TLP:GREEN  ·  Iran / Israel Conflict
Silence Becomes the Loudest Warning:

Iran's Cyber Forces Go Quiet as Critical Vulnerabilities Explode

CRITICAL. Day 199 of open US-Iran hostilities. Three CVSS 9.8-10.0 zero-days hit CISA KEV in 48 hours - Cisco Secure Email Gateway, GitLab, and Gitea - while MuddyWater and the entire pro-Iran hacktivist ecosystem have gone silent for 39 days. This synchronized silence during an active shooting war is unprecedented and matches the pattern that has preceded every major Iranian cyber escalation on record.

I am a
My sector

DevelopmentSignificance
Three CVSS 9.8-10.0 vulnerabilities hit CISA KEV in 48...All three are deployed across military, government, and DIB networks
Active state-level exploitation of Gitea by Chinese...Proves the exploit chain works at scale
Iranian aerospace phishing campaign refreshed Sep 15...Active operations against defense supply chain
New Iranian C2 server provisioned on state telecom...Suggests operational confidence and state sanction
MuddyWater silence reaches 39 days - the longest gap...Historically precedes major escalation
APT42 TAMECAT nuclear campaign refreshed Sep 14...Intensifying IRGC-IO intelligence collection
Four ICS/medical advisories affect pipeline...All within Iranian targeting scope

PhaseTimeframeCyber Activity
Conflict beginsFeb 28, 2026US-Iran open hostilities begin, activating Iranian cyber retaliation...
Silence begins, water systems compromisedAug 7 - Sep 2, 2026MuddyWater's 39-day silence begins; CISA discloses 100+ US water...
Infrastructure pre-positioningSep 8-9, 2026New Iranian C2 IP appears on TIC Iran state telecom; FortiOS added to...
Vulnerability surgeSep 11-14, 2026GitLab (CVSS 10.0) and Cisco SEG (CVSS 9.8) added to KEV; new...
Current (Day 199)Sep 15, 2026UNC6446 aerospace phishing refreshed; Red Heron Gitea exploitation...

CVE-2026-76461 is a pre-auth SQL injection in Cisco AsyncOS chaining to root command execution. A crafted email transiting the gateway exploits it - no credentials, no user interaction, the email doesn't even need to be opened.

MuddyWater, APT34, and APT42 all rely heavily on spearphishing. This vulnerability converts the infrastructure...

T1190T1059.004T1068

GitLab (CVSS 10.0): unauthenticated arbitrary file read via the commits API exposes source code, CI/CD secrets, SSH keys, and deployment credentials. Affects 18.7 through unpatched 19.x.

Gitea (CVSS 9.8): actively exploited by Chinese actor "Red Heron" across 7 countries. Register account, craft malicious...

T1190T1005T1552.001T1014

UNC6446 (Mirage Kitten, Imperial Kitten, Nimbus Manticore, TA455, Pioneer Kitten) refreshed its aerospace/defense phishing campaign Sep 15 - fake resume lures on GitHub distributing ScreenConnect installers via miranarts-top[.]cc. Legitimate RMM tools give full remote desktop access through software many organizations whitelist.

T1566.002T1204.002T1219

Active C2 confirmed across four distinct Iranian ISPs - a deliberate resilience strategy. Most significant: a new IP on TIC Iran (state telecom) first seen Sep 8, using non-standard port 7443 with unidentified malware - provisioning on government-controlled telecom suggests state sanction. Also active: Cactus (ASN 213790...

T1071.001T1571T1573

The most important signal this cycle. MuddyWater has been silent 39 days. Simultaneously, every pro-Iran hacktivist persona has gone dark: Handala, Cyber Toufan, DieNet, 313 Team, Banished Kitten. Zero claims, zero defacements, zero DDoS, zero Telegram activity.

Three explanations: centralized stand-down pending a kinetic...

ScenarioProbabilityBasis
MuddyWater breaks silence with new campaign — likely...60–70%39-day retooling gap + C2 infrastructure refresh on ASN 213790 and...
Iranian actors adopt Gitea CVE-2026-60004...40–50%Red Heron demonstrated the exploit works at scale; UNC6446 already...
FortiOS CVE-2025-25249 exploitation confirmed against allied...70–80%KEV-listed Sep 9 with RAT association; Iranian actors (APT33, Pioneer...
Pro-Iran hacktivist personas re-emerge with coordinated IO...25–40%39-day synchronized silence suggests centralized direction; next...
Destructive wiper or ransomware operation against critical...30–45%Flagged in prior cycle as expected within 7–14 days; MuddyWater...
Cisco Secure Email Gateway CVE-2026-76461 weaponized by...35–50%Pre-auth RCE via email transit is a perfect fit for Iranian...

1. Cisco Secure Email Gateway Exploitation (CVE-2026-76461):

Hunt hypothesis: Adversary sends crafted email...

2. GitLab Unauthenticated File Read (CVE-2026-85706):

Hunt hypothesis: Adversary queries GitLab commits...

3. Gitea RCE and Rootkit Deployment (CVE-2026-60004 / JITTERLY / SIXZUT):

Hunt hypothesis: Adversary registers account on...

4. Iranian C2 Communication:

Hunt hypothesis: Compromised internal hosts beacon...

