Initial access techniques used by Iran-based threat actors

2026-03-13T20:51:40Zb18c99d85c36af456638f21c9701d14a7730601773c7896ec7eb9f63ff2e9614
Active AdversaryCVE-2022-20775CVE-2026-20127Cisco SD-WANClickFixIranOperation Epic FurySophos Workspace Protectionadvisoryfirewall v22hacktivisminfostealerinitial accessmacOSthreat research

What happened

Collection of Sophos blog posts (Mar–Feb 2026) summarizing threat research and advisories: analysis of initial access techniques used by Iran-linked groups; evolution of ClickFix lures and macOS-targeting infostealers; increased hacktivist activity tied to US–Israel–Iran tensions (Operation Epic Fury); active exploitation of Cisco SD‑WAN vulnerabilities (CVE-2026-20127, CVE-2022-20775); product announcements (Sophos Firewall v22, Sophos Workspace Protection); and the 2026 Active Adversary Report. Recommendations and defensive guidance are included in related advisories.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sophos_news
Record identifier
b18c99d85c36af456638f21c9701d14a7730601773c7896ec7eb9f63ff2e9614
Enrichment time
2026-03-13T20:51:40Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Initial access techniques used by Iran-based threat actors · Baitaphish