Operation Epic Fury: Potential Iranian Cyber Counteroffensive Operations
2026-03-05T20:52:30Z•a41f4639068108e30eed657c64be8e4978fbad5eac419c9b35cc909133f99163
active-directoryambar-srcauthentication-bypassbotnetcisco-sd-wancloud-ai-governancecritical-infrastructurecyber-retaliationddosdynamic-objectsexploited-in-the-wildiranian-state-actorsmalicious-packagemicrosoft-patch-tuesdaynpm-malwareopen-source-malwareoverprivileged-identitiespersistence-evasionsupply-chainuam-8616wiperzero-day
What happened
This set of Tenable blog posts highlights multiple high-risk issues: (1) Following Operation Epic Fury, Iran-linked actors are expected to launch cyber counteroffensives (wiper/ransomware, DDoS, botnet activity) against critical infrastructure and opportunistic targets. (2) A maximum-severity authentication-bypass zero-day (CVE-2026-20127) in Cisco Catalyst SD-WAN Controller/Manager is being exploited in the wild (actor UAT-8616); Cisco has released patches and additional related exploited SD‑WAN vulnerabilities (CVE-2026-20128, CVE-2026-20122) were noted. (3) A malicious npm package (“ambar‑s
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- tenable_blog
- Record identifier
- a41f4639068108e30eed657c64be8e4978fbad5eac419c9b35cc909133f99163
- Enrichment time
- 2026-03-05T20:52:30Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.