| Development | Significance |
|---|---|
| Three CVSS 9.8-10.0 vulnerabilities hit CISA KEV in 48... | All three are deployed across military, government, and DIB networks |
| Active state-level exploitation of Gitea by Chinese... | Proves the exploit chain works at scale |
| Iranian aerospace phishing campaign refreshed Sep 15... | Active operations against defense supply chain |
| New Iranian C2 server provisioned on state telecom... | Suggests operational confidence and state sanction |
| MuddyWater silence reaches 39 days - the longest gap... | Historically precedes major escalation |
| APT42 TAMECAT nuclear campaign refreshed Sep 14... | Intensifying IRGC-IO intelligence collection |
| Four ICS/medical advisories affect pipeline... | All within Iranian targeting scope |
| Phase | Timeframe | Cyber Activity |
|---|---|---|
| Conflict begins | Feb 28, 2026 | US-Iran open hostilities begin, activating Iranian cyber retaliation... |
| Silence begins, water systems compromised | Aug 7 - Sep 2, 2026 | MuddyWater's 39-day silence begins; CISA discloses 100+ US water... |
| Infrastructure pre-positioning | Sep 8-9, 2026 | New Iranian C2 IP appears on TIC Iran state telecom; FortiOS added to... |
| Vulnerability surge | Sep 11-14, 2026 | GitLab (CVSS 10.0) and Cisco SEG (CVSS 9.8) added to KEV; new... |
| Current (Day 199) | Sep 15, 2026 | UNC6446 aerospace phishing refreshed; Red Heron Gitea exploitation... |
CVE-2026-76461 is a pre-auth SQL injection in Cisco AsyncOS chaining to root command execution. A crafted email transiting the gateway exploits it - no credentials, no user interaction, the email doesn't even need to be opened.
MuddyWater, APT34, and APT42 all rely heavily on spearphishing. This vulnerability converts the infrastructure...
GitLab (CVSS 10.0): unauthenticated arbitrary file read via the commits API exposes source code, CI/CD secrets, SSH keys, and deployment credentials. Affects 18.7 through unpatched 19.x.
Gitea (CVSS 9.8): actively exploited by Chinese actor "Red Heron" across 7 countries. Register account, craft malicious...
UNC6446 (Mirage Kitten, Imperial Kitten, Nimbus Manticore, TA455, Pioneer Kitten) refreshed its aerospace/defense phishing campaign Sep 15 - fake resume lures on GitHub distributing ScreenConnect installers via miranarts-top[.]cc. Legitimate RMM tools give full remote desktop access through software many organizations whitelist.
Active C2 confirmed across four distinct Iranian ISPs - a deliberate resilience strategy. Most significant: a new IP on TIC Iran (state telecom) first seen Sep 8, using non-standard port 7443 with unidentified malware - provisioning on government-controlled telecom suggests state sanction. Also active: Cactus (ASN 213790...
The most important signal this cycle. MuddyWater has been silent 39 days. Simultaneously, every pro-Iran hacktivist persona has gone dark: Handala, Cyber Toufan, DieNet, 313 Team, Banished Kitten. Zero claims, zero defacements, zero DDoS, zero Telegram activity.
Three explanations: centralized stand-down pending a kinetic...
| Scenario | Probability | Basis |
|---|---|---|
| MuddyWater breaks silence with new campaign — likely... | 60–70% | 39-day retooling gap + C2 infrastructure refresh on ASN 213790 and... |
| Iranian actors adopt Gitea CVE-2026-60004... | 40–50% | Red Heron demonstrated the exploit works at scale; UNC6446 already... |
| FortiOS CVE-2025-25249 exploitation confirmed against allied... | 70–80% | KEV-listed Sep 9 with RAT association; Iranian actors (APT33, Pioneer... |
| Pro-Iran hacktivist personas re-emerge with coordinated IO... | 25–40% | 39-day synchronized silence suggests centralized direction; next... |
| Destructive wiper or ransomware operation against critical... | 30–45% | Flagged in prior cycle as expected within 7–14 days; MuddyWater... |
| Cisco Secure Email Gateway CVE-2026-76461 weaponized by... | 35–50% | Pre-auth RCE via email transit is a perfect fit for Iranian... |
Hunt hypothesis: Adversary sends crafted email...
Hunt hypothesis: Adversary queries GitLab commits...
Hunt hypothesis: Adversary registers account on...
Hunt hypothesis: Compromised internal hosts beacon...
Hunt hypothesis: Employees in aerospace/defense...
Hunt hypothesis: APT34 (OilRig/Hexane/Chrysene)...
| Threat | ATT&CK |
|---|---|
| 1. Cisco Secure Email Gateway Exploitation (CVE-2026-76461) | T1190 T1059.004 T1068 |
| 2. GitLab Unauthenticated File Read (CVE-2026-85706) | T1190 T1005 T1552.001 |
| 3. Gitea RCE and Rootkit Deployment (CVE-2026-60004 / JITTERLY /... | T1190 T1014 T1046 |
| 4. Iranian C2 Communication | T1071.001 T1571 T1573 |
| 5. UNC6446 Aerospace Phishing / ScreenConnect Abuse | T1566.002 T1204.002 T1219 |
| 6. APT34 Malware Artifact | T1105 |
Block above at perimeter/DNS, plus the ScreenConnect installer URL...
- Audit Cisco SEG deployments; review CI/CD pipeline security for self-hosted GitLab/Gitea
- Apply AVEVA CSAF mitigations (ICSA-26-253-01); segment OT from IT networks running Cisco SEG/GitLab/Gitea
- Patch Orthanc DICOM and Mirth Connect; hunt Cactus C2 traffic (185.93.89[.]43, 77.90.185[.]118)
- Audit self-hosted GitLab/Gitea; brief aerospace/defense staff on UNC6446 fake resume phishing
- Block ScreenConnect installs from non-IT sources; review ST Engineering iDirect satellite firmware
miranarts-top[.]cc and the ScreenConnect...2b533757086499e224d5717f94a0f...On Day 199, the threat environment is defined by a single dangerous asymmetry: the attack surface is expanding at an unprecedented rate while the adversary's most capable operators have gone dark. Three CVSS 9.8-10.0 vulnerabilities in 48 hours. Active state-level exploitation of code repositories with rootkit deployment. Iranian C2 infrastructure refreshing on state telecom. And 39 days of silence from MuddyWater and every tracked pro-Iran hacktivist group - the longest quiet period since this...