Nine Iran-cyber reports from July and August keep surfacing as though they broke this week
Searches scoped to the last 72 hours returned a stack of material two weeks to two months old. On a desk that covers the information war, that ranking pattern is the finding.
The oldest item still ranking high is CISA advisory AA26-097A on Iranian-affiliated actors exploiting programmable logic controllers across US critical infrastructure, published 22 July. Citizen Lab’s Pegasus mapping across 45 countries dates to 24 July and its Candiru report to 16 July. Axios reported Meta’s disruption of an Iran-linked AI operation targeting politicians and journalists on 27 August. NBC News, citing unnamed sources, reported attempted Iranian cyberattacks on US infrastructure around 2–3 September — a story already recirculated once through NewsNation — and The National in Abu Dhabi ran its Iran cyber-strategy piece on 2 September. RFE/RL’s 3 September report on a new Iranian bill to tighten internet control is mirrored on GlobalSecurity.org, which strips the publication date. Middle East Eye’s report on suspected spyware attacks against Turkish ministers' phones is from around 10 September.
Two characteristics recur. The first is undated publication: Trellix’s “The Iranian Cyber Capability 2026” carries no visible date on the page, which makes any citation of it unfalsifiable as to timing. The second is date-stripping in transit — the RFE/RL mirror is the clean example, where a dated wire report becomes an undated claim one hop downstream. Neither requires anyone to lie. A sanctioned vendor, an anonymous-source wire story and a two-month-old federal advisory can all be accurately quoted and still leave a reader with a false impression of when, and how often, something happened. The honest caveat is that this is a read of search returns, not a measurement of what regional audiences actually saw; it establishes availability, not reach.
Assessment: The test over the coming week is narrow and answerable: whether any of these nine resurfaces in partisan or state-aligned feeds presented as current. AA26-097A and the undated Trellix paper are the likeliest candidates, because one carries federal authority and the other carries no timestamp to contradict. Two in-window items deserve attention for the opposite reason. Citizen Lab published UN reports citing its submissions on 23 September, and no outlet has yet said which states are named. And CISA retires its weekly vulnerability bulletin on 28 September — a measurable reduction in public advisory visibility, with a hard date, and no announced regional successor.