Thousands of consumer routers hacked by Russia's military

2026-04-08T20:51:51Z617b6c0b7e3f960d08614a043c7a5461eb7c03d29e88866bc1f723ff1e4ca297
AI-agent compromise','credential-theftDarkSwordGPU rowhammerIoTIranKVM vulnerabilitiesNVIDIAOpenClawRowhammerRussiaStryker incidentTrivyconsumer routerscredential theftiOS zero-dayiPhone exploitinvisible-unicodemalwarenation-stateopen-source poisoningresilient botnetrouter compromisesoftware supply chainsupply-chain attackwiper

What happened

A collection of Ars Technica security stories (Mar–Apr 2026) detailing multiple high-impact incidents: Russia's military compromising thousands of end-of-life consumer routers to harvest credentials; mass router infections and resilient malware campaigns (including a separate 14,000-device outbreak); supply-chain compromises (Trivy scanner, invisible Unicode attack, tampered open-source packages); prolific nation-state activity from Iran and Russia (campaigns against US/Israel, iPhone zero-day DarkSword in the wild); GPU Rowhammer variants (GDDRHammer, GeForge, GPUBreach) enabling CPU takeover

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
arstechnica_security
Record identifier
617b6c0b7e3f960d08614a043c7a5461eb7c03d29e88866bc1f723ff1e4ca297
Enrichment time
2026-04-08T20:51:51Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.