:

IRAN-LINKED HACKERS TARGET SOUTH KOREAN TECH FIRM

SECURITY DESK1 MIN READ
WED, MAY 13, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

The MuddyWater hacking group, linked to Iran, launched a cyber-espionage campaign against a major South Korean electronics maker alongside eight other high-profile organizations across multiple sectors and countries.

MuddyWater, also known as Seedworm and Static Kitten, conducted a broad attack targeting at least nine organizations globally. The Iran-affiliated group is known for espionage operations focused on collecting sensitive information from government and private sector entities. The campaign represents a significant escalation in cyber-espionage activities targeting South Korean tech companies, which are frequent targets due to their access to advanced technologies and intellectual property. The attack underscores growing concerns about state-sponsored hacking operations in the region. Details on compromised systems, stolen data, or the specific nature of the electronics maker's breach remain limited. The targeted organization has not yet issued a public statement regarding the incident. MuddyWater has maintained an active presence in cyber-espionage since at least 2017, targeting organizations across energy, telecommunications, and government sectors. Security researchers have tracked the group's evolving tactics and infrastructure over the past six years.

■ SOURCES

Bleeping Computer

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

Britain's communications regulator has issued its largest Online Safety Act fine to date—£950,000 ($1.28 million)—against an unnamed suicide forum for hosting illegal content accessible in the UK. The platform is linked to over 130 deaths.

JUST NOWIndustry Desk

The Department of Homeland Security will run an experimental program this fall deploying autonomous drones and ground vehicles along the US-Canada border. The system will transmit reconnaissance data over 5G networks as part of a bilateral initiative.

JUST NOWAI Desk

West Pharmaceutical Services disclosed a cyberattack involving data theft and system encryption. The incident affects the drug delivery and medical device manufacturer.

JUST NOWSecurity Desk

A critical vulnerability in the Exim mail transfer agent enables unauthenticated remote attackers to execute arbitrary code on affected systems. The flaw impacts certain Exim configurations and poses significant risk to mail infrastructure worldwide.

2H AGOAI Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.