# Iran

Published articles for Iran.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Iranian spies hit Windows machines with Chosen Brick data-stealing malware

DevFeed: [Iranian spies hit Windows machines with Chosen Brick data-stealing malware](<https://devfeed.tech/articles/iranian-spies-hit-windows-machines-with-chosen-brick-data-stealing-malware-26961.md>)

Original publisher: [Read original article](<https://www.theregister.com/security/2026/09/15/iranian-spies-hit-windows-machines-with-chosen-brick-data-stealing-malware/5296646>)

Author: Jessica Lyons

Published: 2026-09-15T18:01:57Z

Content type: news

Language: en

Sources: [www.theregister.com - Articles](<https://devfeed.tech/sources/www-theregister-com-articles.md>)

Topics: [Malware](<https://devfeed.tech/topics/malware.md>), [Windows](<https://devfeed.tech/topics/windows.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>)

Tags: [cyber-crime](<https://devfeed.tech/tags/cyber-crime.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [iran](<https://devfeed.tech/tags/iran.md>), [malware](<https://devfeed.tech/tags/malware.md>), [microsoft](<https://devfeed.tech/tags/microsoft.md>), [security](<https://devfeed.tech/tags/security.md>), [windows](<https://devfeed.tech/tags/windows.md>)

### AI overview

The article reports that Iranian spies targeted Windows machines with Chosen Brick, a data-stealing malware.

### Source excerpt

'Enemies of the regime' on notice

## Edge infrastructure under siege: what two independent datasets reveal about who's exploiting your perimeter

DevFeed: [Edge infrastructure under siege: what two independent datasets reveal about who's exploiting your perimeter](<https://devfeed.tech/articles/edge-infrastructure-under-siege-what-two-independent-datasets-reveal-about-who-s-exploiting-your-perimeter-8262.md>)

Original publisher: [Read original article](<https://www.tenable.com/blog/edge-infrastructure-under-siege>)

Author: Research Special Operations

Published: 2026-08-26T13:00:00Z

Content type: article

Language: en

Sources: [Tenable Blog](<https://devfeed.tech/sources/tenable-blog.md>)

Topics: [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [telemetry](<https://devfeed.tech/topics/telemetry.md>)

Tags: [analysis](<https://devfeed.tech/tags/analysis.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [china](<https://devfeed.tech/tags/china.md>), [complexity](<https://devfeed.tech/tags/complexity.md>), [containers](<https://devfeed.tech/tags/containers.md>), [datasets](<https://devfeed.tech/tags/datasets.md>), [edge](<https://devfeed.tech/tags/edge.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [iran](<https://devfeed.tech/tags/iran.md>), [ransomware](<https://devfeed.tech/tags/ransomware.md>), [telemetry](<https://devfeed.tech/tags/telemetry.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

A joint Tenable-SentinelOne analysis finds state-sponsored and criminal actors converging on the same edge vulnerabilities. It compares exposure and remediation patterns across vendors and recommends faster patching, attack-surface reduction, and endpoint protection.

### Source excerpt

A joint Tenable-SentinelOne analysis of 93 CVE-actor attribution pairs reveals that both state-sponsored actors and cybercriminals independently converge on the same edge infrastructure. Special thanks to SentinelOne® Incident Readiness & Response for their contributions to this publication. It is the shared attack surface where state-sponsored threat actors and financially motivated criminal groups independently converge -- not the province of a single adversary category, and not exclusively a nation-state problem, despite two years of headlines about China-nexus actors targeting Ivanti, Fortinet, and Palo Alto Networks. The data here tells a different and much broader story. One focused on vendors vs CVEs. Key Takeaways Two independent observation systems, Tenable exposure telemetry across thousands of customer containers and SentinelOne DFIR casework across 66 CVEs, converge 79% on the same vendor attack surfaces despite minimal CVE-level overlap. Twelve CVEs in the combined dataset have confirmed multi-nexus attribution: state-sponsored and criminal actors independently exploiting the same vulnerability, across five nexus categories (China, Russia, DPRK, Iran, ransomware). The exposure picture is flatter than the headlines suggest: Fortinet, the vendor most associated with edge-device attacks in the press, sits mid-pack on container-grain exposure (25%) -- well behind F5 (54%) and in a tight 10-point band with Check Point, Ivanti, and Citrix. 54% of customer environments running F5 products have at least one exposed, actively-exploited CVE; Citrix customers show the slowest remediation patterns at 461 days median time to patch. Remediation complexity, particularly of high priority CVEs, leads to a statistically significant 24-day remediation gap, leaving large windows of opportunity for attackers. The same product lines get hit again and again: Ivanti EPMM and Ivanti Connect Secure each show a newly exploited CVE roughly every 8.5 to 13 months. Leverage multiple d

