Threat Brief: March 2026 Escalation of Cyber Risk Related to Iran
2026-03-04T21:27:52Z•f1e77c10e85473c6ed981caf4d46173e785e8b3f8a754b6aae240b887d588cd3
CVE-2025-0921CVE-2026-0628CVE-2026-1281CVE-2026-1340CVE-2026-1731BeyondTrust CVE-2026-1731Chrome CVE-2026-0628Iranian cyber activityIvanti EPMM CVE-2026-1281Ivanti EPMM CVE-2026-1340LLM-enabled runtime attacksOT-securityQR-code phishingSCADA CVE-2025-0921cloud detection techniquesnation-statephishingsupply-chain compromiseweb shells
What happened
Unit 42 published a March 2026 collection of threat research and advisories covering an escalation in Iranian cyber activity plus multiple actively exploited and high-impact vulnerabilities. Notable disclosures include Chrome Gemini extension hijack (CVE-2026-0628, patched), a BeyondTrust RCE exploited to deploy VShell and SparkRAT (CVE-2026-1731), widespread exploitation of Ivanti EPMM zero-days (CVE-2026-1281, CVE-2026-1340) with web shells and backdoors, and a SCADA privileged file system flaw (CVE-2025-0921). Other topics include Notepad++ supply-chain compromise, QR-code and mobile-phishl
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- paloalto_unit42
- Record identifier
- f1e77c10e85473c6ed981caf4d46173e785e8b3f8a754b6aae240b887d588cd3
- Enrichment time
- 2026-03-04T21:27:52Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.