Close Menu
    DevStackTipsDevStackTips
    • Home
    • News & Updates
      1. Tech & Work
      2. View All

      CodeSOD: Across the 4th Dimension

      September 25, 2025

      Cursor vs GitHub Copilot (2025): Which AI Platform Wins for Your Node.js Dev Team?

      September 25, 2025

      NuGet adds support for Trusted Publishing

      September 25, 2025

      AWS launches IDE extension for building browser automation agents

      September 25, 2025

      Distribution Release: Kali Linux 2025.3

      September 23, 2025

      Distribution Release: SysLinuxOS 13

      September 23, 2025

      Development Release: MX Linux 25 Beta 1

      September 22, 2025

      DistroWatch Weekly, Issue 1140

      September 21, 2025
    • Development
      1. Algorithms & Data Structures
      2. Artificial Intelligence
      3. Back-End Development
      4. Databases
      5. Front-End Development
      6. Libraries & Frameworks
      7. Machine Learning
      8. Security
      9. Software Engineering
      10. Tools & IDEs
      11. Web Design
      12. Web Development
      13. Web Security
      14. Programming Languages
        • PHP
        • JavaScript
      Featured

      Beyond Denial: How AI Concierge Services Can Transform Healthcare from Reactive to Proactive

      September 25, 2025
      Recent

      Beyond Denial: How AI Concierge Services Can Transform Healthcare from Reactive to Proactive

      September 25, 2025

      IDC ServiceScape for Microsoft Power Apps Low-Code/No-Code Custom Application Development Services

      September 25, 2025

      A Stream-Oriented UI library for interactive web applications

      September 24, 2025
    • Operating Systems
      1. Windows
      2. Linux
      3. macOS
      Featured

      FOSS Weekly #25.39: Kill Switch Phones, LMDE 7, Zorin OS 18 Beta, Polybar, Apt History and More Linux Stuff

      September 25, 2025
      Recent

      FOSS Weekly #25.39: Kill Switch Phones, LMDE 7, Zorin OS 18 Beta, Polybar, Apt History and More Linux Stuff

      September 25, 2025

      Distribution Release: Kali Linux 2025.3

      September 23, 2025

      Distribution Release: SysLinuxOS 13

      September 23, 2025
    • Learning Resources
      • Books
      • Cheatsheets
      • Tutorials & Guides
    Home»Development»U.S. Hit by Hacktivist DDoS Attacks Following Iran Bombings

    U.S. Hit by Hacktivist DDoS Attacks Following Iran Bombings

    June 24, 2025

    U.S. DDoS attacks follow Iran bombing

    Iran-aligned hacktivists launched DDoS attacks against 15 U.S. organizations and 19 websites in the first 24 hours after the U.S. bombed Iranian nuclear targets on June 21, Cyble threat intelligence researchers reported today.

    The Cyble blog post said the cyberattack targets have included U.S. Air Force websites, Aerospace & Defense companies, financial services organizations, and an unverified claim of an attack on Truth Social, the social media platform of U.S. President Donald Trump.

    The U.S. entry into the Israel-Iran conflict was met with less intensive cyber activity than the hacktivism and cyberwarfare that have engulfed the Middle East since the conflict began on June 13 with Israeli attacks on Iranian nuclear and military targets. The U.S. DDoS attacks coincided with a June 22 Department of Homeland Security warning that “Low-level cyber attacks against US networks by pro-Iranian hacktivists are likely, and cyber actors affiliated with the Iranian government may conduct attacks against US networks.”

    U.S. DDoS Attacks Launched by Iran-linked Hacktivists

    Cyble said four hacktivist groups were predominantly responsible for the initial U.S. DDoS attacks: Mr Hamza, Team 313, Keymous+ and Cyber Jihad. The groups’ claims range from “credible to questionable,” the researchers wrote.

    Mr Hamza claimed that it targeted several websites belonging to the U.S. Air Force and Aerospace & Defense companies. The group posted its exploits using the hashtag #Op_Usa and included check-host.net reports that indicated downtime of the websites over a 10-hour period on June 22 (screenshot below).

    Mr Hamza claims U.S. DDoS attacks
    Hacktivist group Mr Hamza claims U.S. DDoS attacks (Cyble)

    Keymous+ claimed to have targeted U.S. financial organizations and included check-host.net links showing website disruptions over a one-hour period on June 22.

