Iran-Linked Hackers Breach FBI Director’s Personal Email, Hit Stryker With Wiper Attack

2026-03-29T07:24:06Zdfc55313f30424eba79d30466caf38e3d9e4e6d164690d3aee3e0cc67f019b50
CI/CD compromiseCISA KEVCSP bypassing exfiltration','Anthropic Claude extension XSS','LaCVE-2025-53521CVE-2026-3055Citrix NetScalerCorunaDarkSwordF5 BIG-IP APMHandala Hack TeamIran-linkedOAuth abusePyPI compromiseStrykerTeamPCPTrivyWebRTC skimmeractive exploitationdevice-code phishingiOS exploit kitlitellmnation-state activitysupply chain compromisetelnyxwiper

What happened

A broad set of high-impact cyber incidents and vulnerabilities: Iran-linked Handala Hack Team breached FBI Director Kash Patel’s personal email and leaked data while also conducting a wiper attack against Stryker; critical vulnerabilities are being actively probed and exploited (Citrix NetScaler CVE-2026-3055 under active recon; F5 BIG-IP APM CVE-2025-53521 added to CISA’s KEV after observed exploitation). Multiple supply-chain compromises by TeamPCP backdoored PyPI packages (telnyx, litellm) via CI/CD abuse, and targeted campaigns include TA446 deploying the DarkSword iOS exploit kit and Coru

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
dfc55313f30424eba79d30466caf38e3d9e4e6d164690d3aee3e0cc67f019b50
Enrichment time
2026-03-29T07:24:06Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.