The Justice Department accused 17 alleged hackers with ties to the Iranian government of breaching email accounts at U.S. government agencies and stealing intellectual property from dozens of universities.

The U.S. Justice Department has unsealed a 14-count indictment against 17 individuals, accusing them of participating in a wide-ranging hacking campaign on behalf of Iran’s Islamic Revolutionary Guard Corps (IRGC). The campaign, which allegedly began around 2013, targeted numerous U.S. and international entities, including government agencies, universities, and private companies.
Prosecutors allege that the hackers operated through an Iranian company identified as the Mabna Institute. Eight of the individuals named in the current indictment had previously been charged in 2018 for their involvement in a separate hacking operation. The State Department has offered a reward of up to $10 million for information leading to the apprehension of five individuals—Behzad Mesri, Mojtaba Galekuhi, Arman Kahzadian, Keyvan Fayaz, and Saber Shahbazi Ballojeh—who are accused of being employed by or affiliated with the Mabna Institute to conduct cyber intrusions.
The indictment details breaches of employee email accounts at several U.S. government entities, including the Department of Labor and the Federal Energy Regulatory Commission. State government agencies in Hawaii and Indiana were also reportedly affected. Internationally, the campaign targeted multiple United Nations organizations, specifically mentioning the U.N. Children’s Fund. The U.N. has not publicly commented on these allegations.
Beyond government targets, the group is accused of compromising 144 U.S.-based universities and 42 U.S. companies, alongside 178 foreign universities and at least 11 foreign companies. The university attacks allegedly involved successfully compromising approximately 8,000 email accounts belonging to professors between 2013 and 2017. The hackers reportedly used stolen credentials to gain access to these accounts.
The stolen data, which prosecutors estimate to be at least 31 terabytes, included academic journals, theses, dissertations, and electronic books across dozens of fields. This intellectual property was allegedly provided to the Iranian government and also sold through two websites to universities within Iran. One of these websites reportedly allowed Iranian customers to use stolen professor accounts to access the online library systems of various U.S. universities. Universities impacted by these breaches are estimated to have spent around $20 million on investigation and remediation efforts.
One of the indicted individuals, Behzad Mesri, was previously charged for an attack on the media company HBO, from which he allegedly attempted to extort $6 million.
Assistant Attorney General John Eisenberg stated that the defendants, at the behest of entities including the IRGC, hacked into universities and research institutions worldwide, stealing intellectual property of "untold value." FBI Assistant Director Brett Leatherman described the operation as a "sprawling hacking-for-hire operation" that targeted intellectual property for the benefit of the Iranian government.

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.