Iranian attacks on US critical infrastructure puts 3,900 devices in crosshairs
2026-04-10T14:51:44Z•e6df1df3606f2064940c485b4d64c7f01b1fff67ecc33d1d0e20daaee6226ef3
AI-security','Project Glasswing','vulnerability-hunting','quantuAPT28BitterForest BlizzardGRUGrafanaICSIranMENAOTOperation MasqueradeProSpyRussiacredential-theftcritical infrastructuredata-exfiltrationenergy sectorhack-for-hireindustrial-control-systemsjournalistsnation-stateprompt-injectionroutersspywarewater sector
What happened
Multiple CyberScoop reports describe an escalating, multi-faceted threat landscape: Censys and U.S. agencies warn of an Iranian government campaign targeting ICS/OT devices in U.S. energy, water and government environments (roughly 3,900 exposed devices reported), and a separate disruptive Iran-aligned activity tied to recent geopolitical events. U.S. law enforcement disrupted a Russia-linked GRU/APT28 router hijacking (Forest Blizzard/Operation Masquerade) that impacted ~18,000 devices and stole credentials/tokens. Researchers disclosed a Grafana prompt‑injection data‑exfiltration technique (
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- cyberscoop
- Record identifier
- e6df1df3606f2064940c485b4d64c7f01b1fff67ecc33d1d0e20daaee6226ef3
- Enrichment time
- 2026-04-10T14:51:44Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.