TLP:GREEN  ·  Iran / Israel Conflict
Peak Danger:

What CISOs Must Do Before Iran's Next Strike

HIGH. The convergence of military escalation, a confirmed Iranian-directed bomb plot against a NATO air base, a critical Fortinet zero-day under active exploitation, and Microsoft's confirmation that 39% of Iranian cyber operations now target Israel signals the most dangerous phase of the conflict since hostilities began seven months ago. A CVSS 9.8 FortiMail zero-day carries a CISA deadline of October 4 - two days away.

I am a
My sector

DevelopmentSignificance
A new Fortinet zero-day is being actively exploited. CVE-2026-104286 (CVSS 9.8) in FortiMail enables unauthenticated RCE...Email security gateways are a crown jewel for espionage-focused adversaries
Microsoft quantified the scale of Iran's cyber war. The 2026 Digital Defense Report confirms 39% of Iranian cyber...Israel is now the #2 most-targeted country globally
Iran directed a physical bomb plot against a US air base in the UK. Five arrested near RAF Fairford Sep 28; a dual...First confirmed Iranian-directed physical attack plot against NATO military infrastructure
BANISHED KITTEN's malware arsenal expanded with joint allied advisory confirmation of ChosenBrick RAT, attributed via...The Handala Hack Team is confirmed as an IRGC-linked front operation
The US deployed a third carrier strike group toward Iran. USS Theodore Roosevelt and 2,000+ Marines departed Sep 28...Trump signaled post-midterm escalation is "possible"
MuddyWater and APT42 have entered coordinated operational silence exceeding three weeks, alongside Cavern Manticore and...A reliable pre-campaign indicator during peak kinetic escalation
PULSAR KITTEN confirmed exploiting TeamCity CVE-2026-63077 to deploy SlumberRAT against aerospace and defense CI/CD...Extends Iranian supply chain compromise into software build infrastructure

PhaseTimeframeCyber Activity
Conflict begins, mass credential theftFeb 28 - Jun 2026US-Israeli conflict with Iran begins, shifting Iranian cyber operations to wartime tempo; ~75,000 FortiGate firewall credentials...
ChosenBrick advisory, Citrix mega-disclosureMid-Sep - Sep 27, 2026Joint NCSC/FBI/AIVD advisory confirms BANISHED KITTEN/Handala's ChosenBrick RAT; Citrix discloses 8 NetScaler CVEs (two CVSS 10.0)...
RAF Fairford plot, carrier deploymentSep 28-29, 2026UK arrests near RAF Fairford in a bomb plot targeting the F-35/B-2 hub; USS Theodore Roosevelt and Makin Island MEU depart for Iran...
KEV surge, supply chain targetingSep 30 - Oct 1, 2026Cisco SD-WAN and FortiMail both added to KEV; PULSAR KITTEN confirmed exploiting TeamCity to deploy SlumberRAT against aerospace/defense...
Current (Day ~216) - scale confirmed, arrest madeOct 2, 2026Microsoft's Digital Defense Report quantifies Iran's cyber war (39% targets Israel, 21% ransomware increase); a dual UK/Iranian citizen...

CVE-2026-104286 adds FortiMail to an exploitation surface Iranian APTs have long preferred (PULSAR KITTEN exploited CVE-2018-13379 historically; the June 2026 mass compromise of 75,000 FortiGate credentials feeds Storm-2570's Cactus/Qilin ransomware deployments). A compromised FortiMail gives an attacker email interception, credential...

T1190T1505.003T1059

BANISHED KITTEN operates one of the most diverse Iranian malware arsenals: ChosenBrick (espionage RAT), WovenMist, GoneXML (ransomware), ZeroShred and BiBiWiper (wipers), AllinOneNeo, MisleadingAxe, PhantomBlade, plus abuse of NetBird/ZeroTier. The joint NCSC/FBI/AIVD advisory represents three allied agencies publicly attributing Iranian...

