BT
Privacy ToolboxJournalProjectsResumeBookmarks
Feed
Privacy Toolbox
Journal
Projects
Resume
Bookmarks
Intel
CIPHER
The Vault
Threat Actors
Privacy Threats
Malware IoC
Dashboard
CVEs
Tags
Intel
CIPHERThe VaultThreat ActorsPrivacy ThreatsMalware IoCDashboardCVEsTags

Intel

  • Feed
  • Threat Actors
  • Privacy Threats
  • Dashboard
  • Privacy Toolbox
  • CVEs

Personal

  • Journal
  • Projects

Resources

  • Subscribe
  • Bookmarks
  • Developers
  • Tags
Cybersecurity News & Analysis
github
defconxt
•
© 2026
•
blacktemple.net
  1. Feed
  2. /Nation-State Roundup: Iran-linked Handala Targets FBI Director, ShinyHunters Breaches EU Commission, Apple Warns of Active Web Exploits

Nation-State Roundup: Iran-linked Handala Targets FBI Director, ShinyHunters Breaches EU Commission, Apple Warns of Active Web Exploits

highNation-State & APT|March 29, 20262 min read

Originally reported by Security Affairs

#iran-apt#handala#shinyhunters#european-commission#apple-ios#web-exploits#fbi-director#data-breach
Share

TL;DR

Iran-linked threat actor Handala reportedly compromised FBI Director Kash Patel's systems while ShinyHunters claims to have breached the European Commission's mail servers. Apple is simultaneously warning users of active web-based exploits targeting unpatched iOS devices.

Why high?

Iran-linked APT targeting FBI Director Kash Patel represents a significant nation-state operation against senior US law enforcement leadership. ShinyHunters' alleged breach of the European Commission adds further high-impact institutional targeting.

Iran-linked Handala APT Targets FBI Director

According to Security Affairs reporting, the Iran-linked threat group Handala has allegedly compromised systems belonging to FBI Director Kash Patel. The targeting of senior US law enforcement leadership represents a significant escalation in nation-state cyber operations against American government officials.

Handala has previously been associated with pro-Iranian hacktivist activities, though specific technical details of the alleged compromise have not been disclosed. The targeting of the FBI Director carries particular significance given the bureau's counterintelligence and cybercrime investigation responsibilities.

ShinyHunters Claims European Commission Breach

The cybercrime group ShinyHunters has claimed responsibility for breaching the European Commission, allegedly exfiltrating data from mail servers and internal communications systems. Security Affairs reports that the group has added the Commission to its Tor-based data leak site.

The alleged breach represents a significant compromise of European Union institutional infrastructure. ShinyHunters, known for previous high-profile data breaches, claims to have obtained sensitive internal communications, though the full scope and verification of the alleged compromise remains unclear.

The European Commission has not yet publicly confirmed the breach or provided details on potential data exposure.

Apple Issues Urgent Lock Screen Exploit Warnings

Apple is actively pushing lock screen notifications to users running outdated iOS and iPadOS versions, warning of active web-based attacks targeting unpatched devices. The company is urging immediate software updates to protect against ongoing exploitation attempts.

The lock screen alerts represent an unusual direct intervention by Apple, suggesting active threat intelligence indicating widespread targeting of vulnerable iOS devices. The web-based nature of the attacks suggests drive-by exploitation techniques that could affect users through malicious websites or compromised legitimate sites.

Users running older iOS versions should immediately update to the latest available software version to protect against these active threats.

Sources

  • Security Affairs newsletter Round 569 by Pierluigi Paganini
  • Apple issues urgent lock screen warnings for unpatched iPhones and iPads
  • ShinyHunters claims the hack of the European Commission

Originally reported by Security Affairs

Tags

#iran-apt#handala#shinyhunters#european-commission#apple-ios#web-exploits#fbi-director#data-breach

Threat Actors

🏴ShinyHunters

Tracked Companies

🇺🇸Apple

Related Intelligence

  • Security Roundup: FBI Warns of Iranian Fake App Campaign, OVHcloud Denies Major Breach Claims

    mediumMar 25, 2026
  • APT Activity Roundup: Iran-Linked Energy Targeting, Major DeFi Breach, and Critical Infrastructure Vulnerabilities

    highMar 24, 2026
  • Magento Under Siege: PolyShell Zero-Day Fuels Mass Defacements, AI Fraud Tactics Emerge

    highMar 21, 2026

Related Knowledge

  • Threat Intelligence Deep Training

    reference
  • MITRE ATT&CK / D3FEND Deep Reference

    reference
  • CIPHER Training: Emerging Threats Deep Dive (2025-2026)

    reference

Explore

  • Dashboard
  • Privacy Threats
  • Threat Actors
← Back to the feed

Previous Article

← CISA KEV Additions, TeamPCP Supply Chain Attacks, and Critical Infrastructure Under Fire

Next Article

Lloyds Banking Group to Compensate 450,000 Customers Following Mobile App Data Exposure→