| Date | Development | Significance |
|---|---|---|
| Jul 27 | CVE-2026-16232 (Check Point SmartConsole, CVSS 9.1) added to CISA KEV | Auth bypass grants full admin control; exploitation confirmed against a "very small number of customers" — expected to grow rapidly |
| Jul 27 | CVE-2025-68686 (FortiOS symlink persistence) added to CISA KEV | Defeats prior patch remediation — organizations may still harbor persistent access from before they patched |
| Jul 28 | Cavern Manticore (MOIS) threat profile refreshed | High operational tempo; modular .NET C2 framework designed to evade analysis |
| Jul 28 | Cactus ransomware C2 confirmed active on Iranian ASNs (213790, 215930, 34918) | State-criminal infrastructure convergence validated, confidence 77–91 |
| Jul 23 | Seven CISA ICS advisories published (IEC 61850, IEC 60870-5-104, Rockwell, Johnson Controls, Panduit) | Foundational power grid protocols exposed to unauthenticated attack |
| Jul 25–28 | APT42's TAMECAT backdoor silent 3+ days; BELLACIAO/SHELLAFEL campaign updated Jul 28 | Likely tooling rotation rather than operational pause |
| Jul 27 | PULSAR KITTEN profile refreshed — confirmed targeting a U.S. transportation company via its German subsidiary | Demonstrates deliberate exploitation of international subsidiaries as weaker entry points |
| Phase | Timeframe | Cyber Activity |
|---|---|---|
| Escalation begins | 2026-02-28 | Iran-Israel conflict escalation begins; marks start of sustained state-on-state cyber operations |
| Coordination & tooling buildup | Jul 18 – 23 | MuddyWater/Dalbit ransomware samples confirmed active (defense, energy, government); APT42 AI-generated phishing with TAMECAT against defense officials (Jul 21); CISA publishes 7 ICS advisories exposing IEC 61850/60870-5-104 (Jul 23) |
| Active exploitation & retaliation window | Jul 25 – 28 | Qilin RaaS affiliates exploit Fortinet/Palo Alto/Check Point/Citrix VPNs, ~75,000 FortiGate devices compromised (Jul 25–27); Ukrainian strike eliminates Iran's Caspian Sea maritime corridor (Jul 26); APT42 infrastructure refreshed (Jul 26); CVE-2026-16232 (Check Point) and CVE-2025-68686 (FortiOS) added to CISA KEV (Jul 27); PULSAR KITTEN targeting U.S. transportation via German subsidiary confirmed (Jul 27) |
| Current (Day 150) | Jul 28, 2026 | Cavern Manticore (MOIS) Operation Epic Fury profile refreshed at high tempo; Cactus ransomware C2 confirmed on Iranian ASN 213790 (confidence 91) — state-criminal infrastructure convergence validated |
CVE-2026-16232 represents the most urgent patching priority this week. An unauthenticated attacker can obtain a full administrative token for any Check Point SmartConsole management server accessible from the internet without Trusted Client restrictions. The implications are severe: complete firewall policy manipulation, VPN credential extraction, and network-wide visibility for the attacker.
CVE-2025-68686 is equally concerning for a different reason — it defeats the remediation for a previously patched symlink persistence mechanism in FortiOS. Organizations that patched earlier Fortinet vulnerabilities may still harbor persistent access if attackers exploited the original flaw before patching. Affects FortiOS 7.6.0–7.6.1, 7.4.0–7.4.6, and all 7.2/7.0/6.4 branches.
Why it matters: Pioneer Kitten (Fox Kitten, RUBIDIUM) has a documented pattern of weaponizing firewall and VPN authentication bypasses within two weeks of KEV listing. Its known exploit arsenal already includes CVE-2022-47966, CVE-2021-44228, CVE-2022-26134, CVE-2021-34473, and CVE-2018-13379.
Intelligence confirms an operational convergence between Iranian state espionage actors, hacktivist-cover operations, and ransomware-as-revenue groups sharing infrastructure: Pioneer Kitten (IRGC-affiliated espionage), Handala / Banished Kitten (hacktivist-cover operations), and Cactus ransomware (criminal revenue generation).
