惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

The Cloudflare Blog
小众软件
小众软件
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
T
Tailwind CSS Blog
WordPress大学
WordPress大学
有赞技术团队
有赞技术团队
博客园 - 司徒正美
V
Visual Studio Blog
G
Google Developers Blog
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
月光博客
月光博客
aimingoo的专栏
aimingoo的专栏
博客园_首页
Blog — PlanetScale
Blog — PlanetScale
博客园 - 聂微东
S
SegmentFault 最新的问题
T
The Blog of Author Tim Ferriss
D
Docker
Vercel News
Vercel News
Recent Announcements
Recent Announcements
Last Week in AI
Last Week in AI
爱范儿
爱范儿
J
Java Code Geeks
大猫的无限游戏
大猫的无限游戏

Security

Report: Business email compromise attacks surged dangerously in April Scope Systems confirms cyber incident, says no data loss occurred Instructure breach: ShinyHunters says ‘matter has been resolved’ Rapid7 launches Cyber GRC program to connect compliance with live risk data Australian federal budget 2026: The industry perspective Op-Ed: Microsoft May Patch Tuesday reveals 137 vulnerabilities Federal Budget 2026: The state of cyber security spending for the coming year OpenAI offers EU early access to its cyber security model Exclusive: Aussie firm Earth Systems listed by INC Ransom hacking group Op-Ed: Why Middle East tensions demand immediate action on OT security Aussie schools breach: Instructure boss “reaches agreement” with ShinyHunters to not release data Institute of Public Accountants members hit by data breach Union demands answers on Qantas AI plans 1 in 3 small businesses don't think they're a cyber target, new research finds Exclusive: Aussie toy distributor listed by M3rx ransomware Exclusive: Australian Computer Society investigating possible breach after ShinyHunters hack claims The industry speaks – part 2: World Password Day 2026 Aussie schools breach: The Instructure hack “transcends an isolated IT incident” Exclusive: Aussie car part importer Strategic Imports allegedly breached by threat actors New South Wales, other states, investigating Instructure/Canvas data breach Australian Cyber Security Centre warns of ClickFix campaign leveraging Australian infrastructure Queensland Department of Education confirms students & staff impacted by ShinyHunters data breach ACMA takes action against SpinTel & Yomojo over mobile number fraud violations The Industry Speaks, Part 1: World Password Day 2026 Qualys and Converge tie cyber insurance pricing to real-time security posture Fakeout: Iranian APT caught hiding behind Chaos ransomware activity Exclusive: Australian energy management firm allegedly breached by SafePay Real estate giant Cushman & Wakefield confirms cyber incident, Qilin and ShinyHunters claim attack CrowdStrike expands Project QuiltWorks as more partners join AI security coalition Hacked: ALS discloses cyber incident, unauthorised access to IT systems
Cyber war: Pro-Iranian hackers vow to fight on despite a ...
david.hollingworth@momentummedia.com.au (David Hollingworth) · 2026-04-10 · via Security

The missiles and drones may have stopped for now, but hackers in support of Iran are far from laying down arms – and critical infrastructure is in their crosshairs.

A civilisational apocalypse in Iran may have been averted for now, but despite the ceasefire now in place, hacktivists and state-linked hackers are expected to continue targeting the country’s perceived enemies.

“The current environment reflects a fragmented ceasefire. Hostilities are continuing across key theatres, particularly in Lebanon and across Gulf energy infrastructure,” Kathryn Raines, cyber threat intelligence team lead for the national security solutions team at Flashpoint, said in an overnight threat summary.

You’re out of free articles for this month

To continue reading the rest of this article, please log in.

“That fragmentation introduces additional uncertainty. When activity continues despite formal agreements, it becomes more difficult to anticipate escalation pathways, which increases operational risk for organisations with regional exposure.”

And cyber attacks, by their non-kinetic nature, are a particularly open pathway to continue hostilities, according to Raines.

“A military ceasefire does not translate to a cyber pause. What we’re seeing is continuity in activity, with threat actors maintaining tempo while adjusting targeting and messaging,” Raines said.