T1219T1486T1485

MuddyWater (MOIS) and APT42 (IRGC-IO) have been coordinately silent exceeding three weeks - historically a reliable pre-campaign indicator. Cavern Manticore (MOIS-linked, modular C2/ICS capability) has produced zero new reporting, and UWAYS QARANI (Houthi-affiliated) has gone quiet despite active Houthi kinetic participation. When multiple...

Active or recent Iranian exploitation now spans FortiMail (CVSS 9.8), Cisco Catalyst SD-WAN (CVSS 9.8), Citrix NetScaler (two CVSS 10.0, WHIPSHOT/SLAPSHOT), FortiGate (75K credentials compromised), JetBrains TeamCity (SlumberRAT), Zimbra, and Unitronics PLCs (HYDRO KITTEN/Cyber Av3ngers ICS targeting). This breadth reflects a deliberate...

T1190

A third carrier strike group (USS Theodore Roosevelt, 2,000+ Marines) is projected to bring ~60,000 troops near Iran by late November. Iran's ceasefire proposal was rejected, and Trump has signaled post-midterm escalation is possible. Israel's National Cyber Directorate has stated there is no ceasefire in cyber - even a diplomatic breakthrough...

ScenarioProbabilityKey Drivers
Iranian retaliatory cyber operation (wiper or DDoS) against US/Israeli targets70% — HIGHThird carrier deployment + ceasefire rejection + midterm political window
New Fortinet exploitation attributed to an Iranian APT55% — MODERATE-HIGHCVE-2026-104286 active exploitation + documented Iranian preference for Fortinet
BANISHED KITTEN expansion to additional NATO countries50% — MODERATERAF Fairford precedent; UK/Gulf expansion already confirmed
HYDRO KITTEN (IRGC-CEC) / Cyber Av3ngers ICS-OT activation45% — MODERATEKinetic escalation post-midterms; Houthi coordination potential
MuddyWater (MOIS) or APT42 (IRGC-IO) breaking operational silence with major campaign40% — MODERATE3+ weeks of silence during escalation = historical pre-campaign indicator
Diplomatic breakthrough or de-escalation15% — LOWCeasefire rejected; no new proposals; Trump signals escalation

DetectionATT&CK IDData SourcePriority
FortiMail path traversal / null byte in HTTP requestsT1190Web application firewall, FortiMail logsCRITICAL
Password spray against Entra ID / M365T1110.003Azure AD sign-in logs, SIEMHIGH
NetBird / ZeroTier unauthorized installationT1219EDR, software inventoryHIGH
Anomalous file writes on Fortinet appliancesT1505.003FortiAnalyzer, syslogHIGH
TeamCity / CI-CD unauthorized pipeline changesT1195.002CI/CD audit logs, SCM webhooksHIGH
Wiper behavior (mass file deletion/encryption)T1485, T1486EDR, file integrity monitoringHIGH
Outbound connections to known APT34 infrastructureT1071Firewall, proxy, DNS logsMEDIUM
IOC Blocking Table:
43.231.4[.]745.131.66[.]10664.20.53[.]23062.60.226[.]102.58.16[.]86irancepat[.]xyzFileTransfer[.]io

Block the above at perimeter firewalls, proxies, and DNS. Hashes: 2b533757086499e224d5717f94a0f4c33e705398a7610219d82b9d3bc8763378...

Hunting Hypotheses:
HUNT 01 · T1190
T1190
FortiMail path traversal / null byte in HTTP requests — T1190 — Web application firewall, FortiMail logs — CRITICAL
HUNT 02 · T1110.003
T1110.003
Password spray against Entra ID / M365 — T1110.003 — Azure AD sign-in logs, SIEM — HIGH
HUNT 03 · T1219
T1219
NetBird / ZeroTier unauthorized installation — T1219 — EDR, software inventory — HIGH
HUNT 04 · T1505.003
T1505.003
Anomalous file writes on Fortinet appliances — T1505.003 — FortiAnalyzer, syslog — HIGH
HUNT 05 · T1195.002
T1195.002
TeamCity / CI-CD unauthorized pipeline changes — T1195.002 — CI/CD audit logs, SCM webhooks — HIGH
HUNT 06 · T1485
T1485, T1486
Wiper behavior (mass file deletion/encryption) — T1485, T1486 — EDR, file integrity monitoring — HIGH
HUNT 07 · T1071
T1071
Outbound connections to known APT34 infrastructure — T1071 — Firewall, proxy, DNS logs — MEDIUM

