Searches for this week’s Iran cyber news keep returning documents six months old
A sweep of the 28 September–1 October window surfaced almost no new reporting on Iranian and Israeli cyber operations. What it surfaced instead was a stack of spring documents being re-indexed as current.
The single clearest signal from this desk’s sweep of the past 72 hours is negative: queries built around the current window returned, repeatedly, the CISA advisory AA26-097A on Iranian-affiliated actors exploiting programmable logic controllers across US critical infrastructure. That advisory, published at cisa.gov and mirrored as a PDF on the FBI’s IC3 site, is dated 7 April 2026 — roughly 177 days old. It is a legitimate document. It is not this week’s news, and anything presenting it as such is a re-share. The same pattern held across the spyware beat, where search indexing assigned a recent page age to Citizen Lab research on Pegasus deployments in 45 countries that in fact dates from 2018, making the “45 countries” figure the most reliably misdated number in circulation.
The recycling runs across every sub-beat. Reporting on an Iranian hack-and-leak operation touching Benjamin Netanyahu’s circle dates to 7 January 2026, some 266 days back, and surfaces on nearly every Israeli hack-and-leak query. Remarks by an Israeli cyber chief on a surge in Iranian attacks are roughly 93 days old and still passed around as current. Unit 42’s “Screening Serpens” research is about 111 days old; Symantec’s Seedworm work around 208. On connectivity, NetBlocks posts describing Iran’s 2026 blackout reaching its tenth week date to approximately May 2026, and the “two full weeks” and “20 full days” posts to March. This desk found no evidence of a fresh Iranian disruption in the window — but could not complete a live measurement check, so that is unconfirmed absence, not absence.
What was genuinely published inside the window is thin and mostly aggregation rather than reporting: Security Boulevard’s daily OT security digest for 30 September, and the Thai National Cyber Security Agency’s 30 September threat intelligence post, a government CERT digest that occasionally carries regional industrial control items ahead of Western trackers. Both are indexes to primary sources, not primary sources. The nearest thing to a measured regional data point remains Internet Society Pulse’s record of an exam-related shutdown in Iraq on 8 September — three weeks old, usable only as one entry in a pattern, and only if dated plainly.
Assessment: The failure mode here is not fabrication, it is velocity. Search indexing assigns page ages, not publication dates, and a document re-crawled last week reads as last week’s. Feeds and vendor newsletters then launder the age out entirely. The result is a Middle East cyber discourse in which April’s PLC advisory and 2018’s Pegasus count are perpetually fresh, which flatters analysts who need a threat to be ongoing and costs nothing to anyone who repeats it. Treat any Iranian-attack claim this week as dated until the original publication line is checked. The absence of new APT research in the window is itself worth noting — and worth confirming properly.