5. UNC6446 Aerospace Phishing / ScreenConnect Abuse:

Hunt hypothesis: Employees in aerospace/defense...

6. APT34 Malware Artifact:

Hunt hypothesis: APT34 (OilRig/Hexane/Chrysene)...

ThreatATT&CK
1. Cisco Secure Email Gateway Exploitation (CVE-2026-76461)T1190 T1059.004 T1068
2. GitLab Unauthenticated File Read (CVE-2026-85706)T1190 T1005 T1552.001
3. Gitea RCE and Rootkit Deployment (CVE-2026-60004 / JITTERLY /...T1190 T1014 T1046
4. Iranian C2 CommunicationT1071.001 T1571 T1573
5. UNC6446 Aerospace Phishing / ScreenConnect AbuseT1566.002 T1204.002 T1219
6. APT34 Malware ArtifactT1105
IOC Blocking Table:
217.60.241[.]1778.39.51[.]2395.38.161[.]209185.93.89[.]4377.90.185[.]118192.253.248[.]65176.46.152[.]4677.90.185[.]248miranarts-top[.]cc

Block above at perimeter/DNS, plus the ScreenConnect installer URL...

Hunting Hypotheses:
H1
Cisco SEG already exploited via crafted email
Monitor SEG logs for unexpected child processes, anomalous SQL patterns, and outbound connections.
H2
GitLab already queried for unauthenticated file reads
Monitor access logs for unauthenticated requests to the commits API.
H3
Gitea account registered to stage JITTERLY/SIXZUT
Monitor new registrations from unexpected geolocations, Git hook anomalies, and LD_PRELOAD manipulation.
H4
Internal host already beaconing to Iranian C2
Alert on outbound connections to the IOC IPs above; hunt retroactively in DNS/NetFlow logs.
H5
Aerospace employee already targeted via fake resume lure
Alert on traffic to miranarts-top[.]cc and ScreenConnect MSI downloads from non-corporate sources.

Financial Services
SWIFT, CI/CD Pipelines
Primary threat
Cactus-tagged infrastructure (ASN 213790) actively targets fintech alongside...
Actions
  • Audit Cisco SEG deployments; review CI/CD pipeline security for self-hosted GitLab/Gitea
Energy
Pipeline Monitoring, SCADA
Primary threat
Most acute risk sector. Cyber Av3ngers compromised 100+ US water systems Sep 1; AVEVA Pipeline...
Actions
  • Apply AVEVA CSAF mitigations (ICSA-26-253-01); segment OT from IT networks running Cisco SEG/GitLab/Gitea
Healthcare
DICOM, Integration Engines
Primary threat
Dual threat: direct Cactus-tagged targeting plus new vulnerabilities in medical-specific systems...
Actions
  • Patch Orthanc DICOM and Mirth Connect; hunt Cactus C2 traffic (185.93.89[.]43, 77.90.185[.]118)
Government
DIB, Nuclear/Defense Policy
Primary threat
Primary target of the UNC6446 aerospace campaign and the broader Iranian APT apparatus. Two CVSS...
Actions
  • Audit self-hosted GitLab/Gitea; brief aerospace/defense staff on UNC6446 fake resume phishing
Aviation / Logistics
SAP, Satellite Comms
Primary threat
UNC6446's active campaign and code-repository supply chain risk directly affect this sector.
Actions
  • Block ScreenConnect installs from non-IT sources; review ST Engineering iDirect satellite firmware
No sector cards match the selected filters.

Patch Cisco Secure Email Gateway for CVE-2026-76461 (CVSS 9.8...
Incident Responder
Upgrade Gitea to 1.27.1+ for CVE-2026-60004; disable open...
Incident Responder
Upgrade GitLab CE/EE to 19.1.8/19.2.6/19.3.2 for...
Incident Responder
Block miranarts-top[.]cc and the ScreenConnect...
SOC Analyst
No immediate actions for the selected roles.
Hunt for APT34 hash SHA-256 2b533757086499e224d5717f94a0f...
Threat Hunter
Patch MikroTik RouterOS and JFrog Artifactory Self-Hosted...
Incident Responder
Apply CSAF mitigations for AVEVA and ST Engineering iDirect...
ICS / OT
Deploy LD_PRELOAD rootkit detection - scan Linux servers for...
SOC Analyst
No 7-day actions for the selected roles.
Commission a proactive Telegram/dark web sweep for pro-Iran...
Threat Hunter
Add GitLab/Gitea instance inventory to continuous attack...
CISO / Exec
Develop a MuddyWater resumption playbook - pre-position...
Incident Responder
Review cyber insurance coverage for destructive wiper...
CISO / Exec
No 30-day actions for the selected roles.
The Bottom Line

On Day 199, the threat environment is defined by a single dangerous asymmetry: the attack surface is expanding at an unprecedented rate while the adversary's most capable operators have gone dark. Three CVSS 9.8-10.0 vulnerabilities in 48 hours. Active state-level exploitation of code repositories with rootkit deployment. Iranian C2 infrastructure refreshing on state telecom. And 39 days of silence from MuddyWater and every tracked pro-Iran hacktivist group - the longest quiet period since this...

1
Patch today.
2
Hunt today.
3
Brief your teams today. The window between capability accumulation and capability employment is closing.
No items found.