This Week's Top Five Stories in Cyber Unit 42 Shows How Iranian Hackers Hide Behind Job Postings In modern warfare, a large part of the fighting is done away from the battlefield. Cyberspace is now a frontier of war, alongside land, sea, air and space. This is certainly the case for the unfolding conflict in the Middle East. Researchers have uncovered an Iranian advanced persistent threat (APT) group in action targeting organisations across the US, Israel and UAE. Palo Alto Networks’ Unit 42 stumbled upon a sophisticated cyber espionage campaign linked to Screening Serpens – who also go by aliases such as Smoke Sandstorm, Iranian Dream Job and UNC1549. The latest findings from Unit 42 points to the threat group deploying six new remote access Trojan (RAT) variants deployed between February and April 2026. Researchers believe additional entities across the Middle East may also have been affected. CrowdStrike Dismantles Developer-Targeting Glassworm Botnet In a year where software supply chain attacks dominated the cyber news cycle, the strategic takedown of the Glassworm botnet is welcome news for developers everywhere. Through a combined operation with Google and the Shadowserver Foundation, cybersecurity giant CrowdStrike successfully dismantled a sophisticated global botnet designed to withstand traditional takedown efforts. The effort led by CrowdStrike’s Counter Adversary Operations team targeted an advanced malware infrastructure that used four separate command and control channels to remain active even if parts of the network were disabled. From early in 2025, Glassworm operators had been systematically targeting their prey of choice – developers, high value targets with access to source code repos, cloud, CI/CD pipelines and package registries. A good target choice, as a single developer compromise could soon snowball into vast supply chain compromises impacting thousands of users and enterprises downstream. Zscaler Acquires Symmetry Systems to Map & Secure AI