惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
美团技术团队
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
月光博客
月光博客
J
Java Code Geeks
Jina AI
Jina AI
罗磊的独立博客
宝玉的分享
宝玉的分享
S
SegmentFault 最新的问题
D
DataBreaches.Net
博客园 - 叶小钗
腾讯CDC
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
Last Week in AI
Last Week in AI
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
Google DeepMind News
Google DeepMind News
阮一峰的网络日志
阮一峰的网络日志
B
Blog
V
Visual Studio Blog
雷峰网
雷峰网
博客园 - 【当耐特】
Apple Machine Learning Research
Apple Machine Learning Research
Engineering at Meta
Engineering at Meta
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报

Security

Report: Business email compromise attacks surged dangerously in April Scope Systems confirms cyber incident, says no data loss occurred Instructure breach: ShinyHunters says ‘matter has been resolved’ Rapid7 launches Cyber GRC program to connect compliance with live risk data Australian federal budget 2026: The industry perspective Op-Ed: Microsoft May Patch Tuesday reveals 137 vulnerabilities Federal Budget 2026: The state of cyber security spending for the coming year OpenAI offers EU early access to its cyber security model Exclusive: Aussie firm Earth Systems listed by INC Ransom hacking group Op-Ed: Why Middle East tensions demand immediate action on OT security Aussie schools breach: Instructure boss “reaches agreement” with ShinyHunters to not release data Institute of Public Accountants members hit by data breach Union demands answers on Qantas AI plans 1 in 3 small businesses don't think they're a cyber target, new research finds Exclusive: Aussie toy distributor listed by M3rx ransomware Exclusive: Australian Computer Society investigating possible breach after ShinyHunters hack claims The industry speaks – part 2: World Password Day 2026 Aussie schools breach: The Instructure hack “transcends an isolated IT incident” Exclusive: Aussie car part importer Strategic Imports allegedly breached by threat actors New South Wales, other states, investigating Instructure/Canvas data breach Australian Cyber Security Centre warns of ClickFix campaign leveraging Australian infrastructure Queensland Department of Education confirms students & staff impacted by ShinyHunters data breach ACMA takes action against SpinTel & Yomojo over mobile number fraud violations The Industry Speaks, Part 1: World Password Day 2026 Qualys and Converge tie cyber insurance pricing to real-time security posture Fakeout: Iranian APT caught hiding behind Chaos ransomware activity Exclusive: Australian energy management firm allegedly breached by SafePay Real estate giant Cushman & Wakefield confirms cyber incident, Qilin and ShinyHunters claim attack CrowdStrike expands Project QuiltWorks as more partners join AI security coalition Hacked: ALS discloses cyber incident, unauthorised access to IT systems
Cyber war: Pro-Iranian hackers vow to fight on despite a ...
david.hollingworth@momentummedia.com.au (David Hollingworth) · 2026-04-10 · via Security

The missiles and drones may have stopped for now, but hackers in support of Iran are far from laying down arms – and critical infrastructure is in their crosshairs.

A civilisational apocalypse in Iran may have been averted for now, but despite the ceasefire now in place, hacktivists and state-linked hackers are expected to continue targeting the country’s perceived enemies.

“The current environment reflects a fragmented ceasefire. Hostilities are continuing across key theatres, particularly in Lebanon and across Gulf energy infrastructure,” Kathryn Raines, cyber threat intelligence team lead for the national security solutions team at Flashpoint, said in an overnight threat summary.

You’re out of free articles for this month

To continue reading the rest of this article, please log in.

“That fragmentation introduces additional uncertainty. When activity continues despite formal agreements, it becomes more difficult to anticipate escalation pathways, which increases operational risk for organisations with regional exposure.”

And cyber attacks, by their non-kinetic nature, are a particularly open pathway to continue hostilities, according to Raines.

“A military ceasefire does not translate to a cyber pause. What we’re seeing is continuity in activity, with threat actors maintaining tempo while adjusting targeting and messaging,” Raines said.

