Initial access techniques used by Iran-based threat actors

2026-03-17T20:51:44Ze4f1b718166b9f5a42c0f31136146a9aed838f2723dda1d7414b41239bb153a6
active-exploitationcisco-sd-wanclickfixfirewall-v22hacktivisminfostealerinitial-accessiranmacospatch-tuesdayproduct-releasesecurity-operationssocial-engineeringsophos-workspacethreat-researchvulnerabilities

What happened

Sophos RSS feed containing multiple recent posts (Mar 2026) from Sophos X-Ops and threat research teams. Topics include analysis of initial-access techniques used by Iran-linked threat actors, macOS infostealers and ClickFix social-engineering campaigns, increased hacktivist activity tied to US–Iran–Israel tensions, and a March Patch Tuesday roundup reporting 84 CVEs (including eight Critical). The feed also flags active exploitation of Cisco SD-WAN vulnerabilities (CVE-2026-20127 and CVE-2022-20775) and includes product announcements (Sophos Workspace Protection, Firewall v22) and a cyber-adv

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sophos_news
Record identifier
e4f1b718166b9f5a42c0f31136146a9aed838f2723dda1d7414b41239bb153a6
Enrichment time
2026-03-17T20:51:44Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Initial access techniques used by Iran-based threat actors · Baitaphish