These actors share IOCs, infrastructure on Iranian ASNs (213790, 34918, 215930), and targeting profiles. The same IPs tagged to Cactus ransomware C2 are co-located on networks hosting LockBit-affiliated infrastructure — a deliberate operational model where state actors use ransomware personas for deniability and revenue while maintaining espionage access. Active C2 on ASN 213790 (Limited Network) is tagged with both IcedID loader delivery and Cactus operations, targeting healthcare, government, education, and technology.
The libIEC61850 vulnerability (ICSA-26-204-06) deserves particular attention. IEC 61850 is the international standard for substation automation communication — it underpins power grid operations globally. The vulnerability allows an unauthenticated network-adjacent attacker to crash IEC 61850 services, creating denial-of-service conditions at substations.
Similarly, lib60870 (ICSA-26-204-07) affects IEC 60870-5-104, the standard for SCADA telecontrol. Both are open-source libraries used across multiple vendor implementations — meaning the blast radius extends far beyond any single product.
Threat actor context: Cyber Av3ngers (IRGC-affiliated) has demonstrated both intent and capability to target water and energy infrastructure. These protocol-level vulnerabilities require no authentication and only network adjacency — a low bar for an actor that has already demonstrated ICS access.
Cavern Manticore — linked to Iran's Ministry of Intelligence and Security (MOIS) — is conducting destructive operations against Israeli government and IT sectors under the campaign name "Operation Epic Fury." The group employs a modular .NET C2 framework with multiple compilation formats as an anti-analysis layer, combined with wiper capabilities.
This actor operates alongside MuddyWater (also MOIS-affiliated) in an apparent division of labor: MuddyWater handles initial access and espionage, while Cavern Manticore executes destructive payloads when political objectives demand visible impact.
A refreshed profile for PULSAR KITTEN reveals targeting of a German branch of a U.S. transportation company — demonstrating the Iranian playbook of attacking Western organizations through their international subsidiaries where security controls may be weaker. The actor deploys SilkySand and SurveyAgent malware, focuses on aerospace, defense, and satellite organizations, and maintains infrastructure overlap with operations against Iraqi telecom entities.
| Scenario | Probability | Timeframe | Indicators to Watch |
|---|---|---|---|
| CVE-2026-16232 exploitation expands beyond initial victims as PoC circulates | 70% | 7 days | Public PoC release, exploitation volume increase in vendor telemetry, additional victim disclosures |
| Coordinated retaliatory cyber operations by Handala/Cyber Toufan/DieNet following kinetic escalation | 70% | 7–14 days | Telegram channel reactivation, new leak sites, DDoS infrastructure provisioning |
| Pioneer Kitten weaponizes CVE-2025-68686 for persistent access to previously-patched FortiGate devices | 55% | 14–21 days | Fortinet-heavy exploit portfolio; symlink persistence bypass enables re-entry |
| APT42 surfaces with BELLACIAO or SHELLAFEL indicators (tooling rotation from TAMECAT) | 50% | 7–14 days | Campaign infrastructure updated Jul 28 but TAMECAT silent 3+ days — active tool-swap pattern |
| Iranian election influence operations surge targeting Israeli elections | 45% | 14–21 days | Historical IO campaigns activate 2–3 weeks before elections; current silence may indicate OPSEC pause before surge |
| Cyber Av3ngers probes libIEC61850 implementations in Israeli/Gulf power infrastructure | 35% | 14 days | Vulnerability requires only network adjacency, targets exact protocol stack in regional power infrastructure |
Alert on SmartConsole admin logins from non-whitelisted source IPs. Monitor for bulk policy export or rule modification events. Correlate with Trusted Client configuration — any management server without this restriction is vulnerable (CVE-2026-16232).
Post-patch integrity verification of FortiOS filesystem. Compare running configuration against known-good baseline. Monitor for FortiGate devices communicating with IPs on ASN 213790 or 215930 (CVE-2025-68686).
Monitor for outbound connections to 77.90.185[.]118, 62.60.130[.]237, 5.202.4[.]18, 185.93.89[.]75. Alert on IcedID-characteristic HTTPS patterns on non-443 ports.
Deploy ICS-aware network monitoring on OT segments. Alert on any non-whitelisted source communicating with IEC 61850/60870-5-104 services (port 102/TCP). Baseline normal MMS traffic patterns and alert on deviations.
Monitor for csc.exe or msbuild.exe invocations outside development environments. Alert on .NET assemblies loaded from temp directories. Behavioral detection for wiper precursors (volume shadow copy deletion, boot record access).