“For organisations, that means risk remains elevated. Critical infrastructure, particularly in energy and water systems, continues to be actively targeted, and the use of the ceasefire as cover creates additional uncertainty around what comes next.”

War by any other means

Ceasefires are, in effect, agreements between more or less sovereign powers. Hacktivist groups, such as Handala, do not feel bound by any such concessions. Despite one of its websites being taken down recently by the US authorities, the group has said it is prepared to fight on.

“The cyber war did not begin with the military conflict, and it will not end with any military ceasefire,” Handala said in an 8 April blog post.

“Our cyber jihad is the extension of our martyrs’ blood, and it will go on until full vengeance is achieved.”

That said, the group has agreed to postpone “overt confrontation with the United States”, but has also promised more activity is to come.

“The hack of the FBI director was just a glimpse of our power; For us, no land is too distant and no network is truly secure,” Handala added.

“Rest assured: when the time comes, the darkest of nights will have only just begun for America and all its supporters.”

As of 8 April, here’s just a sample of cyber incidents linked to the fighting in Iran:

A group calling itself the Cyber Islamic Resistance said it was expressing solidarity with Russian hacking group Team Killnet, a sign of a possible alliance between groups with extreme anti-Western beliefs.

Pro-Islam group Conquerors Electronic Army said it had launched a distributed denial-of-service attack on several Israeli entities, including a pair of volunteer associations, Beit Cham and All-Volunteer Force.

Australia, though far from the conflict, is not immune either. A group calling itself the 313 Team claimed to have launched a large-scale attack on an Australian government portal.

Meanwhile, US authorities distributed an advisory warning of Iran-linked threat actors targeting critical infrastructure entities via internet-facing hardware in the water and energy sectors.

Critical threat

In that latter case, the hackers are targeting hardware that was traditionally not internet-connected – programmable logic controllers – which presents a unique problem for defenders.

“The threat actors here are assessed to be affiliated with Iran’s Islamic Revolutionary Guard Corps (IRGC). They accessed CompactLogix and Micro850 devices using Rockwell Automation’s Studio 5000 Logix Designer,” Nozomi Networks CISO Markus Mueller said.

“The traffic looks like a regular remote engineering session because that’s exactly what it was. The difference is who was sitting at the keyboard.”

According to Mueller, such malicious activity is an unavoidable byproduct of geopolitical tension.

“That correlation isn’t new – Iranian-affiliated OT activity has tracked with periods of kinetic escalation consistently over the past several years,” Mueller said.

“That doesn’t mean your threat level should spike with every news cycle, but when the regional picture gets more volatile, it’s a reasonable prompt to re-verify your exposure, refresh your indicators of compromise (IOC) hunts, and confirm your monitoring coverage is actually running the way you think it is.

“In critical infrastructure, geopolitical context is a legitimate input to threat posture.”

Addressing the scale of any future cyber threat Iran may pose, Andrew Chipman, GRC manager at cyber security and compliance firm ProCircular, was particularly blunt in his assessments.

“The threat of cyber attack from Iran is real. At this time, we expect to see that threat realised through proxies, hacktivists, and other allies to the Iranian regime,” Chipman told Cyber Daily.

“If Iran is able to build back its regime, we may see direct retaliation from Iran in the form of cyber attacks against highly visible targets. History teaches us that hospitals and medical service providers are prime targets for the regime and its supporters.”

Iran, Chipman contends, may not be in a position to wage large-scale cyber warfare against the US and its allies at this point, but the country has other options.

“Hacktivists and proxy attackers are plentiful – expect attacks to come and prepare appropriately,” he said.

Cyber DailyWant to see more stories from trusted news sources?
Make Cyber Daily a preferred news source on Google.

David Hollingworth

David Hollingworth has been writing about technology for over 20 years, and has worked for a range of print and online titles in his career. He is enjoying getting to grips with cyber security, especially when it lets him talk about Lego.

Tags: