| Development | Why It Matters |
|---|---|
| BANISHED KITTEN wiper campaign validated by... | Handala Hack Team's claims of data destruction against... |
| Arista VeloCloud Orchestrator CVE-2026-93952 (CVSS... | Active zero-day exploitation of SD-WAN orchestrators. Compromise of a... |
| F5 BIG-IP APM OAuth RCE CVE-2026-94127 (CVSS 9.8) | First confirmed wild exploitation of an OAuth-specific vulnerability... |
| Check Point Quantum Gateway CVE-2026-85102 (CVSS 9.8) | Unauthenticated RCE via VPN certificate trust validation bypass... |
| 16 ICS advisories in 48 hours | Siemens-heavy batch includes Industrial Edge Management auth bypass... |
| Tehran-hosted C2 infrastructure active | Agentemis/CobaltStrike beacons on ports 443 and 53, plus... |
| Plugin4Shell and AI-accelerated exploitation | Zero-click RCE class affecting major AI coding agents (Claude Code... |
| U.S.-Iran rhetoric escalation | "Annihilate" vs. "crushing" language detected in diplomatic channels... |
| Phase | Timeframe | Cyber Activity |
|---|---|---|
| Conflict begins | Feb 28, 2026 | Iran-US conflict begins; Iranian cyber operations activate across... |
| PAYLOAD and BANISHED KITTEN claims, water systems compromised | Apr - Aug 2026 | PAYLOAD ransomware breaches a manufacturer via FortiGate VPN... |
| Edge device CVEs emerge | Sep 9-19, 2026 | Check Point Quantum Gateway CVE published; Brevo supply chain attack... |
| KEV surge, wiper validation | Sep 22, 2026 | CISA adds 4 vulnerabilities to KEV; 9 ICS advisories published... |
| Current (Day ~208) - active C2, five concurrent campaigns | Sep 23, 2026 | UNC6446 aerospace phishing updated; Tehran-hosted... |
CrowdStrike now assesses BANISHED KITTEN's (Handala Hack Team) April 2026 claims of data deletion against UAE, Saudi Arabia, and Bahrain government/manufacturing targets as "likely valid" based on screenshot analysis and correlated wiper samples. Confirmed arsenal: GoneXML ransomware, ZeroShred wiper, AllinOneNeo implant, BiBiWiper, plus...
Iranian APTs weaponize KEV additions within 3-7 days. Three new critical CVEs join the active exploitation landscape: Arista VeloCloud Orchestrator (CVSS 10.0, active zero-day, controls SD-WAN routing enterprise-wide), F5 BIG-IP APM OAuth RCE (CVSS 9.8, combines initial access with OAuth token theft), and...
Sixteen ICS/SCADA advisories in 48 hours is the highest two-day volume of this conflict, seven from Siemens. Most critical: Siemens Industrial Edge Management auth bypass (the exact IT-to-OT bridge Cyber Av3ngers and SPECTRAL KITTEN have been developing), lwIP TCP/IP stack full code execution on embedded...
Four IPs geolocated to Tehran hosting active C2: two Agentemis/CobaltStrike BEACON servers (ports 443/53), a Tofsee server, and a Chaos/FakeRyuk/Yashma server on Iranian academic infrastructure (IPM). Port 53 CobaltStrike traffic indicates DNS tunneling - standard Iranian APT tradecraft.
Plugin4Shell: zero-click RCE affecting AI coding agents (Claude Code, OpenAI Codex, GitHub Copilot) via plugin SHA-pinning bypass - no user interaction required since agents auto-update plugins. A new attack surface category Iranian actors could weaponize against developer environments at scale.
AI-accelerated...
| Scenario | Probability | Basis |
|---|---|---|
| Iranian actors attempt exploitation of at least one of today's three... | 75% (HIGH) | Historical pattern: Iranian groups weaponize KEV additions within 3–7... |
| BANISHED KITTEN escalates information operations with new breach... | 50% (MODERATE) | U.S.-Iran rhetoric escalation ("annihilate" vs. "crushing") detected... |
| SPECTRAL KITTEN breaks operational silence with exploitation of... | 35% (LOW-MODERATE) | SPECTRAL KITTEN typically exploits ICS advisories within days... |
| Iranian actors weaponize F5 BIG-IP APM OAuth RCE (CVE-2026-94127) for... | 40% (MODERATE) | The OAuth profile requirement makes this a high-value target for... |
| Ransomware affiliate (ISRL) deploys FortiGate VPN credential... | 30% (LOW-MODERATE) | Stockpile existence confirmed in prior cycles. Deployment timing... |
Hunt hypothesis: Adversaries are scanning for and...
Hunt hypothesis: BANISHED KITTEN has pre-positioned...
Hunt hypothesis: Iranian proxy groups are probing...
Hunt hypothesis: Adversaries are exploiting F5...
| Threat | ATT&CK |
|---|---|
| 1. Edge Device Exploitation Monitoring | T1190 T1133 T1078... |
| 3. BANISHED KITTEN Wiper Pre-Positioning | T1485 T1486 T1489... |
| 4. ICS/OT Network Monitoring | T1190 T0890 T0816... |
| 5. OAuth and Identity Abuse | T1078 T1550.001 |
Block the above at perimeter firewalls, proxies, and DNS. Hashes...
217.60.241[.]17:443, 87.107.191[.]39:53, 217.60.241[.]39:431, 94.184.37[.]68:8080 - Hunt for DNS queries to unusual ports (port 53 traffic to non-DNS-server IPs is a strong C2 indicator) - Monitor for CobaltStrike BEACON behavioral signatures: regular interval callbacks, named pipe usage, reflective DLL injection - Alert on any traffic to AS51396 (Pfcloud UG) and AS44436 (Toosee Ertebatat Damavand) — these ASNs host confirmed Iranian C2- Audit third-party JS/CDN dependencies and implement SRI tags; patch or disable F5 OAuth Authorization Server profiles
- Verify IT/OT segmentation for Siemens Industrial Edge Management; patch VCO On-Prem within CISA's 3-day window
- Patch Linux kernel on medical imaging/EHR systems; patch Acronis Backup for CVE-2026-87886
- Prioritize Check Point and Arista VCO patching for compliance deadlines; request UNC6446 IOC packages
- Patch VCO On-Prem immediately; brief security teams on current UNC6446 phishing TTPs
Seven months into this conflict, Iranian cyber operations have matured from opportunistic exploitation to industrialized, multi-vector campaigns spanning edge devices, OT systems, cloud identity infrastructure, and destructive wiper deployments simultaneously. The validation of BANISHED KITTEN's destructive capability, combined with three CVSS 9.8-10.0 edge device vulnerabilities under active exploitation, means the question is not whether these vulnerabilities will be weaponized by Iranian...