Hacktivist campaigns increase as United States, Iran, and Israel conflict intensifies

2026-03-05T20:51:41Zeb8c5e34d4ad844531e67bd7194638a24214c43d246e890dc4f8f4246cf7e88b
Active Adversary ReportCVE-2022-20775CVE-2026-20127Cisco SD‑WANITDRIdentity SecurityIranIsraelMDROperation Epic FurySaaSSecure by DesignSophos CTUWorkspace ProtectionXDRactive exploitationcyber advisoryhacktivismvulnerability

What happened

Sophos published multiple items covering an increase in regionally focused hacktivist activity tied to the U.S.–Iran–Israel escalation (including references to Operation Epic Fury) and issued a Cyber Advisory with defensive guidance from Sophos X‑Ops/CTU. They also reported active exploitation of Cisco SD‑WAN vulnerabilities (CVE‑2026‑20127 and CVE‑2022‑20775). In addition, Sophos released product/news updates including Sophos Workspace Protection and the 2026 Active Adversary Report with operational lessons and remediation guidance (MDR/XDR/identity/ITDR focused).

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sophos_news
Record identifier
eb8c5e34d4ad844531e67bd7194638a24214c43d246e890dc4f8f4246cf7e88b
Enrichment time
2026-03-05T20:51:41Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.