sana.sy Joint Warning on Iranian Cyber Espionage Targeting Activists
Article Content
- •Iranian state-linked actors are using malware 'Chosen Break' for cyber espionage.
- •Targets include activists, journalists, and dissidents on platforms like WhatsApp and Telegram.
- •The FBI and UK authorities confirm ongoing surveillance and data theft operations.
On September 15, 2026, the UK, US, and Netherlands issued a joint warning about Iranian cyber espionage programs targeting activists, journalists, and dissidents. The UK's National Cyber Security Centre reported that Iranian state-linked actors employed malware known as 'Chosen Break' to steal sensitive information through targeted phishing campaigns on messaging platforms like WhatsApp and Telegram. The malware can access email, contacts, and even capture screen content and microphone audio. The FBI confirmed that Iran's Ministry of Intelligence and Security is using this malware for intelligence gathering and discrediting targets. This warning updates a previous advisory from March 2026, highlighting ongoing threats from a hacker known as 'Handala Hack.' The campaign has reportedly led to the exposure of personal data on pro-Iran leak sites. Authorities are urging vigilance against these targeted attacks.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…