APT37 hackers use new malware to breach air-gapped networks
2026-03-04T20:03:13Z•25d534f0b25047df2c62aaae4e0b352375f0304399e557551bdcf74b6a065f8c
CVE-2025-0282APT37CISAEuropol Project CompassGemini AIGoogle API keysIvanti Connect SecureJuniper PTXJunos OS EvolvedOnlyFake (AI fake IDs)RCERESURGETrend Micro Apex Oneair-gapped malwaredata breachdeveloper supply-chain attackransomware trendsremovable mediasupply-chain/third-party patchingzero-day
What happened
A diverse set of cyber incidents and vulnerabilities was reported: North Korea-linked APT37 deployed new removable-drive malware to bridge internet-connected and air‑gapped systems; CISA detailed RESURGE, an implant tied to zero‑day exploitation of Ivanti Connect Secure (CVE-2025-0282) that can remain dormant; Trend Micro patched critical Apex One RCE flaws; Juniper PTX (Junos OS Evolved) has a critical unauthenticated remote root takeover vulnerability; and Google API keys embedded in client code can expose private Gemini AI data. Law‑enforcement and abuse updates include a Europol operation,
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 25d534f0b25047df2c62aaae4e0b352375f0304399e557551bdcf74b6a065f8c
- Enrichment time
- 2026-03-04T20:03:13Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.