Skip to content
October 8, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • DNS Lookup
    • Encoder & Hash Generator
    • IP / Subnet Calculator
    • Whois Lookup
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
  • Home
  • News
  • After the mass demonstrations, Infy hacker group launched a cyber-attack to target protesters and their contacts abroad
  • News

After the mass demonstrations, Infy hacker group launched a cyber-attack to target protesters and their contacts abroad

Do Son January 9, 2018 2 minutes read
Add Daily CyberSecurity as a preferred source on Google

A retrospective review: Reuters reported that on 28 December, Iran suddenly broke out against government demonstrations and quickly spread to many major cities including Tehran, Mashhad, Hamadan, and Shah Rudd. The wave of government protests against the government was caused by the discontent with economic difficulties, rising prices and corruption, the largest protest in Iran since 2009.

Foreign media January 7, after cybersecurity company said mass demonstrations, Iran Infy hacker may try to attack the protesters and their network of foreign contacts. At present, Iranian authorities have a wider scope of repression against protesters and political dissidents, including anyone who contacts the target groups.

According to experts from Palo Alto Networks, Iranian Infy hackers have been active at least since 2007, with malware attacks covering Iran and abroad. It is reported that, unlike other Iran-based foreign aid to state sponsors, Infy’s organization seems to be focused on rebels and dissidents.

Infy ​​malware was first submitted to VirusTotal in August 2007, while experts found that the C & C domain names used in its oldest sample were also associated with malicious activity in December 2004. Not only that, but Colin Anderson, a researcher, confirmed that Infy attackers have conducted numerous malware assaults on Iranian civil society since the end of 2014. Over the years, its author has implemented many new features to continuously improve Infy malware.

Related media said that in response to the recent mass demonstrations, the Iranian government also tried to shield the Internet by shielding the protests, such as the blockade of messaging services such as Instagram and Telegram.

Source: SecurityAffairs

Related coverage

  • France and Germany will jointly submit Bitcoin regulatory advice to the G20
  • Passwords and SMS Are Dead: Microsoft Begins Sunsetting Text Message Verification for Consumer Accounts
  • Windows 11 Experimental Builds Face a Time Bomb on August 11
  • Mauri Ransomware Exploits Apache ActiveMQ Flaw (CVE-2023-46604)
  • Fake Free VPN & Minecraft Mod Repositories Deliver Lumma Stealer
  • OpenAI’s Next-Gen AI: O3-Pro’s Enhanced Reasoning Power
Track all actively exploited CVEs →

Support Our Threat Intelligence

Find our zero-day alerts and CVE reports helpful? Support our work today and unlock a 100% ad-free reading experience!

Buy Me a Coffee Logo Buy Me a Coffee
Select your plan
Free Pro Team

Hover over a plan to see its benefits.

Get Zero-Hour Vulnerability Alerts

Critical CVEs, CVSS scores, and PoC updates — straight to your inbox every week.

We respect your inbox. Unsubscribe anytime.

SHARE
Share on FacebookShare on XShare on LinkedInShare on TelegramShare on BlueskyShare on Mastodon
Tags: Infy hacker

Search

Translation

CVE ALERTS
📈

EPSS Spike Alerts
Catch risk spikes before they make headlines.

🎯

Custom EPSS/CVSS
Set score thresholds to effectively filter noise.

🛡️

Exploit Intel
Real-world exploit signals beyond the KEV catalog.

🐙

GitHub Issues
Auto-create alert tickets without duplication.

📬

Weekly Digest
Clean summaries, eliminating email spam.

🏷️

Watchlist Groups
Tag vulnerabilities by team (Infra/AppSec/SOC).

🔀

Smart Routing
Route chat channels based on severity levels.

🚨

RBP Tracker
Early warning detection and tracking system.

Subscribe – $7/mo or try free for 14 days →

🚨 Active Exploits in the Wild

  • CVE-2026-94504CVSS 7.2
    Ninja Forms 3.15.3 stores an anonymous non-RTE textarea value and renders it without safe HTML encoding in the...
    Admin intel📅 Updated: Oct 7, 2026
  • CVE-2026-93836CVSS 7.2
    The WPC Product Bundles for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the \'qty\'...
    Admin intel📅 Updated: Oct 7, 2026
  • CVE-2026-21589CVSS 9.3
    This is a vulnerability in Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software...
    Admin intel📅 Updated: Oct 7, 2026
  • CVE-2026-61500CVSS 9.3
    Rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the non-cryptographic Math.random() generator and discloses outputs...
    Admin intel📅 Updated: Oct 7, 2026
  • CVE-2026-88779CVSS 8.7
    Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS,...
    Admin intelCISA KEV📅 Added to KEV: Oct 4, 2026📅 Updated: Oct 4, 2026
  • CVE-2026-102490CVSS 8.5
    All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.
    Admin intelCISA KEV📅 Added to KEV: Oct 2, 2026📅 Updated: Oct 2, 2026
  • CVE-2026-102489CVSS 8.7
    Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as...
    Admin intelCISA KEV📅 Added to KEV: Oct 2, 2026📅 Updated: Oct 2, 2026
  • CVE-2026-100382CVSS 10.0
    Improper Neutralization of Special Elements used in an OS Command (\'OS Command Injection\') vulnerability in Wikimedia Foundation Mediawiki...
    Admin intel📅 Updated: Oct 1, 2026
Powered by CVE Watchtower

Critical Vulnerabilities

  • CVE-2026-9209CVSS 9.3
    mJobTime through build 15.7.3.32 contains an unauthenticated SQL execution vulnerability in the Login.aspx admin panel handlers, where the...
    📅 Updated: Oct 8, 2026
  • CVE-2026-95606CVSS 9.8
    Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP The Events Calendar allows Object Injection. This issue...
    📅 Updated: Oct 8, 2026
  • CVE-2026-95605CVSS 9.3
    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Passionate Programmer Peter WP...
    📅 Updated: Oct 8, 2026
  • CVE-2026-85097CVSS 9.8
    The Bricksforge plugin for WordPress is vulnerable to unauthenticated arbitrary file upload in versions up to, and including,...
    📅 Updated: Oct 8, 2026
  • CVE-2026-17609CVSS 9.1
    The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary Directory Deletion...
    📅 Updated: Oct 8, 2026
  • CVE-2022-37897CVSS 9.8
    There is a command injection vulnerability that could lead to unauthenticated remote code execution by sending specially crafted...
    📅 Updated: Oct 8, 2026
  • CVE-2026-105110CVSS 9.3
    OS Command Injection in the login.xgi CGI endpoint in Iskratel Innbox GPON ONT devices allows an unauthenticated remote...
    📅 Updated: Oct 8, 2026
  • CVE-2026-61447CVSS 10.0
    ### Summary `CodeAgent._execute_python()` executes LLM-generated Python code in a subprocess with the complete parent-process environment (`os.environ.copy()`), zero AST...
    📅 Updated: Oct 8, 2026
Powered by CVE Watchtower

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.