APT37 hackers use new malware to breach air-gapped networks

2026-03-04T20:03:13Z25d534f0b25047df2c62aaae4e0b352375f0304399e557551bdcf74b6a065f8c
CVE-2025-0282APT37CISAEuropol Project CompassGemini AIGoogle API keysIvanti Connect SecureJuniper PTXJunos OS EvolvedOnlyFake (AI fake IDs)RCERESURGETrend Micro Apex Oneair-gapped malwaredata breachdeveloper supply-chain attackransomware trendsremovable mediasupply-chain/third-party patchingzero-day

What happened

A diverse set of cyber incidents and vulnerabilities was reported: North Korea-linked APT37 deployed new removable-drive malware to bridge internet-connected and air‑gapped systems; CISA detailed RESURGE, an implant tied to zero‑day exploitation of Ivanti Connect Secure (CVE-2025-0282) that can remain dormant; Trend Micro patched critical Apex One RCE flaws; Juniper PTX (Junos OS Evolved) has a critical unauthenticated remote root takeover vulnerability; and Google API keys embedded in client code can expose private Gemini AI data. Law‑enforcement and abuse updates include a Europol operation,

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
25d534f0b25047df2c62aaae4e0b352375f0304399e557551bdcf74b6a065f8c
Enrichment time
2026-03-04T20:03:13Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.