Shaky Ceasefire Unlikely to Stop Cyberattacks From Iran-Linked Hackers for Long

2026-04-09T01:24:07Z8f9b7f3551d7e5d8ccf2960e25c002e1ccfd54da9cc653abe501b3d8e7300b71
AIAPT28ActiveMQAnthropicDNS hijackingFBIIoT botnetIran-linkedJolokiaMasjesuMikroTikNinja FormsOTOpenSSLPLC/SCADARussiaTP-LinkWordPresscritical infrastructurecybercrime lossesdual-usehospital outageroutersstate-sponsored

What happened

Multiple SecurityWeek reports highlight elevated cyber risk from both state-linked actors and active zero-day/known-exploit activity. Iran-linked groups remain poised to resume attacks despite a tentative ceasefire and are implicated in disruptive PLC/SCADA targeting of US critical infrastructure; separately, US authorities disrupted a Russian espionage operation (APT28) that used compromised TP‑Link and MikroTik routers for AitM/DNS hijacking. Multiple active malware and vulnerability stories: an evasive Masjesu IoT DDoS botnet is targeting devices; a Massachusetts hospital suffered service-­

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityweek
Record identifier
8f9b7f3551d7e5d8ccf2960e25c002e1ccfd54da9cc653abe501b3d8e7300b71
Enrichment time
2026-04-09T01:24:07Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.