Microsoft suspends dev accounts for high-profile open source projects
2026-04-09T07:23:34Z•cf68e2465e8e566a235e6d2819c05acdb16da21c31326447c46f10eb5fd1476b
ActiveMQAtomic StealerBPO-compromiseCISACVE-2025-59528ClickFixDNS-hijackFlowiseFrostArmadaIvantiMagentoMikroTikNinja FormsSVGSnowflake-data-theft','SaaS-integrator','PLCs','industrial-ics',TP-LinkUNC6783WordPresscredit-card-theftexploitedmacOSpayment-skimmerremote-code-executionroutersvulnerability
What happened
A batch of active threats and high-impact security incidents was reported: a maximum-severity Flowise RCE (CVE-2025-59528) is being exploited in the wild, and CISA has ordered federal patching for a widely exploited critical Ivanti EPMM flaw. Attackers are also exploiting a critical Ninja Forms File Uploads add-on for WordPress to achieve RCE, and researchers disclosed a 13-year-old RCE in Apache ActiveMQ Classic. Multiple campaigns and compromises were highlighted: a pixel-sized SVG skimmer is stealing credit cards from Magento stores, UNC6783 is compromising BPO providers to exfiltrate Zend‑
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- cf68e2465e8e566a235e6d2819c05acdb16da21c31326447c46f10eb5fd1476b
- Enrichment time
- 2026-04-09T07:23:34Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.