Financial Services
SWIFT, Core Banking
Primary threat
Iranian ransomware against Israeli financial institutions up 21% YoY; spillover targeting expected...
Actions
  • Harden SWIFT/core banking segmentation; validate offline backups against ZeroShred/BiBiWiper wiper scenarios
Energy
ICS/OT, Modbus/SCADA
Primary threat
HYDRO KITTEN has demonstrated capability and intent against ICS/OT including Unitronics PLCs; their...
Actions
  • Audit internet-exposed OT/ICS interfaces; verify Modbus/DNP3/OPC-UA cannot traverse IT/OT boundaries uninspected
Healthcare
Email Security, Clinical Networks
Primary threat
IMPERIAL KITTEN targets healthcare per Microsoft's report; FortiMail compromise is especially...
Actions
  • Patch or isolate FortiMail/Citrix/Cisco appliances in healthcare perimeters; test manual fallback for pharmacy/lab/imaging systems
Government
Classified Systems, Physical Security
Primary threat
Primary Iranian espionage target; RAF Fairford demonstrates willingness to target...
Actions
  • Enforce phishing-resistant MFA given >99% password-spray cloud intrusions; coordinate physical and cyber security post-Fairford
Aviation / Logistics
CI/CD, Supply Chain
Primary threats
PULSAR KITTEN, UNC6446/GRITCASPIAN, and IMPERIAL KITTEN all confirmed targeting aerospace/defense...
Actions
  • Audit CI/CD pipelines for unauthorized modifications; pin dependencies to verified commit SHAs
No sector cards match the selected filters.

Block FortiMail management interface access from the internet...
Incident Responder
Hunt for APT34 IOC 43.231.4[.]7 and the associated hash across...
SOC Analyst
Verify Cisco SD-WAN patching for CVE-2026-76504 and Citrix...
Incident Responder
Brief executive leadership on the RAF Fairford plot - Iranian...
CISO / Exec
No immediate actions for the selected roles.
Deploy detection for BANISHED KITTEN malware families...
SOC Analyst
Audit all Fortinet appliance inventory - FortiGate and...
Incident Responder
Audit JetBrains TeamCity instances for CVE-2026-63077; check...
Incident Responder
Implement enhanced Entra ID password-spray monitoring: >10...
SOC Analyst
No 7-day actions for the selected roles.
Implement phishing-resistant MFA (FIDO2) for all...
IAM Analyst
Commission a threat assessment modeling simultaneous wiper +...
CISO / Exec
Conduct a tabletop exercise for Iranian destructive attack...
CISO / ExecIncident Responder
Establish or refresh CISA/FBI/ISAC relationships - information...
CISO / Exec
No 30-day actions for the selected roles.
The Bottom Line

The Iran conflict has entered its most dangerous cyber phase. Military escalation increases the probability of retaliatory cyber operations. Failed diplomacy removes the only off-ramp. The RAF Fairford plot demonstrates willingness to strike NATO assets directly, with cyber pre-positioning as the expected parallel. Sustained cyber operations confirm there is no ceasefire in cyberspace. And operational silence from MuddyWater, APT42, Cavern Manticore, and UWAYS QARANI during peak escalation is...

1
Patch FortiMail before October 4.
2
Hunt for APT34 infrastructure in your logs today.
3
Deploy phishing-resistant MFA and test your IR plan this month.
No items found.