Critical flaw in Protobuf library enables JavaScript code execution

2026-04-19T07:23:26Z101b30053041989c680dc6a409a38ffb94d47b129f78a79001a89c480e6918bc
Apache ActiveMQCISADDoSGrinexHuggingFaceJavaScriptMarimoMicrosoft DefenderNAKIVONKAbuseOperation PowerOFFPayouts KingPoCProtocol BuffersQEMURedSunWindows zero-dayZionSiphonbackup and replicationcryptocurrency exchangeoperational technologyprotobuf.jsransomwareremote code executionwater treatment

What happened

Recent BleepingComputer reports cover multiple high‑risk security developments: a critical remote code execution flaw in protobuf.js with public proof‑of‑concept allowing JavaScript code execution; active exploitation of a high‑severity Apache ActiveMQ vulnerability flagged by CISA; several recently leaked Windows zero‑days and a public PoC for a Microsoft Defender “RedSun” zero‑day granting SYSTEM; and an exploited Marimo notebook flaw used to deploy NKAbuse malware from Hugging Face. Other notable items include Payouts King ransomware using hidden QEMU VMs to evade endpoint security, ZionSih

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
101b30053041989c680dc6a409a38ffb94d47b129f78a79001a89c480e6918bc
Enrichment time
2026-04-19T07:23:26Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.