodafonecloud data exfiltrationdestructive attacksransomwaresupply‑chainwiperzero‑day
What happened
Collection of Check Point Research posts (Apr–May 2026) summarizing multiple high‑impact campaigns and intelligence items. Highlights include Iran‑nexus Nimbus Manticore (UNC1549) operations involving internet‑connected camera compromise, destructive attacks, and cloud data exfiltration; multiple high‑profile breaches and supply‑chain incidents (Vodafone/Lapsus$, Vercel/Context.ai OAuth token misuse, European Commission/Trivy); emergence and analysis of new RaaS actors (The Gentlemen, VECT) including accidental wiper behavior; a TrueConf zero‑day (CVE-2026-3502, CVSS 7.8) exploited in targeted
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- checkpoint_research
- Record identifier
- 17f4efc0997f91d5490a4a0493e7eb8e62209471d1f1bbb6853c567ed3c848e0
- Enrichment time
- 2026-05-22T20:52:23Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.