## Cloudflare DDoS Threat Report H1 2026: 1 Tbps attacks soar as DNS floods and geopolitical tensions drive a new wave

DevFeed: [Cloudflare DDoS Threat Report H1 2026: 1 Tbps attacks soar as DNS floods and geopolitical tensions drive a new wave](<https://devfeed.tech/articles/cloudflare-ddos-threat-report-h1-2026-1-tbps-attacks-soar-as-dns-floods-and-geopolitical-tensions-drive-a-new-wave-113.md>)

Original publisher: [Read original article](<https://blog.cloudflare.com/ddos-threat-report-2026-h1/>)

Author: Cloudforce One

Published: 2026-08-11T13:00:00Z

Content type: article

Language: en

Sources: [Cloudflare Blog](<https://devfeed.tech/sources/cloudflare-blog.md>)

Topics: [DDoS](<https://devfeed.tech/topics/ddos.md>), [Cloudflare](<https://devfeed.tech/topics/cloudflare.md>), [Threat Research](<https://devfeed.tech/topics/threat-research.md>), [Cloudforce One](<https://devfeed.tech/topics/cloudforce-one.md>), [Network](<https://devfeed.tech/topics/network.md>), [data](<https://devfeed.tech/topics/data.md>), [Cybercrime](<https://devfeed.tech/topics/cybercrime.md>), [High Profile Threats](<https://devfeed.tech/topics/high-profile-threats.md>)

Tags: [analysis](<https://devfeed.tech/tags/analysis.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [cloudflare](<https://devfeed.tech/tags/cloudflare.md>), [cloudforce-one](<https://devfeed.tech/tags/cloudforce-one.md>), [data](<https://devfeed.tech/tags/data.md>), [ddos](<https://devfeed.tech/tags/ddos.md>), [dns](<https://devfeed.tech/tags/dns.md>), [drive](<https://devfeed.tech/tags/drive.md>), [global](<https://devfeed.tech/tags/global.md>), [government](<https://devfeed.tech/tags/government.md>), [industry](<https://devfeed.tech/tags/industry.md>), [iran](<https://devfeed.tech/tags/iran.md>), [media](<https://devfeed.tech/tags/media.md>), [network](<https://devfeed.tech/tags/network.md>), [radar](<https://devfeed.tech/tags/radar.md>), [streaming](<https://devfeed.tech/tags/streaming.md>), [threat-report](<https://devfeed.tech/tags/threat-report.md>)

### AI overview

Cloudflare's H1 2026 DDoS Threat Report analyzes attacks from January through June 2026. It highlights a 519% quarter-over-quarter increase in attacks exceeding 1 Tbps, a shift toward DNS and CLDAP reflection and amplification vectors, and the influence of geopolitical events on attack patterns. The report also covers attack volumes, an April peak, and the possible impact of Operation PowerOFF.

### Source excerpt

In the first half of 2026, Cloudflare detected a 519% surge in hyper-volumetric DDos attacks across its network. These attacks were driven heavily by DNS and CLDAP reflection vectors. This report breaks down how major geopolitical conflicts reshaped the global cyber threat landscape.

## Iran War Cyber Threat Landscape | A Midyear Assessment on What Matters

DevFeed: [Iran War Cyber Threat Landscape | A Midyear Assessment on What Matters](<https://devfeed.tech/articles/iran-war-cyber-threat-landscape-a-midyear-assessment-on-what-matters-8314.md>)

Original publisher: [Read original article](<https://www.sentinelone.com/labs/iran-war-cyber-threat-landscape-a-midyear-assessment-on-what-matters/>)

Author: Tom Hegel

Published: 2026-07-21T13:00:21Z

Content type: article

Language: en

Sources: [SentinelLabs - We are hunters, reversers, exploit developers, and tinkerers shedding light on the world of malware, exploits, APTs, and cybercrime across all platforms.](<https://devfeed.tech/sources/sentinellabs-we-are-hunters-reversers-exploit-developers-and-tinkerers-shedding-light-on-the-world-of-malware-exploits-apts-and-cybercrime-across-all-platforms.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [incident](<https://devfeed.tech/topics/incident.md>)

Tags: [iran](<https://devfeed.tech/tags/iran.md>), [us](<https://devfeed.tech/tags/us.md>), [what-matters](<https://devfeed.tech/tags/what-matters.md>)

### AI overview

A midyear assessment of Iran-linked cyber activity finds that the strategic risk centers on persistent access, trusted administration, service-provider pathways, selective disruption, and changing operational tasking. It distinguishes among Iran-linked actors and cautions that impact claims often exceed independently verified evidence.

