Feds quash widespread Russia-backed espionage network spanning 18,000 devices
2026-04-08T02:51:46Z•f7e2391e36c187079d23443da4d717940b12885d1a59371230607cfe760346ab
AI securityAPT28CVE-2026-35616FBI IC3Forest BlizzardFortiClient EMSFortinetGRUGrafanaICS/SCADAIranian threat actorsParagonProject GlasswingRussiaactive exploitationcredential theftcybercrimeenergy sectorprompt injectionrouter hijackspywarestalkerwaretoken theftwater sectorzero-day
What happened
CyberScoop roundup: U.S. authorities disrupted 'Forest Blizzard' (APT28/GRU) infrastructure that hijacked ~18,000 routers to steal Microsoft credentials and tokens; Iranian state-linked actors launched disruptive attacks against U.S. energy and water ICS/SCADA systems; GrafanaGhost researchers demonstrated stealthy AI prompt-injection exfiltration of sensitive data; Fortinet customers are facing an actively exploited FortiClient EMS zero-day (CVE-2026-35616) with only a hotfix available pending a full patch; major tech firms launched an AI-driven Project Glasswing to proactively find critical,
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- cyberscoop
- Record identifier
- f7e2391e36c187079d23443da4d717940b12885d1a59371230607cfe760346ab
- Enrichment time
- 2026-04-08T02:51:46Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.