Operation Epic Fury: Potential Iranian Cyber Counteroffensive Operations

2026-03-04T22:32:13Z15e1498ff7ea29fbc6535aa535a839baa3b2eddb3f6c983debc31624286f9fba
CVE-2023-2804CVE-2026-20127CVE-2026-21510CVE-2026-21513UAT-8616active-directoryai-vulnerability-discoveryambar-srcanthropic-claude-opusauthentication-bypasscisco-catalyst-sd-wancloud-ai-securitydestructive-attacksdynamic-objectsexposure-managementiranian-threat-actorsmicrosoft-patch-tuesdaymoltbooknpm-malwareopenclawoperation-epic-furyprompt-injectionsupply-chain-malwaretenable-one

What happened

Tenable published a set of security advisories and research covering multiple active and emerging risks: a likely Iran-linked cyber counteroffensive following Operation Epic Fury that may include destructive wipers, ransomware, DDoS and botnet activity; an actively exploited critical (CVSS 10.0) authentication‑bypass zero‑day in Cisco Catalyst SD‑WAN Controller/Manager (CVE-2026-20127) with patches available and no workarounds; a malicious npm package (“ambar-src”) that reached ~50k downloads and executes malware during install; stealthy Active Directory “dynamic objects” abuse that evades for

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
tenable_blog
Record identifier
15e1498ff7ea29fbc6535aa535a839baa3b2eddb3f6c983debc31624286f9fba
Enrichment time
2026-03-04T22:32:13Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Operation Epic Fury: Potential Iranian Cyber Counteroffensive Operations · Baitaphish