### Source excerpt

In April, SentinelLABS' Tom Hegel published an initial assessment of the first five weeks of the conflict. Three months later, the evidence supports refinement.

## ESET APT Activity Report Q4 2025-Q1 2026

DevFeed: [ESET APT Activity Report Q4 2025-Q1 2026](<https://devfeed.tech/articles/eset-apt-activity-report-q4-2025-q1-2026-8362.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/eset-research/eset-apt-activity-report-q4-2025-q1-2026/>)

Author: Jean-Ian Boutin

Published: 2026-05-28T08:45:00Z

Content type: article

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [High Profile Threats](<https://devfeed.tech/topics/high-profile-threats.md>)

Tags: [apt](<https://devfeed.tech/tags/apt.md>), [china](<https://devfeed.tech/tags/china.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [eset-research](<https://devfeed.tech/tags/eset-research.md>), [iran](<https://devfeed.tech/tags/iran.md>), [virustotal](<https://devfeed.tech/tags/virustotal.md>)

### AI overview

ESET's report summarizes selected APT activity from October 2025 through March 2026, including China-aligned espionage, activity targeting government and strategic-technology entities, and changes in Iran-aligned activity during the war in Iran.

### Source excerpt

An overview of the activities of selected APT groups investigated and analyzed by ESET Research in Q4 2025 and Q1 2026

## This month in security with Tony Anscombe - April 2026 edition

DevFeed: [This month in security with Tony Anscombe - April 2026 edition](<https://devfeed.tech/articles/this-month-in-security-with-tony-anscombe-april-2026-edition-8416.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/videos/month-security-tony-anscombe-april-2026/>)

Author: Editor

Published: 2026-04-30T09:00:00Z

Content type: news

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [spoofing](<https://devfeed.tech/topics/spoofing.md>)

Tags: [attacks](<https://devfeed.tech/tags/attacks.md>), [critical-infrastructure](<https://devfeed.tech/tags/critical-infrastructure.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [helpdesk](<https://devfeed.tech/tags/helpdesk.md>), [iran](<https://devfeed.tech/tags/iran.md>), [microsoft](<https://devfeed.tech/tags/microsoft.md>), [microsoft-teams](<https://devfeed.tech/tags/microsoft-teams.md>), [scams](<https://devfeed.tech/tags/scams.md>), [security](<https://devfeed.tech/tags/security.md>), [us](<https://devfeed.tech/tags/us.md>), [video](<https://devfeed.tech/tags/video.md>)

### AI overview

A monthly video security roundup covers Microsoft Teams helpdesk impersonation scams, Iran-linked targeting of Rockwell PLCs at U.S. critical-infrastructure organizations, and FBI figures on cyber-enabled crime.

### Source excerpt

Warnings about helpdesk impersonation scams and Iran-linked hackers targeting critical sectors in the US, plus the most damaging scams of 2025 - here's some of what made the headlines this month

## Cyber fallout from the Iran war: What to have on your radar

DevFeed: [Cyber fallout from the Iran war: What to have on your radar](<https://devfeed.tech/articles/cyber-fallout-from-the-iran-war-what-to-have-on-your-radar-8329.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/business-security/cyber-fallout-iran-war-what-have-radar/>)

Author: Tomáš Foltýn

Published: 2026-03-12T14:17:33Z

Content type: article

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [Security & Privacy](<https://devfeed.tech/topics/security-privacy.md>), [Threat Research](<https://devfeed.tech/topics/threat-research.md>), [cloud-infrastructure](<https://devfeed.tech/topics/cloud-infrastructure.md>), [Amazon Web Services (AWS)](<https://devfeed.tech/topics/amazon-web-services-aws.md>), [DDoS](<https://devfeed.tech/topics/ddos.md>), [Reconnaissance](<https://devfeed.tech/topics/recon.md>)

Tags: [amazon-web-services-aws](<https://devfeed.tech/tags/amazon-web-services-aws.md>), [business-security](<https://devfeed.tech/tags/business-security.md>), [canada](<https://devfeed.tech/tags/canada.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [ddos](<https://devfeed.tech/tags/ddos.md>), [iran](<https://devfeed.tech/tags/iran.md>), [united-kingdom](<https://devfeed.tech/tags/united-kingdom.md>), [us](<https://devfeed.tech/tags/us.md>)

### AI overview

The article examines the cybersecurity fallout from the Iran war, including attacks on AWS data centers and the rapid mobilization of pro-Iranian cyber groups. It describes hacktivism, APT reconnaissance and initial access, espionage, disruption, sabotage, and the heightened risks to organizations with Middle East supply-chain or cloud dependencies.

