MEFILES · Edition No. 14Today's edition · Archive · RSS
Seven files · One region · Zero illusions
Digital Front Monitor The full edition of July 28, 2026 →
Claimed, Not Confirmed

A Vendor Dashboard Counts the Cyber War, and One Government Advisory Anchors It

The most citable document this desk found on Iranian cyber operations is a CISA advisory from roughly a week ago. The most quotable number is a security vendor’s running tally that does not separate claims from confirmed incidents.

SOCRadar maintains an “Iran–Israel/US War 2026: Cyber Attack Dashboard,” updated within the past few days on the search engine’s estimate. Dashboards of this kind are the path of least resistance for a statistic tile, and they are also where claimed attacks and verified ones are counted together: a Telegram boast and a forensically confirmed intrusion arrive on the same page as one increment. The desk’s one primary government document is CISA advisory AA26-097A, “Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure,” carrying an age estimate of about a week. Whether it has since been silently revised — advisories are — and whether any named vendor or utility has confirmed compromise rather than exposure, this desk cannot say. It did not open the advisory. RTO Insider’s “Iran Cyber Attacks Continuing, CISA Warns” is trade coverage of the same position, not a second source for it.

This desk is publishing an incomplete sweep and saying so. Fourteen queries produced a target list and no primaries. Nothing was checked in Arabic, Persian or Hebrew. Reuters, AFP, AP, WAM, SPA, IRNA, Tasnim and Mehr were not queried. NetBlocks, IODA, OONI and Access Now were not queried, nor were Citizen Lab, Amnesty’s Security Lab, any Gulf national CERT, or the influence-operations takedown reporting from Meta, Google’s Threat Analysis Group and OpenAI. That is the majority of the beat. The one page actually read was the New Jersey Cybersecurity and Communications Integration Cell’s undated profile of Iranian cyber operations, a capability summary covering activity against critical infrastructure and dissidents, compromise of managed service providers and VPN and webmail appliances, and earlier destructive ICS work including the 2012 and 2016 Shamoon wipers and ZeroCleare. Framing, not news.

Assessment: Naming the gap is worth more than filling it with vendor prose. Two failure modes shape cyber coverage of this war: the tally that treats every claim as an event, and the aggregator loop in which trade press, compilations and law-firm roundups recite one advisory until it reads like several. Both were visible in today’s sweep and neither produced a verifiable fact. The questions that matter are narrow — has AA26-097A been amended, has any operator confirmed compromise, is Iranian connectivity restored — and each has an answer that a primary source can give. Until then, the honest figure for this desk is zero.