MEFILES · Edition No. 55Today's edition · Archive · RSS
Ten files · One region · Zero illusions
All Digital Front Monitor stories → The full edition of September 8, 2026 →
The Evidence Base

The documentary record behind this week’s Iran cyber coverage is between six weeks and eight months old

A July 22 CISA advisory is being repackaged with September datelines. Everything else on the desk — shutdown data, hack-and-leak incidents, wiper activity — predates the window by months.

The most solid document in circulation on Iranian cyber activity against US infrastructure is joint advisory AA26-097A, issued by CISA with the FBI, the EPA and other US government partners, warning that Iran-affiliated actors are exploiting programmable logic controllers across critical infrastructure. It is dated July 22, 2026, and CISA framed it at the time as an update to earlier warnings, the predecessor being AA23-335A on IRGC-affiliated PLC exploitation from 2023. That advisory is now seven weeks old. It is nonetheless resurfacing in search results with fresh datelines: an aggregation site, shattered.io, was indexed around September 5 with a piece headlined on Iranian hackers targeting three US sectors and a CISA warning. The Files has not opened that page and makes no claim about its contents beyond the date it carries.

The rest of the record follows the same shape. The heaviest body of reported Iranian offensive activity is the hack-and-leak series against Israeli figures running from January to May 2026, documented largely by Haaretz — material touching Netanyahu’s circle in January, the emails of former Mossad chief Tamir Pardo on March 30, photographs of former IDF chief Herzi Halevi in April. Krebs on Security reported the CanisterWorm wiper campaign aimed at Iran in March. Connectivity data is older still: the NetBlocks figure of 1,056 cumulative hours of internet shutdown in Iran was reported by IranWire in April, and The Files has not confirmed the measurement window it covers. No new APT research dated inside September 5–8 surfaced in this sweep.

Assessment: Two cautions. First, vendor material dominates the freshest-looking results — dashboards and capability reports from firms whose revenue rises with the perceived threat level. Read them as marketing with research attached. Second, the absence of a finding is not the absence of an event: this sweep was truncated, ran no Arabic, Persian or French queries, and covered none of the Sahel. What can be said is narrower and more useful. Nothing in the public documentary record has moved since July 22. A story that feels like it is accelerating is being carried by republication, not by new evidence.

Digital Front MonitorMEFILES tracking
July 22date of the advisory now carrying September datelines
Evidence6 cited sources · CISA · Haaretz · Krebs on Security · IranWire
The file19 Jul: 0 stories22 Jul: 2 stories23 Jul: 1 story24 Jul: 1 story25 Jul: 2 stories26 Jul: 2 stories27 Jul: 2 stories28 Jul: 2 stories29 Jul: 2 stories30 Jul: 2 stories31 Jul: 2 stories1 Aug: 2 stories2 Aug: 2 stories3 Aug: 2 stories4 Aug: 2 stories5 Aug: 2 stories6 Aug: 2 stories7 Aug: 2 stories8 Aug: 2 stories9 Aug: 2 stories10 Aug: 2 stories11 Aug: 2 stories13 Aug: 2 stories14 Aug: 2 stories15 Aug: 2 stories16 Aug: 2 stories17 Aug: 2 stories18 Aug: 2 stories19 Aug: 2 stories20 Aug: 2 stories21 Aug: 2 stories22 Aug: 3 stories23 Aug: 2 stories24 Aug: 3 stories25 Aug: 3 stories26 Aug: 2 stories27 Aug: 2 stories28 Aug: 2 stories29 Aug: 2 stories30 Aug: 2 stories31 Aug: 2 stories1 Sept: 2 stories2 Sept: 2 stories3 Sept: 2 stories4 Sept: 2 stories5 Sept: 2 stories6 Sept: 3 stories7 Sept: 2 stories8 Sept: 2 stories
Digital Front Monitor · 49 editions since 19 July 2026 · 98 stories filed · 2 in this edition