[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fsJZnYnXtzhsdOAFz7YiLTVWAm2Mo8pvujeDiI23PQjQ":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":18,"created_at":19,"published_at":20,"article":21,"tags":25,"podcasts":38},"79baf9e8-ee1e-43ee-a17b-eef0364b0d0d","iranian-state-actors-exploit-human-vulnerabilities-through-advanced-phishing-and-seo-poisoning","c5a240b2-5ffb-41b2-a0ec-e40dfc19ce75","Iranian State Actors Exploit Human Vulnerabilities Through Advanced Phishing and SEO Poisoning","Iranian state-sponsored group Nimbus Manticore successfully compromised aviation and software sector employees by combining traditional phishing with innovative SEO poisoning tactics to distribute trojanized software installers. The attackers leveraged human trust in legitimate-looking websites and software downloads, bypassing technical security controls through social engineering. This campaign demonstrates how threat actors are evolving their tactics to exploit the weakest link in cybersecurity - human decision-making - while potentially using AI to enhance their malware development capabilities.","**Immediate actions:**\n- Implement mandatory security awareness training focused on identifying phishing attempts and suspicious downloads\n- Deploy email security solutions with advanced threat protection and sandboxing capabilities\n- Establish strict policies requiring verification of software sources before installation\n\n**Long-term improvements:**\n- Develop comprehensive software supply chain security procedures including approved vendor lists and download verification\n- Create regular phishing simulation programs to test and improve employee awareness\n- Implement application whitelisting and endpoint detection and response (EDR) solutions\n\n**Detection measures:**\n- Monitor for unusual network traffic patterns and suspicious process executions\n- Establish baseline monitoring for legitimate software installation patterns\n- Deploy web filtering solutions to block known malicious domains and SEO-poisoned results",[12,13,14,15,16,17],"CIS Control 14 (Security Awareness Training)","CIS Control 7 (Email and Web Browser Protections)","NIST SP 800-53 AT-2 (Security Awareness Training)","NIST SP 800-161 (Supply Chain Risk Management)","NIST CSF PR.AT (Security Awareness)","ISO 27001 A.7.2.2 (Information Security Awareness)","published","2026-05-27T04:56:40.209864+00:00","2026-05-27T04:56:40.12+00:00",{"id":7,"url":22,"slug":23,"title":24},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F05\u002Firanian-hackers-deploy-minifast-and.html","iranian-hackers-deploy-minifast-and-minijunk-v2-via-phishing-and-seo-poisoning-c93bc1","Iranian Hackers Deploy MiniFast and MiniJunk V2 via Phishing and SEO Poisoning",[26,32],{"id":27,"name":28,"slug":29,"description":30,"color":31},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",{"id":33,"name":34,"slug":35,"description":36,"color":37},"f0c2a0af-58aa-4128-87c9-6acd30f2dc48","Supply Chain","supply-chain","Third-party risk, compromised dependencies","#8b5cf6",[39],{"id":40,"date":41,"edition":42,"title":43,"audio_url":44},"634568c7-4de9-45db-8fed-04406640f9c8","2026-05-26","afternoon","ThreatNoir Afternoon Brief — May 26","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-05-26\u002Fthreatnoir-afternoon-brief-2026-05-26.mp3"]