Security News

Cybersecurity news aggregator

CRITICAL News Dark Reading

Iran's Cyber Crosshairs Focus Beyond Critical Infrastructure

The article warns that Iranian state-linked threat groups like Handala and Ababil of Minab are conducting opportunistic, wide-scale attacks beyond critical infrastructure, targeting any organization with internet-facing vulnerabilities such as exposed PLCs, unpatched VPNs, or stolen credentials. These groups exploit readily available weaknesses to deploy ransomware, cause disruptive data wipes, or deface systems, as demonstrated in attacks against a medical device manufacturer and a logistics GPS platform. The primary attack vectors are the exploitation of known, unpatched vulnerabilities and the use of compromised credentials obtained from commodity malware and illicit markets.
Read Full Article →

Informa TechTarget | SearchSecurity Cybersecurity Dive InformationWeek Channel Dive Explore our brands Dark Reading Resource Library Black Hat News Omdia Cybersecurity Advertise NEWSLETTER SIGN-UP Cybersecurity Topics World The Edge DR Technology Events Resources CYBER RISK CYBERATTACKS & DATA BREACHES CYBERSECURITY OPERATIONS COMMENTARY Iran's Cyber Crosshairs Focus Beyond Critical Infrastructure Obscurity isn't a defense. If your company has any Internet-facing vulnerability, you're at risk from multiple threats. Joe Slowik,Senior Manager, Gigamon July 9, 2026 5 Min Read SOURCE: ZENOBILLIS VIA ALAMAY STOCK PHOTO OPINION For many CISOs, the headlines detailing Iranian-linked strikes on water utilities and power grids trigger a dangerous sense of immunity: "I'm not a utility; I'm not a target." There is a comforting, yet flawed, assumption that these operations are merely geopolitical theater confined to the high-stakes arena of critical infrastructure. But in the modern threat landscape, obscurity is not a defense, and "non-critical" status is not a shield. If your organization has a digital heartbeat and an Internet-facing vulnerability, you're already at risk from multiple potential threats, whether you realize it or not. The groups behind recent attacks, including Handala, Ababil of Minab, and others operating within Iran's cyber-influence ecosystem, cloak themselves in the mask of cyber activism, or "hacktivism." They are largely opportunistic. They aren't specifically hunting targets; they are on "Shodan Safaris" hunting easily exploited vulnerabilities or insecure systems. A law firm or logistics hub with an exposed programmable logic controller or an unpatched VPN is an easy, appealing target. LOADING... Related:AI Gateways Offer Attackers the Keys to the Kingdom Many companies don't realize how much of their infrastructure is externally accessible, or how little it takes to exploit what's exposed. Handala, which the US Justice Department has attributed to Iran's Ministry of Intelligence and Security, remotely wiped over 200,000 hosts in an attack on Stryker, a medical device manufacturer, in March. The incident disrupted manufacturing and impacted their first-quarter earnings. More recently, Ababil of Minab compromised Vyncs, a GPS tracking platform used across the logistics sector, taking systems offline and defacing its website. In the Stryker incident, the attack was likely made possible through credentials stolen via commodity malware and provided for sale via illicit channels — emphasizing the opportunistic nature of these events. Separating Signal From Hacktivist Noise The headlines around Iran-related cyber operations tend to either treat every claimed attack as an impending catastrophe, or dismiss it as unsubstantial incidents that amount to a denial of service or a defaced website. Both reactions miss something. A notionally "unsophisticated" attack may highlight weaknesses that, in other hands, could result in far worse impacts to victim organizations. Operational technology (OT)-related incidents illustrate the problem. Attackers typically find their way into victim networks through old exploits or default credentials on externally exposed systems. While concerning and opening the possibility to various outcomes, physical safety systems and engineering constraints limit what adversaries can actually do. So, they produce contextless screenshots of devices, post them on Telegram, and call it an "infrastructure attack." LOADING... Related:Mexico's New Cyber Plan Faces Its First Real Test While the impact is limited, the weaknesses that enabled access are not. The same entry points found through opportunistic scanning are available to more sophisticated threat actors. A more capable adversary with actual domain knowledge could follow the same initial access route and potentially do more serious damage. What these low-sophistication intrusions reveal, in practical terms, is which environments are accessible. That information doesn't disappear once the hacktivist moves on. Get Your House in Order The attack patterns here are predictable. Here is where to start: Attack surface management. The first question is simple: What can someone on the Internet actually reach in your environment? The answer is often different from what internal asset inventories show. Forgotten remote access points and unmanaged devices are the most common entry points — and the easiest to miss. Authentication. Default credentials and weak or absent multifactor authentication (MFA) remain