149 Hacktivist DDoS Attacks Hit 110 Organizations in 16 Countries After Middle East Conflict
2026-03-05T14:21:48Z•72ea2b92db264a699b4100a18aaa4a34db148fa1848ff5bb2f9e9863f89ddeb4
AI-assisted attacksAPT41CISA-KEVChrome vulnerabilityCobalt StrikeCorunaCyberStrikeAIDDoSFreePBX web shellsGoogle Drive C2Havoc C2MFA bypassMSHTML 0-dayOAuth redirect abusePackagistQualcomm AndroidRATSilver DragonStarkiller phishingVMware Ariaexploit-chainshacktivistiOS exploit kitnpmsupply-chain
What happened
A broad set of active threats and vulnerabilities was reported: surge in hacktivist DDoS activity tied to Middle East conflict; a powerful Coruna iOS exploit kit (five chains, 23 exploits) targeting iOS 13–17.2.1; malicious Packagist and npm packages delivering cross‑platform RATs; APT activity (Silver Dragon linked to APT41 using Cobalt Strike and Google Drive C2; APT28 tied to an MSHTML 0‑day); and multiple actively exploited or patched high‑severity flaws added to advisories/KEV. Additional notable issues include OAuth redirect abuse for credential/token theft, MFA bypass via the Starkiller
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 72ea2b92db264a699b4100a18aaa4a34db148fa1848ff5bb2f9e9863f89ddeb4
- Enrichment time
- 2026-03-05T14:21:48Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.