Feds quash widespread Russia-backed espionage network spanning 18,000 devices

2026-04-08T02:51:46Zf7e2391e36c187079d23443da4d717940b12885d1a59371230607cfe760346ab
AI securityAPT28CVE-2026-35616FBI IC3Forest BlizzardFortiClient EMSFortinetGRUGrafanaICS/SCADAIranian threat actorsParagonProject GlasswingRussiaactive exploitationcredential theftcybercrimeenergy sectorprompt injectionrouter hijackspywarestalkerwaretoken theftwater sectorzero-day

What happened

CyberScoop roundup: U.S. authorities disrupted 'Forest Blizzard' (APT28/GRU) infrastructure that hijacked ~18,000 routers to steal Microsoft credentials and tokens; Iranian state-linked actors launched disruptive attacks against U.S. energy and water ICS/SCADA systems; GrafanaGhost researchers demonstrated stealthy AI prompt-injection exfiltration of sensitive data; Fortinet customers are facing an actively exploited FortiClient EMS zero-day (CVE-2026-35616) with only a hotfix available pending a full patch; major tech firms launched an AI-driven Project Glasswing to proactively find critical,

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cyberscoop
Record identifier
f7e2391e36c187079d23443da4d717940b12885d1a59371230607cfe760346ab
Enrichment time
2026-04-08T02:51:46Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Feds quash widespread Russia-backed espionage network spanning 18,000 devices · Baitaphish