Iran-Linked Handala Breached a California Water Utility. It Could Have Done Worse, and It Knows That.
2026-06-13T08:51:43Z•f2da13cd2a29faca7d67ca3d5733b334b441a8d48071ee6dd42a61edcd05211e
BitLocker bypassCISA KEVCVE-2025-8088CVE-2026-10520CVE-2026-25089California Water ServiceDLL sideloadingFortiSandboxGreatXMLHandalaIoT camerasIvanti SentryJDY botnetMaaSOnyxC2Oracle PeopleSoftRCEShinyHuntersVolt TyphoonWinRARdata-breachexposed webcamsmalware-as-a-servicestealerzero-day
What happened
Multiple high-impact incidents and vulnerabilities reported: Iran-linked Handala claimed a breach of California Water Service and published a 5GB data dump (billing data for ~2M customers). CISA added Ivanti Sentry OS command injection (CVE-2026-10520, CVSS 10.0) to its KEV catalog after widespread post-patch exploitation. A critical Oracle PeopleSoft RCE zero-day was exploited by ShinyHunters against >100 organizations (mostly universities) before an advisory was issued. Researcher Chaotic Eclipse published GreatXML, an unpatched BitLocker bypass that yields SYSTEM in Recovery Mode. Fortinet/
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- f2da13cd2a29faca7d67ca3d5733b334b441a8d48071ee6dd42a61edcd05211e
- Enrichment time
- 2026-06-13T08:51:43Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.