U.S. Sanctions Iran-Linked Hackers Behind Critical Infrastructure Breaches
2026-08-25T19:24:01Z•7b02077e1e803fe727963817aaf8b8b6511519504b6dd4320552702c4762208f
CVE-2026-18963CVE-2026-19478CVE-2026-21962CVE-2026-61979account-takeoveractive-exploitationai-securityauthentication-bypassbackdoorclickfixcritical-vulnerabilitiesgitlabidentity-and-access-managementkeycloakmalwaremcpmicrosoft-365miniorange-samlmodel-poisoningnpm-supply-chainollamaoracle-weblogicpasskeysphishingratrootkit-like-behaviorweb-application-securitywordpresszero-day
What happened
The document aggregates cybersecurity news covering active exploitation, critical vulnerabilities, phishing campaigns, malware distribution, supply-chain abuse, nation-state operations, and AI/agent security. The highest-risk items include actively exploited Oracle WebLogic/HTTP Server and GitLab flaws, critical Keycloak account takeover, miniOrange SAML authentication bypasses, malicious NemoClaw/Ollama model poisoning, and attacks involving trojanized npm packages and ransomware-access malware delivery.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 7b02077e1e803fe727963817aaf8b8b6511519504b6dd4320552702c4762208f
- Enrichment time
- 2026-08-25T19:24:01Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.