    Team 313 claimed to have targeted Truth Social “but the group did not offer sufficient proof to deem the claim credible,” Cyble said.

    Cyber Jihad Movement said it was planning to launch cyberattacks against U.S. targets between June 23 and June 27.

    U.S. Hacktivist Activity Small Compared to Middle East

    Cyble said the initial volume of hacktivist attacks on U.S. targets “has been small compared to the large number of attacks and threat groups that have been active in the Middle East,” where the threat intelligence researchers have recorded attacks by 88 groups, 81 of which are aligned with Iran (image below).

    Israel Iran hacktivist groups
    Hacktivist groups active in Israel-Iran conflict (Cyble)

    Middle East cyberattacks have included “DDoS attacks, data and credential leaks, website defacements, unauthorized access, and major breaches of Iranian banking and cryptocurrency targets by Israel-linked Predatory Sparrow,” Cyble said. Interference with commercial ship navigation systems in the region has also been reported.

    The Handala hacktivist group “appears to have been one of the more effective attackers,” Cyble said, with 15 claims of mostly well documented ransomware/extortion incidents. The group’s victims have all been based in Israel.

    In one noteworthy incident, a threat actor on the cybercrime forum Darkforums claimed to be offering unauthorized SSH access and VPN credentials of three user accounts for the VPN portal of the Israel Defense Forces (IDF) for the asking price of 2 BTC.

    Russian groups have been largely absent from the Middle East cyber conflict, Cyble said, with two notable exceptions: Z-Pentest claimed that it compromised an industrial control system (ICS) belonging to an Israeli energy and utilities organization, while NoName057(16) claimed a DDoS attack on an Israeli transportation entity.

    Attacks have also been aimed at Jordan, Egypt, the UAE and Saudi Arabia, “which appear to have been perceived as too neutral by Iran-aligned groups,” Cyble said.

    Cyble urged organizations that could become a target of hacktivists to protect themselves against DDoS attacks, data breaches, website defacements, “and increasingly, ransomware and critical infrastructure attacks.”

    Source: Read More

    Facebook Twitter Reddit Email Copy Link
    Previous ArticleHackers Are Poisoning Google Search Results for AI Tools to Deliver Infostealer Malware
    Next Article The AI Fix #56: ChatGPT traps man in a cult of one, and AI is actually stupid

    Related Posts

    Development

    Beyond Denial: How AI Concierge Services Can Transform Healthcare from Reactive to Proactive

    September 25, 2025
    Development

    IDC ServiceScape for Microsoft Power Apps Low-Code/No-Code Custom Application Development Services

    September 25, 2025
    Leave A Reply Cancel Reply

    For security, use of Google's reCAPTCHA service is required which is subject to the Google Privacy Policy and Terms of Use.

    Continue Reading

    CVE-2025-6614 – D-Link DIR-619L Stack-Based Buffer Overflow Vulnerability

    Common Vulnerabilities and Exposures (CVEs)

    CVE-2025-3471 – “SureForms WordPress Plugin Unauthenticated Configuration Update”

    Common Vulnerabilities and Exposures (CVEs)

    CVE-2025-46656 – Markdownify Headline Prefix Overflow

    Common Vulnerabilities and Exposures (CVEs)

    CVE-2025-48146 – LupsOnline SEO Flow CSRF Stored XSS

    Common Vulnerabilities and Exposures (CVEs)

    Highlights

    CVE-2025-40596 – SMA100 Series Web Interface Stack-based Buffer Overflow Vulnerability

    July 23, 2025

    CVE ID : CVE-2025-40596

    Published : July 23, 2025, 3:15 p.m. | 7 hours, 50 minutes ago

    Description : A Stack-based buffer overflow vulnerability in the SMA100 series web interface allows remote, unauthenticated attacker to cause Denial of Service (DoS) or potentially results in code execution.

    Severity: 7.3 | HIGH

    Visit the link for more details, such as CVSS details, affected products, timeline, and more…

    Linus Torvalds: Rivoluzionario per Caso Dal Commodore VIC-20 a Linux

    April 13, 2025

    CVE-2025-4977 – Netgear DGND3700 Cross-Site Scripting Vulnerability

    May 20, 2025

    Neumorphic Login Form with Floating Labels

    April 26, 2025
    © DevStackTips 2025. All rights reserved.
    • Contact
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.