Iran-Linked Actors Breach Are Targeting US Water and Energy Control Systems
2026-07-26T02:51:42Z•1995cf75da30582e37541a6186cf0f8ab82791b867e701d2dde1ab1f6d21549e
AI trustCISA KEVChaos ransomwareCheck PointChrome DevTools ProtocolEU DMAGemini 3.5 Flash CyberGoogle fineHades implantHermes AI agentLaundry BearOrigin EnergySharePointUAC-0099Zimbracritical-infrastructuredata-breachenergy-sectorfake-pluginmalwaremsaRATnation-state activityvulnerability-huntingwater-sector
What happened
Recent reporting highlights multiple high-risk cyber incidents and policy actions: US agencies (CISA, FBI, NSA, DOE) warn Iran-linked actors have gained access to internet-exposed water and energy control systems and are making changes that risk service disruption; Australian energy provider Origin Energy disclosed a data breach reportedly affecting ~2 million customers; researchers uncovered an espionage operation against Thailand’s Ministry of Finance using a Hermes AI agent and Hades implant; CERT-UA attributes UAC-0099 phishing that delivers malware via a fake Notepad++ plugin targeting U‑
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- 1995cf75da30582e37541a6186cf0f8ab82791b867e701d2dde1ab1f6d21549e
- Enrichment time
- 2026-07-26T02:51:42Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.