Hacktivist campaigns increase as United States, Iran, and Israel conflict intensifies
2026-03-04T22:28:54Z•10bf73571519209a7d71148fcf62735c05d74508bba9cd66fe81bc44ac7856ac
CVE-2022-20775CVE-2026-20127Active Adversary ReportCiscoITDRIranIsraelMDROperation Epic FurySD-WANSaaSSophos CTUXDRactive exploitationcyber advisoryhacktivismidentity securitythreat researchvulnerabilityworkspace protection
What happened
Sophos published multiple security updates: a surge in regional hacktivist campaigns tied to the U.S.–Iran–Israel escalation (Operation Epic Fury) with currently minimal impact but elevated risk; a Sophos X‑Ops CTU cyber advisory with defensive recommendations for organizations; active exploitation of Cisco SD‑WAN vulnerabilities (CVE-2026-20127 and CVE-2022-20775); and release of the 2026 Active Adversary Report plus new product announcements (Sophos Workspace Protection) and operational guidance based on 661 incidents remediated. Organizations should prioritize patching/mitigation for the SD
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sophos_news
- Record identifier
- 10bf73571519209a7d71148fcf62735c05d74508bba9cd66fe81bc44ac7856ac
- Enrichment time
- 2026-03-04T22:28:54Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.