Middle east crisis prompts UK NCSC warning on potential Iranian cyber activity
2026-03-04T21:44:31Z•436380b3f175613fcc9f63ea713044fcf228f8e3e57f22792966e5fa0ce17070
CVE-2025-64328CVE-2026-1731CVE-2026-21513AI-assisted attackAPT37Apt28CVEClaude CodeClawJackedFreePBXMSHTMLOnlyFakeProject CompassSangomaScarCruftShinyHuntersUSB implantZoho WorkDriveair-gappeddata-breachexploitlaw-enforcementnation-stateopenclawzero-day
What happened
SecurityAffairs feed (early March 2026) highlights rising geopolitical cyber risk and multiple active campaigns and vulnerabilities: UK NCSC warns of potential increased Iranian activity; Russia-linked APT28 exploited an MSHTML zero-day (CVE-2026-21513) before patching; North Korea-linked APT37 (ScarCruft) used Zoho WorkDrive plus USB implants to breach air-gapped networks (Ruby Jumper); the ClawJacked vulnerability in OpenClaw allowed local AI agents to be hijacked and data-exfiltrated (patched in 2026.2.26); ShinyHunters leaked the full Odido dataset (large Dutch telecom breach); Anthropic’s
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- 436380b3f175613fcc9f63ea713044fcf228f8e3e57f22792966e5fa0ce17070
- Enrichment time
- 2026-03-04T21:44:31Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.