:

IRAN-LINKED HACKERS TARGET SOUTH KOREAN TECH FIRM

SECURITY DESK1 MIN READ
WED, MAY 13, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

The MuddyWater hacking group, linked to Iran, launched a cyber-espionage campaign against a major South Korean electronics maker alongside eight other high-profile organizations across multiple sectors and countries.

MuddyWater, also known as Seedworm and Static Kitten, conducted a broad attack targeting at least nine organizations globally. The Iran-affiliated group is known for espionage operations focused on collecting sensitive information from government and private sector entities. The campaign represents a significant escalation in cyber-espionage activities targeting South Korean tech companies, which are frequent targets due to their access to advanced technologies and intellectual property. The attack underscores growing concerns about state-sponsored hacking operations in the region. Details on compromised systems, stolen data, or the specific nature of the electronics maker's breach remain limited. The targeted organization has not yet issued a public statement regarding the incident. MuddyWater has maintained an active presence in cyber-espionage since at least 2017, targeting organizations across energy, telecommunications, and government sectors. Security researchers have tracked the group's evolving tactics and infrastructure over the past six years.

■ SOURCES

Bleeping Computer

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

Americans are systematically targeting and disabling Flock Safety cameras across the country in a decentralized protest movement. The surveillance devices face everything from vandalism to theft as public opposition intensifies.

3H AGOIndustry Desk

The US Justice Department has dismantled online infrastructure used by Chinese state-sponsored hackers targeting NASA, the Federal Reserve, and the Senate. The action represents a coordinated effort to disrupt cyber operations against American government agencies and critical infrastructure.

3H AGOSecurity Desk

The U.S. Cybersecurity and Infrastructure Security Agency has issued a mandate requiring all federal agencies to patch an actively exploited remote code execution vulnerability in Citrix NetScaler appliances by Saturday.

13H AGOSecurity Desk

A new Rowhammer attack called GPUThor can bypass error-correcting code (ECC) protections on NVIDIA GPUs, enabling denial-of-service attacks and root-level privilege escalation.

YESTERDAYIndustry Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.