Iran‑Backed Threat Actors Hit US CNI Providers via Internet‑Facing OT Assets
2026-04-08T08:52:16Z•31d0eebd28de88e3ea80292e24b228566d7d2e2f35d7cf55ce1e8033401b4159
AI-prompt-injectionAPT28AiTM-phishingCVE-2025-53521CVE-2026-3055Citrix-NetScalerF5-BIG-IPFortiClient-EMSGPUBreachGrafanaGhostIran-backed-actorsOT-securityTeamPCPVenom-Stealercredential-theftcritical-infrastructuredata-exfiltrationinfostealer-RATsmalicious-dnsphishingprivilege-escalationrouter-hijackrowhammersupply-chainzero-day
What happened
Infosecurity Magazine roundup: Multiple high-impact campaigns and active exploits were reported — Iran-backed threat actors targeted US critical national infrastructure via internet-facing OT assets causing disruption and loss; APT28 hijacked routers/modified VPSs to run malicious DNS servers and steal credentials; and a GPU Rowhammer technique (GPUBreach) enables full system privilege escalation. Researchers disclosed several malware-as-a-service and supply‑chain threats (Venom Stealer, Phantom, DeepLoad, TeamPCP) and novel covert channels (GitHub C2, EtherRAT smart‑contract C2). Vendors and,
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- infosecurity_magazine
- Record identifier
- 31d0eebd28de88e3ea80292e24b228566d7d2e2f35d7cf55ce1e8033401b4159
- Enrichment time
- 2026-04-08T08:52:16Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.