### Source excerpt

The cybersecurity implications of the war in the Middle East extend far beyond the region. Here's where to focus your defenses.

## MuddyWater: Snakes by the riverbank

DevFeed: [MuddyWater: Snakes by the riverbank](<https://devfeed.tech/articles/muddywater-snakes-by-the-riverbank-8376.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/eset-research/muddywater-snakes-riverbank/>)

Author: ESET Research

Published: 2025-12-02T10:00:15Z

Content type: article

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [backdoor](<https://devfeed.tech/topics/backdoor.md>), [C++](<https://devfeed.tech/topics/c-plus-plus.md>)

Tags: [analysis](<https://devfeed.tech/tags/analysis.md>), [api](<https://devfeed.tech/tags/api.md>), [apt](<https://devfeed.tech/tags/apt.md>), [backdoor](<https://devfeed.tech/tags/backdoor.md>), [c](<https://devfeed.tech/tags/c.md>), [c-c-plus-plus](<https://devfeed.tech/tags/c-c-plus-plus.md>), [c-plus-plus](<https://devfeed.tech/tags/c-plus-plus.md>), [critical-infrastructure](<https://devfeed.tech/tags/critical-infrastructure.md>), [cryptographic](<https://devfeed.tech/tags/cryptographic.md>), [eset-research](<https://devfeed.tech/tags/eset-research.md>), [iran](<https://devfeed.tech/tags/iran.md>), [malware](<https://devfeed.tech/tags/malware.md>), [memory](<https://devfeed.tech/tags/memory.md>), [persistence](<https://devfeed.tech/tags/persistence.md>), [socks5](<https://devfeed.tech/tags/socks5.md>), [techniques](<https://devfeed.tech/tags/techniques.md>), [tools](<https://devfeed.tech/tags/tools.md>), [windows](<https://devfeed.tech/tags/windows.md>)

### AI overview

ESET analyzes a MuddyWater campaign targeting organizations in Israel and Egypt that uses custom loaders, credential stealers, reverse tunnels, and the MuddyViper backdoor to evade defenses and maintain access.

### Source excerpt

MuddyWater targets critical infrastructure in Israel and Egypt, relying on custom malware, improved tactics, and a predictable playbook

## Devconnect Scholars Program - Ethereum Stories from Istanbul and Beyond

DevFeed: [Devconnect Scholars Program - Ethereum Stories from Istanbul and Beyond](<https://devfeed.tech/articles/devconnect-scholars-program-ethereum-stories-from-istanbul-and-beyond-17095.md>)

Original publisher: [Read original article](<https://blog.ethereum.org/en/2024/02/29/scholars-stories>)

Author: Next Billion

Published: 2024-02-29T00:00:00Z

Content type: opinion

Language: en

Sources: [Ethereum Foundation Blog](<https://devfeed.tech/sources/ethereum-foundation-blog.md>)

Topics: [Ethereum](<https://devfeed.tech/topics/ethereum.md>), [Resilience](<https://devfeed.tech/topics/resilience.md>), [Protocol (disambiguation)](<https://devfeed.tech/topics/protocol.md>), [Blockchain](<https://devfeed.tech/topics/blockchain.md>)

Tags: [africa](<https://devfeed.tech/tags/africa.md>), [backend](<https://devfeed.tech/tags/backend.md>), [banking](<https://devfeed.tech/tags/banking.md>), [bitcoin](<https://devfeed.tech/tags/bitcoin.md>), [blockchain](<https://devfeed.tech/tags/blockchain.md>), [community](<https://devfeed.tech/tags/community.md>), [devconnect](<https://devfeed.tech/tags/devconnect.md>), [diversity](<https://devfeed.tech/tags/diversity.md>), [ecosystem](<https://devfeed.tech/tags/ecosystem.md>), [ethereum](<https://devfeed.tech/tags/ethereum.md>), [geography](<https://devfeed.tech/tags/geography.md>), [india](<https://devfeed.tech/tags/india.md>), [innovation](<https://devfeed.tech/tags/innovation.md>), [iran](<https://devfeed.tech/tags/iran.md>), [java](<https://devfeed.tech/tags/java.md>), [network](<https://devfeed.tech/tags/network.md>), [networks](<https://devfeed.tech/tags/networks.md>), [next-billion](<https://devfeed.tech/tags/next-billion.md>), [perspectives](<https://devfeed.tech/tags/perspectives.md>), [program](<https://devfeed.tech/tags/program.md>), [resilience](<https://devfeed.tech/tags/resilience.md>)

