Iran-Linked Hackers Disrupt U.S. Critical Infrastructure by Targeting Internet-Exposed PLCs

2026-04-08T07:24:06Ze039e0c1ff300c2b7e8ca81575bca418692d4514d58cb02faa2fc5ddc29ce0f1
APT28BYOVDChina-linkedComfyUIDNS-hijackingDPRK-linkedEDR-bypassFlowiseGPUBreachIran-linkedMedusaOT-securityPLCQilinSOHO-router-compromiseTA416UNC1069Warlockcryptominingnation-statenpm-malwareprivilege-escalationransomwareremote-code-executionsupply-chain

What happened

A large set of high-impact threats and active exploitations were reported across critical infrastructure, open-source AI tooling, SOHO routers, supply chains, and enterprise software. Highlights include Iran-linked actors targeting internet-exposed PLCs causing operational disruption; APT28 compromising MikroTik/TP-Link routers for DNS hijacking; an actively exploited CVSS 10.0 RCE in Flowise with 12k+ exposed instances; Docker Engine authorization-bypass (CVE-2026-34040); FortiClient EMS pre-auth API bypass exploited in the wild (CVE-2026-35616); widespread cryptomining targeting exposed Comf

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
e039e0c1ff300c2b7e8ca81575bca418692d4514d58cb02faa2fc5ddc29ce0f1
Enrichment time
2026-04-08T07:24:06Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.