BT
Privacy ToolboxJournalProjectsResumeBookmarks
Feed
Privacy Toolbox
Journal
Projects
Resume
Bookmarks
Intel
CIPHER
The Vault
Threat Actors
Privacy Threats
Dashboard
CVEs
Tags
Intel
CIPHERThe VaultThreat ActorsPrivacy ThreatsDashboardCVEsTags

Intel

  • Feed
  • Threat Actors
  • Privacy Threats
  • Dashboard
  • Privacy Toolbox
  • CVEs

Personal

  • Journal
  • Projects

Resources

  • Subscribe
  • Bookmarks
  • Developers
  • Tags
Cybersecurity News & Analysis
github
defconxt
•
© 2026
•
blacktemple.net
  1. Feed
  2. /APT Activity Roundup: Iran-Linked Energy Targeting, Major DeFi Breach, and Critical Infrastructure Vulnerabilities

APT Activity Roundup: Iran-Linked Energy Targeting, Major DeFi Breach, and Critical Infrastructure Vulnerabilities

March 24, 2026Nation-State & APT3 min readhigh

Originally reported by Security Affairs, The Record, Palo Alto Unit 42

#iran-apt#energy-sector#defi-breach#qnap-vulnerabilities#ransomware#pwn2own#critical-infrastructure
Share

TL;DR

Iranian threat actors are actively targeting Middle East energy infrastructure while QNAP addressed critical SD-WAN vulnerabilities demonstrated at Pwn2Own Ireland 2025. A major DeFi platform breach resulted in $24.5 million stolen, and education company Kaplan disclosed a breach affecting over 230,000 individuals.

Why high?

Iran-linked APT group actively targeting critical energy infrastructure in the Gulf region, combined with critical vulnerabilities in QNAP infrastructure devices and a $24.5 million DeFi breach, represent significant threats to critical systems.

Iran-Linked APT Targets Gulf Energy Infrastructure

Resecurity has identified a new Iran-associated threat group dubbed Nasir Security actively targeting energy organizations across the Middle East. The group's focus on critical energy infrastructure aligns with broader Iranian cyber operations targeting regional adversaries amid ongoing geopolitical tensions.

The energy sector remains a primary target for nation-state actors due to its strategic importance and potential for significant economic and operational disruption. Resecurity's tracking indicates this represents an escalation in Iranian cyber activities against Gulf states.

QNAP Addresses Critical Pwn2Own Vulnerabilities

QNAP has patched four critical vulnerabilities (CVE-2025-62843 through CVE-2025-62846) in its SD-WAN router products after Team DDOS successfully demonstrated exploitation chains at Pwn2Own Ireland 2025. The researchers chained multiple bugs to achieve root access on QNAP devices.

These vulnerabilities could enable remote code execution, unauthorized data access, and system disruption on enterprise network infrastructure. Organizations using QNAP SD-WAN solutions should prioritize immediate patching to prevent potential compromise by threat actors who may weaponize these publicly demonstrated techniques.

$24.5 Million DeFi Platform Breach

An attacker successfully compromised the Resolv DeFi platform, stealing $24.5 million in Ethereum through an exploit of the platform's smart contract mechanisms. Resolv attempted to negotiate with the attacker via blockchain messaging, offering a 10% bounty for return of the remaining funds.

This breach highlights ongoing vulnerabilities in decentralized finance protocols and the substantial financial risks posed to cryptocurrency platforms. The incident demonstrates how smart contract vulnerabilities can result in immediate, irreversible financial losses.

Education Giant Kaplan Discloses Major Data Breach

Educational services company Kaplan reported a cybersecurity incident affecting over 230,000 individuals, with exposed data including Social Security numbers and driver's license information. The breach occurred in fall 2025 but was only recently disclosed to state regulators.

The incident underscores the persistent threat to educational institutions, which often maintain extensive databases of sensitive personal information spanning students, employees, and contractors. The delayed disclosure timeline raises questions about detection capabilities and incident response procedures.

Semiconductor Company Hit by Ransomware

California-based semiconductor testing company Trio Tech reported a ransomware attack against its Singapore subsidiary to the SEC. The incident affects a company operating in the critical semiconductor supply chain, highlighting ongoing threats to technology manufacturing infrastructure.

The attack demonstrates how ransomware groups continue targeting specialized industrial sectors, potentially disrupting global supply chains for critical technology components.

Nigerian National Sentenced in $6 Million BEC Scheme

James Junior Aliyu, 31, received a 90-month federal prison sentence for orchestrating a $6 million business email compromise (BEC) scheme involving wire fraud and money laundering. The case was prosecuted by U.S. Immigration and Customs Enforcement.

This sentencing reflects continued law enforcement focus on international cybercrime networks, particularly BEC operations that have cost organizations billions annually through social engineering and email account compromise techniques.

Google Authenticator Security Analysis Released

Palo Alto Networks Unit 42 published detailed research into Google Authenticator's passwordless authentication mechanisms, examining the security architecture of synced passkey systems. The analysis provides insights into key management and secure communication protocols in modern passwordless authentication systems.

The research offers valuable technical details for security professionals implementing or evaluating passwordless authentication solutions in enterprise environments.

Sources

  • https://securityaffairs.com/189871/security/qnap-fixed-four-vulnerabilities-demonstrated-at-pwn2own-ireland-2025.html
  • https://securityaffairs.com/189865/cyber-warfare-2/pro-iranian-nasir-security-is-targeting-energy-companies-in-the-gulf.html
  • https://therecord.media/hacker-breaches-resolv-defi-25-million
  • https://therecord.media/kaplan-data-breach-hack-notification
  • https://therecord.media/us-sentences-nigerian-national-to-7-years-fraud
  • https://therecord.media/ransomware-trio-tech-semiconductor-sec
  • https://unit42.paloaltonetworks.com/passwordless-authentication/

Originally reported by Security Affairs, The Record, Palo Alto Unit 42

Tags

#iran-apt#energy-sector#defi-breach#qnap-vulnerabilities#ransomware#pwn2own#critical-infrastructure

Tracked Companies

🇺🇸Google

Related Intelligence

  • Nation-State Roundup: North Korea Hits Crypto Platform, Iran War Escalates Cyber Threats, Healthcare Under Fire

    highMar 18, 2026
  • WorldLeaks Ransomware Group Strikes Los Angeles Metro System, Forces Emergency Shutdown

    highMar 22, 2026
  • Nation-State Roundup: Russian APT Exploits Zimbra Zero-Day, Iranian Group Hits Stryker via Microsoft Intune

    highMar 20, 2026

Related Knowledge

  • Threat Intelligence Deep Training

    reference
  • MITRE ATT&CK / D3FEND Deep Reference

    reference
  • CIPHER Training: Emerging Threats Deep Dive (2025-2026)

    reference

Explore

  • Dashboard
  • Privacy Threats
  • Threat Actors
← Back to the feed

Previous Article

← Critical NetScaler Flaw, Supply Chain Attacks, and North Korean VS Code Exploitation

Next Article

Academic Study Reveals How Security Fatigue Undermines Digital Defense Postures→