### AI overview

The article presents stories from participants in the Devconnect Scholars Program, describing how broader geographic and demographic representation can strengthen Ethereum's resilience, security, and community. It profiles scholars from India, Iran, and Kenya and their work in research, education, smart contracts, and open-source projects.

### Source excerpt

Ethereum is growing, and diversity of human participation creates resilience throughout the ecosystem. The Devconnect Scholars Program is one small effort that aims to create resilience through community diversity. Better representation across human geography and demographics leads to diverse experiences and new perspectives that help the Ethereum protocol serve the...

## Help people in Iran reconnect to Signal - a request to our community

DevFeed: [Help people in Iran reconnect to Signal - a request to our community](<https://devfeed.tech/articles/help-people-in-iran-reconnect-to-signal-a-request-to-our-community-1817.md>)

Original publisher: [Read original article](<https://signal.org/blog/run-a-proxy/>)

Published: 2022-09-22T00:00:00Z

Content type: article

Language: en

Sources: [Signal Blog](<https://devfeed.tech/sources/signal-blog.md>)

Topics: [servers](<https://devfeed.tech/topics/servers.md>), [Network](<https://devfeed.tech/topics/network.md>), [TLS (Transport Layer Security)](<https://devfeed.tech/topics/tls.md>), [Android](<https://devfeed.tech/topics/android.md>), [App](<https://devfeed.tech/topics/app.md>)

Tags: [android](<https://devfeed.tech/tags/android.md>), [http](<https://devfeed.tech/tags/http.md>), [iran](<https://devfeed.tech/tags/iran.md>), [network](<https://devfeed.tech/tags/network.md>), [server](<https://devfeed.tech/tags/server.md>), [tls](<https://devfeed.tech/tags/tls.md>)

### AI overview

Signal asks its community to run lightweight proxy servers to help people in Iran reconnect to Signal during network blocking. The article explains the server and domain requirements, Android link-based configuration, and how the TLS proxy is designed to resemble ordinary encrypted web traffic.

### Source excerpt

Signal is currently blocked in Iran. To help people in the country access Signal, we are republishing and revising a post that we originally posted in February, 2021 during a very similar situation in Iran. If you are willing and able, please follow the instructions below to set up a proxy server that will enable people in Iran to connect to Signal. We are grateful to the community who pitches in to help each other during these moments. If you are currently running a proxy, you will need to make some updates to ensure it continues to function. Update instructions are here. Read more...

## Help users in Iran reconnect to Signal

DevFeed: [Help users in Iran reconnect to Signal](<https://devfeed.tech/articles/help-users-in-iran-reconnect-to-signal-1771.md>)

Original publisher: [Read original article](<https://signal.org/blog/help-iran-reconnect/>)

Published: 2021-02-04T00:00:00Z

Content type: article

Language: en

Sources: [Signal Blog](<https://devfeed.tech/sources/signal-blog.md>)

Topics: [Cryptography](<https://devfeed.tech/topics/cryptography.md>)

Tags: [android](<https://devfeed.tech/tags/android.md>), [encryption](<https://devfeed.tech/tags/encryption.md>), [iran](<https://devfeed.tech/tags/iran.md>), [server](<https://devfeed.tech/tags/server.md>), [tls](<https://devfeed.tech/tags/tls.md>)

### AI overview

Signal introduces a lightweight TLS proxy to help users in Iran bypass network blocking and reconnect securely. The article explains proxy setup requirements, traffic forwarding, and how TLS and end-to-end encryption protect communications.

### Source excerpt

Just over a week ago, we announced that Iranian censors had started blocking all Signal traffic in the country. As an interim solution to help people in Iran get connected again, we've added support in Signal for a simple TLS proxy that is easy to set up, can be used to bypass the network block, and will securely route traffic to the Signal service. This new connection method is supported in the latest Signal Android beta release, and will be rolling out to production users in a few days. Our hope is that this will help many people in Iran start sending and receiving messages again while we continue to explore additional censorship circumvention techniques that will work there. Read more...