Iranian attacks on US critical infrastructure puts 3,900 devices in crosshairs

2026-04-10T02:51:47Z1f9ddef3a41b23b2c8ebbd2141bd4ca87b7dba321100c7b4f51205431fb7e81e
ai-securityapt28bittercensyscritical-infrastructurecybercrimedisruptive-attacksfbi-ic3forest-blizzardgrafanaghostgrugruhack-for-hireiranian-state-backedjournalists-targetedot-icspost-quantumproject-glasswingprompt-injectionprospyquantum-computingroutersus-federal-alertvulnerability-discovery

What happened

A series of CyberScoop reports highlight escalating nation-state and crimeware activity and emerging AI-security issues. Censys and U.S. agencies warn an Iran-linked campaign is actively targeting U.S. energy, water and government OT/ICS devices (≈3,900 exposed) with disruptive attacks; separate federal actions disrupted a Russia-linked (GRU/APT28/Forest Blizzard) router-based espionage campaign affecting ~18,000 devices. Researchers also disclosed ‘GrafanaGhost’ prompt-injection data-exfiltration against Grafana’s AI features, while tech firms launched Project Glasswing to find critical open‑

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cyberscoop
Record identifier
1f9ddef3a41b23b2c8ebbd2141bd4ca87b7dba321100c7b4f51205431fb7e81e
Enrichment time
2026-04-10T02:51:47Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.