A quiet weekend on the Iran–Israel cyber front, and an archive pretending otherwise
Searches scoped to early October return Iranian and Israeli cyber material that is weeks to years old. The commercial threat-intel weekly published on 2 October carried no Middle East item at all.
Black Arrow Cyber’s threat briefing of 2 October 2026 contains no Middle East, Iran, Israel, Gulf or Sahel content in its top stories; its geopolitical section is Russia-focused. The items were Microsoft 365 dormant service accounts, unpatched critical and high-severity flaws older than 90 days, UK cyber-skills confidence, employment scams across 21 countries, and deepfake impersonation of executives. That absence is the most reliable datapoint of the window. What fills the gap instead is an archive. Meta’s takedown of an Iran-linked network using AI personas to impersonate Americans is roughly 37 days old — late August — and is still being reposted by advocacy and aggregation sites without a date in the framing. A separate, earlier Meta and Instagram disruption of an Iranian influence operation dates to around March 2026 and is routinely conflated with it. They are two different actions.
The same pattern runs through the operational material. CISA advisory AA26-097A on Iranian-affiliated actors exploiting programmable logic controllers in U.S. critical infrastructure is a good primary document, but the IC3 PDF is an April artefact. The Times of Israel account of the Israeli cyber chief describing a 2026 surge in Iranian attacks dates to early July. Handala Hack Team’s headline numbers — 350,000 Israeli police files, a claimed breach of a major healthcare network, 50,000-plus files from an Israeli security target — are all from February and March, all claimed by the group, and none independently verified in the reporting examined. Predatory Sparrow’s fuel-station and steel-plant operations are from 2022 and 2023. Wikipedia pages titled “Cyberwarfare during the 2026 Iran war” and “2026 Internet blackout in Iran” rank highly, undated, and are continuously edited.
Assessment: Two things are being substituted for news here. One is the vendor dashboard: a commercial threat-intel firm’s rolling Iran–Israel page, refreshed around 2 October, tops nearly every query on the subject, which is a statement about search-engine incentives rather than about events. The other is the live status page — a blackout tracker updating daily proves the page is alive, not that Iran is degraded. Any shutdown claim needs a measurement from IODA, Cloudflare Radar, NetBlocks or Kentik, quoted as a reading. The honest finding for this window is a negative one, and it is worth more than a manufactured incident. The live thread is legislative, not operational: the internet-restriction bill reported moving in Tehran in early September.