[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fiGN7zxoCbPdtSrUpX0gV76wx3ya80qfPK1BUN0lz8xQ":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":27,"created_at":28,"published_at":29,"article":30,"tags":34,"podcasts":53},"3d06f14e-c73a-47ef-ba04-6d79f493c04a","iranian-state-linked-hacker-extradited-after-decade-long-data-theft-campaign","6a249fb0-6c6d-48a1-85f3-be7dd133bf4f","Iranian State-Linked Hacker Extradited After Decade-Long Data Theft Campaign","The Mabna Institute's decade-long campaign succeeded by systematically exploiting weak or reused credentials, unpatched systems, and insufficient monitoring across hundreds of universities and government agencies. Over 31 terabytes of sensitive intellectual property and research data were exfiltrated, demonstrating the catastrophic scale that persistent, state-sponsored intrusions can reach when left undetected. The targeting of academic and government institutions highlights how high-value data repositories are prime targets for nation-state actors seeking strategic, economic, or military advantages. This case underscores that even organizations without obvious 'critical infrastructure' status can be high-value targets, and that prolonged dwell time is enabled by inadequate detection and response capabilities.","**Immediate actions:**\n- Enforce multi-factor authentication (MFA) on all externally accessible systems, especially email, VPNs, and research portals.\n- Conduct an immediate credential audit to identify and reset compromised, reused, or weak passwords across all user accounts.\n- Deploy threat intelligence feeds to detect known Mabna\u002FIRGC-associated indicators of compromise (IOCs).\n\n**Long-term improvements:**\n- Implement a Zero Trust Architecture to require continuous verification for all users accessing sensitive research or government data.\n- Establish a formal vulnerability management program with regular scanning and prioritized patching of internet-facing assets.\n- Segment networks so that academic, administrative, and sensitive research systems cannot be laterally traversed from a single compromised account.\n\n**Detection measures:**\n- Deploy a SIEM solution with behavioral analytics to flag anomalous data exfiltration patterns, such as large-volume transfers or off-hours access.\n- Enable comprehensive logging of authentication events, privileged access, and data movement, with logs retained for a minimum of 12 months.\n- Conduct regular purple-team or threat-hunting exercises specifically simulating nation-state lateral movement and data staging techniques.",[12,13,14,15,16,17,18,19,20,21,22,23,24,25,26],"CIS Control 4 – Controlled Use of Administrative Privileges","CIS Control 6 – Access Control Management","CIS Control 8 – Audit Log Management","CIS Control 12 – Network Infrastructure Management","CIS Control 17 – Incident Response Management","NIST SP 800-53 AC-2 (Account Management)","NIST SP 800-53 AC-17 (Remote Access)","NIST SP 800-53 IA-5 (Authenticator Management)","NIST SP 800-53 SI-4 (System Monitoring)","NIST SP 800-53 RA-5 (Vulnerability Monitoring and Scanning)","NIST CSF DE.CM-1 (Network Monitoring)","NIST CSF PR.AC-1 (Identity and Access Management)","GDPR Article 32 (Security of Processing)","MITRE ATT&CK T1078 (Valid Accounts)","MITRE ATT&CK T1486 (Data Encrypted for Impact \u002F Exfiltration)","published","2026-10-02T12:21:08.349673+00:00","2026-10-02T12:21:07.859+00:00",{"id":7,"url":31,"slug":32,"title":33},"https:\u002F\u002Fwww.securityweek.com\u002Fin-rare-move-iranian-hacker-accused-of-working-for-irgc-extradited-to-us\u002F","in-rare-move-alleged-iranian-state-hacker-extradited-to-us-7e6b0b","In Rare Move, Alleged Iranian State Hacker Extradited to US",[35,41,47],{"id":36,"name":37,"slug":38,"description":39,"color":40},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":42,"name":43,"slug":44,"description":45,"color":46},"1732a005-556e-411c-a9db-5edec3058571","Logging & Monitoring","logging-monitoring","Missing logs, no alerting, blind spots","#a855f7",{"id":48,"name":49,"slug":50,"description":51,"color":52},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",[54],{"id":55,"date":56,"edition":57,"title":58,"audio_url":59},"faf4ceef-c23f-4902-b3c2-971b5b527a35","2026-10-02","afternoon","ThreatNoir Afternoon Brief — October 2","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-10-02\u002Fthreatnoir-afternoon-brief-2026-10-02.mp3"]