Initial access techniques used by Iran-based threat actors

2026-03-18T08:51:39Z4c6e9cf04a3ecd68ceda9c0d2be871c062367509404b1d3c2c344233b7843c4d
CVE-2022-20775CVE-2026-20127Cisco SD-WANIranSophos CTUactive-adversary-reportactive-exploitationclickfixcyber-advisoryfirewall-v22hacktivisminfostealerinitial-accessmacOSpatch-tuesdayproduct-releasethreat-researchvulnerabilitiesworkspace-protection

What happened

Feed of Sophos blog posts (Feb–Mar 2026) covering recent threat research, advisories, and product news: analysis of initial-access techniques used by Iran-linked groups; rising hacktivist campaigns tied to US–Iran–Israel tensions; ClickFix-based social engineering and macOS infostealers; March Patch Tuesday (84 CVEs, including eight Critical); active exploitation of Cisco SD‑WAN vulnerabilities (CVE-2026-20127, CVE-2022-20775); a Sophos CTU cyber advisory with defensive recommendations; the 2026 Active Adversary Report; and product announcements (Sophos Workspace Protection, Firewall v22).

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sophos_news
Record identifier
4c6e9cf04a3ecd68ceda9c0d2be871c062367509404b1d3c2c344233b7843c4d
Enrichment time
2026-03-18T08:51:39Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Initial access techniques used by Iran-based threat actors · Baitaphish