among the most consistent contributing factors across these incidents. Phishing-resistant MFA should be the minimum for anything externally accessible. Audit which externally accessible systems lack MFA and start there. Default vendor credentials on OT or remote access systems should be treated as an open door, emphasizing the need to ensure compensating controls are in place to prevent potential adversary access. Patch management. The vulnerabilities typically targeted are neither new nor sophisticated; they're just unaddressed. For example, recent Iran-linked attacks in the US likely weaponized CVE-2021-22681, a 5-year-old vulnerability. Prioritize patching and hardening external-facing assets first, then work to critical systems and similar. For OT and related technologies, take advantage of maintenance cycles and similar downtime to apply updates whenever possible. Threat awareness. Understanding what is being targeted in a given sector — and how these groups announce and amplify their operations — requires visibility into the threat environment as it develops, not after the fact. That means monitoring the channels these groups actually use, such as Telegram posts and leak sites, not just waiting for formal advisories. By the time a government advisory is published, the activity it describes has often been underway for weeks. Continuous monitoring. Passive defenses are not sufficient. Security teams must be able to detect anomalous activity across external-facing assets and act on it quickly. Unusual logon activity, such as impossible travel scenarios or brute-force detection, are needed to identify when adversaries are attempting to access environments. Know what normal looks like on your external-facing assets so you can spot when something isn't. These groups aren't quiet for long — a Telegram post claiming credit can come hours after initial access. Related:'GitLost' Flaw Leaks Private Data From GitHub's Agentic Workflows Currently, most activity from Iranian-linked hacktivist groups is at best moderately disruptive although in some cases, like Stryker, genuinely damaging. The lesson to take from these events, even if they are mostly in the realm of "cyber nuisance," is how such entities are gaining access to victims. These same pathways can (and in many cases are) leveraged by more concerning actors for more effective results. By extracting this signal from the overall noise of hacktivist events, defenders and decision-makers can better prepare for genuine threats. Read more about: Opinion About the Author Joe Slowik Senior Manager, Gigamon Joe Slowik leads intelligence and detection operations at Gigamon. Joe has more than ten years of experience across multiple roles in the US government and commercial sector performing cyber threat intelligence research, incident response, and threat hunting operations. Want more Dark Reading stories in your Google search results? ADD US NOW More Insights Industry Reports The State of Cloud Security: The Latest Challenges The total economic impact™ of Snyk How Organizations Are Managing Incident Response How Enterprises Are Developing Secure Applications Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy Access More Research Webinars Governing the Agent; Identity Security in the Age of Autonomous AI Securing the AI Era: Shadow AI, AI Agents, and Why AI Detection and Response Changes Everything Practical Zero Trust Implementation on a Budget in the Age of Mythos Building a Risk Based Vulnerability Management Program Threat Hunting That Gets Big Results Despite Small Budgets More Webinars You May Also Like CYBER RISK How Can CISOs Respond to Ransomware Getting More Violent? by James Doggett JAN 28, 2026 CYBER RISK US Cyber Pros Plead Guilty Over BlackCat Ransomware Activity by Alexander Culafi JAN 05, 2026 CYBER RISK Switching to Offense: US Makes Cyber Strategy Changes by Robert Lemos, Contributing Writer NOV 21, 2025 CYBER RISK Microsoft Exchange 'Under Imminent Threat,' Act Now by Arielle Waldman NOV 12, 2025 Editor's Choice CYBERSECURITY OPERATIONS Why Identity Security Is Your Cyber Career Entry Point byKristina Beek JUN 30, 2026 CYBERATTACKS & DATA BREACHES EdTech Attackers Shift From Schools to Their Software Suppliers byArielle Waldman JUN 25, 2026 CYBERSECURITY OPERATIONS Do CISOs Need a Code of Ethics? byDark Reading Editorial Team JUN 24, 2026 Want more Dark Reading stories in your Google search results? Keep up with the latest cybersecurity threats, newly discovered vulnerabilities, data breach information, and emerging trends. Delivered daily or weekly right to your email inbox. SUBSCRIBE LOADING... AUG 1-6 | MANDALAY BAY, LAS VEGAS USE CODE: DARKREADING & SAVE $200 ON A BRIEFINGS PASS OR $100 ON A BUSINESS PASS The premier cybersecurity event returns. GET YOUR PASS Discover More Black Hat Omdia Working With Us About Us Meet the Editors Advertise Reprints Join Us NEWSLETTER SIGN-UP Follow Us Copyright © 2026 TechTarget, Inc. d/b/a Informa TechTarget. This website is owned and operated by Informa TechTarget, part of a global network that informs, influences and connects the world’s technology buyers and sellers. All copyright resides with them. Informa PLC’s registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. TechTarget, Inc.’s registered office is 275 Grove St. Newton, MA 02466. Home| Cookie Policy| Privacy| Terms o

Share this article