Iranian attacks on US critical infrastructure puts 3,900 devices in crosshairs

2026-04-10T14:51:44Ze6df1df3606f2064940c485b4d64c7f01b1fff67ecc33d1d0e20daaee6226ef3
AI-security','Project Glasswing','vulnerability-hunting','quantuAPT28BitterForest BlizzardGRUGrafanaICSIranMENAOTOperation MasqueradeProSpyRussiacredential-theftcritical infrastructuredata-exfiltrationenergy sectorhack-for-hireindustrial-control-systemsjournalistsnation-stateprompt-injectionroutersspywarewater sector

What happened

Multiple CyberScoop reports describe an escalating, multi-faceted threat landscape: Censys and U.S. agencies warn of an Iranian government campaign targeting ICS/OT devices in U.S. energy, water and government environments (roughly 3,900 exposed devices reported), and a separate disruptive Iran-aligned activity tied to recent geopolitical events. U.S. law enforcement disrupted a Russia-linked GRU/APT28 router hijacking (Forest Blizzard/Operation Masquerade) that impacted ~18,000 devices and stole credentials/tokens. Researchers disclosed a Grafana prompt‑injection data‑exfiltration technique (

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cyberscoop
Record identifier
e6df1df3606f2064940c485b4d64c7f01b1fff67ecc33d1d0e20daaee6226ef3
Enrichment time
2026-04-10T14:51:44Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Iranian attacks on US critical infrastructure puts 3,900 devices in crosshairs · Baitaphish