“For organisations, that means risk remains elevated. Critical infrastructure, particularly in energy and water systems, continues to be actively targeted, and the use of the ceasefire as cover creates additional uncertainty around what comes next.”

War by any other means

Ceasefires are, in effect, agreements between more or less sovereign powers. Hacktivist groups, such as Handala, do not feel bound by any such concessions. Despite one of its websites being taken down recently by the US authorities, the group has said it is prepared to fight on.

“The cyber war did not begin with the military conflict, and it will not end with any military ceasefire,” Handala said in an 8 April blog post.

“Our cyber jihad is the extension of our martyrs’ blood, and it will go on until full vengeance is achieved.”

That said, the group has agreed to postpone “overt confrontation with the United States”, but has also promised more activity is to come.

“The hack of the FBI director was just a glimpse of our power; For us, no land is too distant and no network is truly secure,” Handala added.

“Rest assured: when the time comes, the darkest of nights will have only just begun for America and all its supporters.”

As of 8 April, here’s just a sample of cyber incidents linked to the fighting in Iran:

A group calling itself the Cyber Islamic Resistance said it was expressing solidarity with Russian hacking group Team Killnet, a sign of a possible alliance between groups with extreme anti-Western beliefs.

Pro-Islam group Conquerors Electronic Army said it had launched a distributed denial-of-service attack on several Israeli entities, including a pair of volunteer associations, Beit Cham and All-Volunteer Force.

Australia, though far from the conflict, is not immune either. A group calling itself the 313 Team claimed to have launched a large-scale attack on an Australian government portal.

Meanwhile, US authorities distributed an advisory warning of Iran-linked threat actors targeting critical infrastructure entities via internet-facing hardware in the water and energy sectors.

Critical threat

In that latter case, the hackers are targeting hardware that was traditionally not internet-connected – programmable logic controllers – which presents a unique problem for defenders.

“The threat actors here are assessed to be affiliated with Iran’s Islamic Revolutionary Guard Corps (IRGC). They accessed CompactLogix and Micro850 devices using Rockwell Automation’s Studio 5000 Logix Designer,” Nozomi Networks CISO Markus Mueller said.

“The traffic looks like a regular remote engineering session because that’s exactly what it was. The difference is who was sitting at the keyboard.”

According to Mueller, such malicious activity is an unavoidable byproduct of geopolitical tension.

“That correlation isn’t new – Iranian-affiliated OT activity has tracked with periods of kinetic escalation consistently over the past several years,” Mueller said.

“That doesn’t mean your threat level should spike with every news cycle, but when the regional picture gets more volatile, it’s a reasonable prompt to re-verify your exposure, refresh your indicators of compromise (IOC) hunts, and confirm your monitoring coverage is actually running the way you think it is.

“In critical infrastructure, geopolitical context is a legitimate input to threat posture.”

Addressing the scale of any future cyber threat Iran may pose, Andrew Chipman, GRC manager at cyber security and compliance firm ProCircular, was particularly blunt in his assessments.

“The threat of cyber attack from Iran is real. At this time, we expect to see that threat realised through proxies, hacktivists, and other allies to the Iranian regime,” Chipman told Cyber Daily.

“If Iran is able to build back its regime, we may see direct retaliation from Iran in the form of cyber attacks against highly visible targets. History teaches us that hospitals and medical service providers are prime targets for the regime and its supporters.”

Iran, Chipman contends, may not be in a position to wage large-scale cyber warfare against the US and its allies at this point, but the country has other options.

“Hacktivists and proxy attackers are plentiful – expect attacks to come and prepare appropriately,” he said.

Cyber DailyWant to see more stories from trusted news sources?
Make Cyber Daily a preferred news source on Google.

David Hollingworth

David Hollingworth has been writing about technology for over 20 years, and has worked for a range of print and online titles in his career. He is enjoying getting to grips with cyber security, especially when it lets him talk about Lego.

Tags: