Iran-Linked Password-Spraying Campaign Targets 300+ Israeli Microsoft 365 Organizations
2026-04-07T01:24:16Z•5df866e5d97f303e81310c50fd4fdc96c3b7df4065ca22d85347b9c9b889158c
AGEWHEEZEAxios compromiseBYOVDCERT-UA impersonationDPRKDarkSwordDrift theftEDR bypassGitHub C2Iran-linkedLNK decoysMicrosoft 365OAuth phishingPHP cookie-controlled web shellsPlugXQilinSparkCatUNC1069Warlockdurable noncemsimg32.dllnation-statenpm malicious packagespassword-sprayingsupply-chain
What happened
April 2026 reporting highlights a spike in both nation-state and financially motivated campaigns exploiting high‑severity flaws and supply‑chain weaknesses. Active exploitation includes Fortinet FortiClient EMS (CVE-2026-35616, pre‑auth access bypass, CVSS 9.1) and Cisco IMC/SSM (CVE-2026-20093, CVSS 9.8), while mass credential harvesting abused the React2Shell bug (CVE-2025-55182) across hundreds of Next.js hosts. Notable incidents: a DPRK-linked six‑month social engineering theft of $285M from Drift, UNC1069 compromise of the Axios npm package, widespread malicious npm packages and npm/Strap
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 5df866e5d97f303e81310c50fd4fdc96c3b7df4065ca22d85347b9c9b889158c
- Enrichment time
- 2026-04-07T01:24:16Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.