Iranian cyber espionage disguised as a Chaos Ransomware attack

2026-05-06T20:51:51Z46ad25a0d91de0fe81a0762a59cc2f17681805bc323af4d42107d452548be1f1
APTAndroidApache HTTP ServerCVE-2026-0073CVE-2026-0300CVE-2026-23918CVE-2026-4670CVE-2026-5174Chaos ransomwareMOVEitMicrosoft campaign','data breach','Vimeo','third-party breach','MuddyWaterPAN-OSPalo AltoPyPIPyTorch LightningRCEactive exploitauth token theftcredential theftespionagephishingransomwareremote code executionsupply chain

What happened

Multiple high‑impact incidents and vulnerabilities were reported: Iran‑linked APT MuddyWater used ransomware‑style tactics (disguised Chaos ransomware extortion) to mask espionage operations (Rapid7 attribution). High‑severity/actively exploited flaws include Palo Alto PAN‑OS CVE‑2026‑0300 (unauthenticated RCE, CVSS 9.3) and Apache HTTP Server CVE‑2026‑23918 (HTTP/2 double‑free leading to RCE, CVSS 8.8); Google patched critical Android RCE CVE‑2026‑0073. MOVEit Automation fixes address critical authentication bypass and privilege escalation (CVE‑2026‑4670, CVE‑2026‑5174). Supply‑chain and data

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
46ad25a0d91de0fe81a0762a59cc2f17681805bc323af4d42107d452548be1f1
Enrichment time
2026-05-06T20:51:51Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.