Middle east crisis prompts UK NCSC warning on potential Iranian cyber activity

2026-03-04T21:46:13Z8c4643d2fbead4418894cde16e620a69cc815cfb47cf9d6efc864df97caa97dd
CVE-2025-64328CVE-2026-1731CVE-2026-21513AI-assisted attacksAPT28APT37AnthropicClaude CodeClawJackedEuropolFreePBXIranian cyber threatMSHTMLNCSCOdidoOnlyFakeOpenClawProject CompassSangomaScarCruftShinyHuntersUSB implantZoho WorkDriveair-gapped breachdata leakidentity fraudweb shellzero-day exploit

What happened

Multiple high-impact threats and incidents reported: Russia-linked APT28 exploited an MSHTML zero-day (CVE-2026-21513) in the wild prior to Microsoft’s patch; North Korea-linked APT37 (ScarCruft) used Zoho WorkDrive as C2 and USB implants to breach air-gapped networks (Ruby Jumper campaign); hundreds of Sangoma FreePBX systems were infected via exploitation of CVE-2025-64328; OpenClaw’s “ClawJacked” flaw (high severity) allowed local AI agents to be hijacked and was patched in release 2026.2.26; criminals abused Anthropic’s Claude Code to build exploits and exfiltrate ~150GB from Mexican govt.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
8c4643d2fbead4418894cde16e620a69cc815cfb47cf9d6efc864df97caa97dd
Enrichment time
2026-03-04T21:46:13Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.