The documentary record behind this week’s Iran cyber coverage is between six weeks and eight months old
A July 22 CISA advisory is being repackaged with September datelines. Everything else on the desk — shutdown data, hack-and-leak incidents, wiper activity — predates the window by months.
The most solid document in circulation on Iranian cyber activity against US infrastructure is joint advisory AA26-097A, issued by CISA with the FBI, the EPA and other US government partners, warning that Iran-affiliated actors are exploiting programmable logic controllers across critical infrastructure. It is dated July 22, 2026, and CISA framed it at the time as an update to earlier warnings, the predecessor being AA23-335A on IRGC-affiliated PLC exploitation from 2023. That advisory is now seven weeks old. It is nonetheless resurfacing in search results with fresh datelines: an aggregation site, shattered.io, was indexed around September 5 with a piece headlined on Iranian hackers targeting three US sectors and a CISA warning. The Files has not opened that page and makes no claim about its contents beyond the date it carries.
The rest of the record follows the same shape. The heaviest body of reported Iranian offensive activity is the hack-and-leak series against Israeli figures running from January to May 2026, documented largely by Haaretz — material touching Netanyahu’s circle in January, the emails of former Mossad chief Tamir Pardo on March 30, photographs of former IDF chief Herzi Halevi in April. Krebs on Security reported the CanisterWorm wiper campaign aimed at Iran in March. Connectivity data is older still: the NetBlocks figure of 1,056 cumulative hours of internet shutdown in Iran was reported by IranWire in April, and The Files has not confirmed the measurement window it covers. No new APT research dated inside September 5–8 surfaced in this sweep.
Assessment: Two cautions. First, vendor material dominates the freshest-looking results — dashboards and capability reports from firms whose revenue rises with the perceived threat level. Read them as marketing with research attached. Second, the absence of a finding is not the absence of an event: this sweep was truncated, ran no Arabic, Persian or French queries, and covered none of the Sahel. What can be said is narrower and more useful. Nothing in the public documentary record has moved since July 22. A story that feels like it is accelerating is being carried by republication, not by new evidence.