Fast and Furious – Nimbus Manticore Operations During the Iranian Conflict

2026-05-22T20:52:23Z17f4efc0997f91d5490a4a0493e7eb8e62209471d1f1bbb6853c567ed3c848e0
CVE-2026-3502ChatGPT data leakageContext.aiDFIRHandala HackIRGC‑affiliatedLapsus$Nimbus ManticoreOAuth token compromiseQ1 2026 ransomware reportRaaSSystemBCThe GentlemenTrivyTrueConfUNC1549VECTVercelVodafonecloud data exfiltrationdestructive attacksransomwaresupply‑chainwiperzero‑day

What happened

Collection of Check Point Research posts (Apr–May 2026) summarizing multiple high‑impact campaigns and intelligence items. Highlights include Iran‑nexus Nimbus Manticore (UNC1549) operations involving internet‑connected camera compromise, destructive attacks, and cloud data exfiltration; multiple high‑profile breaches and supply‑chain incidents (Vodafone/Lapsus$, Vercel/Context.ai OAuth token misuse, European Commission/Trivy); emergence and analysis of new RaaS actors (The Gentlemen, VECT) including accidental wiper behavior; a TrueConf zero‑day (CVE-2026-3502, CVSS 7.8) exploited in targeted

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
checkpoint_research
Record identifier
17f4efc0997f91d5490a4a0493e7eb8e62209471d1f1bbb6853c567ed3c848e0
Enrichment time
2026-05-22T20:52:23Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Fast and Furious – Nimbus Manticore Operations During the Iranian Conflict · Baitaphish