Initial access techniques used by Iran-based threat actors
2026-03-18T08:51:39Z•4c6e9cf04a3ecd68ceda9c0d2be871c062367509404b1d3c2c344233b7843c4d
CVE-2022-20775CVE-2026-20127Cisco SD-WANIranSophos CTUactive-adversary-reportactive-exploitationclickfixcyber-advisoryfirewall-v22hacktivisminfostealerinitial-accessmacOSpatch-tuesdayproduct-releasethreat-researchvulnerabilitiesworkspace-protection
What happened
Feed of Sophos blog posts (Feb–Mar 2026) covering recent threat research, advisories, and product news: analysis of initial-access techniques used by Iran-linked groups; rising hacktivist campaigns tied to US–Iran–Israel tensions; ClickFix-based social engineering and macOS infostealers; March Patch Tuesday (84 CVEs, including eight Critical); active exploitation of Cisco SD‑WAN vulnerabilities (CVE-2026-20127, CVE-2022-20775); a Sophos CTU cyber advisory with defensive recommendations; the 2026 Active Adversary Report; and product announcements (Sophos Workspace Protection, Firewall v22).
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sophos_news
- Record identifier
- 4c6e9cf04a3ecd68ceda9c0d2be871c062367509404b1d3c2c344233b7843c4d
- Enrichment time
- 2026-03-18T08:51:39Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.