US Indicts 17 Iranians Over Years-Long Cyber Espionage Campaign
2026-08-20T08:51:37Z•59e3ef460b5f2b84f178c68dd708087c8b6fbec62ca3e75b7266ebf7d0900f23
CVE-2025-62593CVE-2026-19478CVE-2026-33824API key exposureCISA KEVDahuaGitLabGraphQLIoTIranMabna InstituteMacSync StealerMicrosoft SharePointRayStripeVMware vCenterWordPress compromisecredential theftcyber-espionagedata breachinfostealerknown exploited vulnerabilitiesmacOSmalware deliveryransomwaresecrets leakagesurveillance camerasunauthenticated RCE
What happened
Security news covering Iranian cyber-espionage indictments, a criminal network abusing nearly 2,000 compromised WordPress sites, large-scale Dahua camera compromises, MacSync Stealer activity, exposure of more than 50,000 Stripe API keys, multiple vulnerabilities added to CISA’s Known Exploited Vulnerabilities catalog, a breach affecting 1.2 million Heights Finance customers, adversarial attacks against surveillance AI, and a critical unauthenticated GitLab GraphQL vulnerability. The most urgent items are actively exploited or critical vulnerabilities, particularly GitLab CVE-2026-19478 and KE
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- 59e3ef460b5f2b84f178c68dd708087c8b6fbec62ca3e75b7266ebf7d0900f23
- Enrichment time
- 2026-08-20T08:51:37Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.