Iran-Linked Password-Spraying Campaign Targets 300+ Israeli Microsoft 365 Organizations
2026-04-06T19:24:11Z•3c2f21d208315998884b4ad7eca2269711e2d32d1e60430d427f1c3cf5bc1e1e
axiosbyovdciscocve-2025-55182cve-2026-20093cve-2026-35616dprk-linkeddriftdurable-nonceedr-bypassfortinetgithub-c2ios-android-malware','apple-ios-18.7.7','darksword','revil','rmmiran-linkedmicrosoft-365mobile-malwarenpm-supply-chainpassword-sprayingqilinreact2shellsocial-engineeringsparkcatunc1069vulnerable-driverswarlock
What happened
The Hacker News roundup (Apr 2026) highlights multiple high-impact incidents and active campaigns: an Iran-linked password-spraying campaign targeting 300+ Israeli Microsoft 365 organizations; DPRK-linked actors using GitHub as C2 and conducting long-term social engineering (including the $285M Drift exploit via durable nonces); active exploitation of high-severity vulnerabilities (Fortinet CVE-2026-35616 — CVSS 9.1 — and Cisco CVE-2026-20093 — CVSS 9.8); large-scale abuse of the React2Shell flaw (CVE-2025-55182) to harvest credentials from Next.js hosts; npm supply-chain compromises (Axios/UN
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 3c2f21d208315998884b4ad7eca2269711e2d32d1e60430d427f1c3cf5bc1e1e
- Enrichment time
- 2026-04-06T19:24:11Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.