Firewall integrations

Fortinet

Elevate the power of your Fortinet Fortigate Firewall using by adding our Intelligence.

Palo Alto

Palo Alto Firewalls can be hardened with our threat intelligence as well.

Sophos XGS

Enhance the Sophos XGS Firewall with our threat intelligence.

OPNsense

Enhance your OPNsense Firewall with our threat intelligence using the native plugin.

SIEM integrations

Splunk

Splunk is a great platform, but without the right Threat Intelligence it's just a log server. Try our threat intelligence today. 

Microsoft Sentinel

One of the most used SIEM solutions should be enriched with the right Intelligence. At Q-Feeds you're at the right place!

Other

Luckily there are many other SIEM vendors whom support 3rd party threat intelligence.

Threat Intelligence Portal

Darkweb Monitoring

Darkweb monitoring is one of our services, not only for threat intelligence but also for you most important assets.

Threat Lookup

With Threat Lookup you get full insights in our IOC database, including full MITRE ATT&K mapping.

External Attack Surface Management

A toolset to check your external facing assets exposed on the internet

Vulnerability Scanner

A comprehensive vulnerability scanner which can scan your infrastructure and web applications

Brand Protection

Protect your brand for look-a-likes and potential phishing attempts

Services

TAXII Feeds & Server Software

TAXII/STIX2.1 standard. Both in form of feeds and server software available

Implementation

Need help with implementations? No worries, we have a strong network of partners who are able to help you.

Solutions

Enrich my SIEM

Elevate the power of your SIEM solution using by adding our Intelligence.

Enrich my Firewall

Firewalls can be hardened with our threat intelligence as well.

Prevent phishing

Enhance your protection against phishing

Achieve compliancy

Achieve compliancy by correlating the best threat intelligence to your logs

Futuristic eye design with circuits and geometric shapes.

Company

About

Read here all about Q-Feeds

News and Updates

Cybersecurity news and updates about us

Publications

All of our media coverage in one place

Become a reseller

Strengthen your portfolio with our comprehensive reseller program

Partner locator

Find our certified partners here

Contact

For all your questions or inquiries

Neural network representation of a human brain

Support

My Account

Access your account and manage your licenses

Downloads & Manuals

On this page you find white papers and manuals

Knowledge base

Our knowledge base full of implementation instructions

Start for free

Start your cyber security intelligence journey here

Abstract geometric wireframe human head

Stay vigilant: Key cybersecurity threats to monitor

Mar 13, 2026 | Threat Intelligence Research

Iranian Cyber Operations Escalate Amid Regional Conflict

TL;DR
The onset of the recent conflict in Iran has led to escalated cyber threats, particularly from Iranian-aligned groups targeting various sectors. Organizations with ties to the Middle East or cloud services are especially at risk as these attacks leverage complex cyber tactics.

Main Analysis
The recent military conflict in Iran has catalyzed a notable increase in cyber activity, particularly from Iranian-affiliated groups. Research from Palo Alto Networks’ Unit 42 highlights the immediate mobilization of over 60 pro-Iranian hacktivist groups following the U.S.-Israel operations on February 28. This surge was quickly met with warnings from cybersecurity agencies in both the United Kingdom and Canada regarding heightened threat levels. The first substantive attack involved Iranian drones targeting AWS data centers in the United Arab Emirates and Bahrain, disrupting cloud infrastructure and financial applications.

This escalation exemplifies how cyber actors often capitalize on kinetic conflicts. The article notes that initial surge activities often come from hacktivist groups, followed closely by advanced persistent threat (APT) operations. These APTs typically focus on reconnaissance and maintaining initial access to targets, emphasizing a diverse threat landscape that includes espionage, disruption, and sabotage. For defenders, the operations appear increasingly sophisticated, shifting from disruptive tactics to more stealthy approaches that leverage legitimate remote management tools, complicating detection efforts.

Amid these developments, there are critical implications for organizations, particularly those with supply chains in or relationships with Middle Eastern entities. Iranian state-aligned groups have shown a propensity for targeting infrastructure within sectors such as engineering and manufacturing. Furthermore, their tactics remain a blend of hacktivist noise and state-sponsored operations, a phenomenon termed “faketivism.” Such activities highlight the pervasive risk of collateral damage that can impact organizations worldwide, reinforcing the need for vigilance across various sectors.

Defensive Context
Organizations reliant on internet-facing services, especially cloud providers, need to prioritize security as the nature of these threats underscores vulnerabilities that serve as gateways for attackers. Companies in engineering or reliant on supply chains connected to the Middle East should be particularly attentive to their security postures.

Why This Matters
The ongoing conflict increases the exposure of critical infrastructure and supply chains to cyberattacks. Organizations connected to the region may find themselves at higher risk, as various Iranian-aligned groups target entities that appear remotely linked to the conflict.

Defender Considerations
Specifically highlighted actions include auditing and securing all internet-facing services and remote access. Organizations should review their third-party dependencies, particularly concerning managed service providers, to identify potential vulnerabilities indicative of the evolving threat landscape. Given recent trends, the likelihood of supply chain compromises should also influence security strategies.

Indicators of Compromise (IOCs)
No concrete IOCs such as IP addresses, domains, or file hashes were specified in the provided article.

Click here for the full article

Try our Intelligence today!

Streamline your security operations with a free Q-Feeds trial and see the difference.

Other articles