Monitor Windows Event ID 1 (process creation) for profile loading utilities accessing non-standard registry paths. Alert on registry hive file access outside normal logon sequences.
Alert on charmap.exe establishing network connections (should never happen legitimately). Monitor for AutoIT script execution preceded by PowerShell. Block cphost17[.]qhoster[.]net at DNS.
| Threat | ATT&CK |
|---|---|
| Check Point Management Exploitation | T1190 T1078.004 T1098 |
| FortiOS Symlink Persistence | T1190 T1547.009 T1562.001 |
| Cactus/IcedID Delivery Chain | T1566.001 T1204.002 T1071 T1571 |
| ICS Protocol Anomalies | T1499 T0816 T0826 |
| .NET C2 Framework (Cavern Manticore) | T1059.001 T1027 T1071.001 T1485 |
| LegacyHive Registry Technique | T1546 T1003 |
| AutoIT Process Injection (VIPKeylogger) | T1055 T1059.005 T1059.001 |
IPv4s above: Cactus ransomware C2 / IcedID (ASN 213790, 215930, 34918), confidence 77–91. Domain: VIPKeylogger C2 (AutoIT injection campaign). SHA-256 (selected): 028d3de0f0709a18c9928526519e761a08f6766d1eca386e908588f995f44e7f, 0a5cf97e699c8bfacee7f89ebfaa851ff03dd004a58ffde9c609fcc2cd27f250 (Pioneer Kitten/Handala convergence), bcf0ee6ec34d835b2521330f57466e357b95970129e5c0742c6da7c40bda56fb (MuddyWater/MOIS). 14 total SHA-256 hashes available via Anomali ThreatStream Next-Gen.
- Deploy behavioral detection for IcedID HTTPS beacon patterns (POST requests with encoded payloads to non-standard ports)
- Review email gateway rules for RAR attachments containing VBS files; implement detonation sandboxing for compressed archive attachments from external senders
- Watch for process injection into
charmap.exe— a novel evasion technique for financial malware in this campaign
- Conduct emergency inventory of all systems using IEC 61850 MMS or IEC 60870-5-104 protocols; verify network segmentation between corporate IT and OT networks
- Deploy ICS-aware intrusion detection on OT segments monitoring for malformed MMS packets; engage vendors to confirm patch availability
- Implement strict access control lists limiting which systems can communicate on port 102/TCP
- Block all communication with IPs on ASN 213790 (Limited Network) and ASN 34918 (Pishgaman Toseeh) — both confirmed hosting Cactus C2 targeting healthcare
- Verify backup integrity and test restoration procedures for critical clinical systems
- Hunt for SHA-256 hashes associated with Pioneer Kitten/Cactus convergence across endpoint telemetry; review logs for connections to
77.90.185[.]118and5.202.4[.]18
- Implement enhanced monitoring for .NET assembly loading from non-standard paths (Cavern Manticore indicator)
- Review all personnel who received external communications in the past 30 days for APT42-style social engineering; verify no Check Point management servers are internet-accessible without Trusted Client restrictions
- Conduct a tabletop exercise for a wiper scenario; ensure offline backup copies exist for critical government systems
- Audit security controls at international subsidiaries and branch offices — Iranian actors deliberately target weaker links; review for CVE-2022-47966, CVE-2021-44228, CVE-2022-26134, CVE-2021-34473
- Implement network segmentation between subsidiary environments and core transportation/logistics systems
- Deploy detection for AnyDesk (T1219) usage outside approved remote access channels — PULSAR KITTEN uses legitimate remote access tools for persistence
77.90.185[.]118, 62.60.130[.]237, 185.93.89[.]75, 5.202.4[.]18 at perimeter firewalls and DNS sinkholes. Confirmed Cactus ransomware C2, confidence 77–91.cphost17[.]qhoster[.]net at DNS — active VIPKeylogger C2.%TEMP% directories outside development environments (Cavern Manticore indicator).The Iran-Israel conflict is now 150 days old with no indication of de-escalation. Iranian cyber operations are not slowing — they are diversifying. The convergence of state espionage actors with ransomware operations, the targeting of foundational ICS protocols, and the active exploitation of critical network security infrastructure (Check Point, Fortinet) create a threat environment where defensive complacency carries measurable risk. The 70% probability of expanded CVE-2026-16232 exploitation within seven days is not a forecast — it is a countdown.