Critical flaw in Protobuf library enables JavaScript code execution
2026-04-18T19:23:32Z•dd7631207f72c6aca1537750a61d90648a5afae93b2e5281772d91e44d8fadf3
apache-activemqcisacriticalcrypto-heistgrinexjavascriptmarimomicrosoft-defendernkabuseoperational-technologypayouts-kingproof-of-conceptprotobuf.jsqemuransomwarerceredsunzero-dayzionsiphon
What happened
Multiple high-impact security stories: a critical remote code execution vulnerability in protobuf.js has a published proof-of-concept enabling JavaScript code execution; CISA warns of active exploitation of a high-severity Apache ActiveMQ flaw; several recently leaked Windows zero-days and a Microsoft Defender zero-day ("RedSun") PoC are being abused for privilege escalation; Marimo notebooks are being exploited to deliver NKAbuse malware from Hugging Face; Payouts King ransomware uses QEMU VMs to evade endpoint defenses; and ZionSiphon malware targets water-treatment OT environments. The feed
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- dd7631207f72c6aca1537750a61d90648a5afae93b2e5281772d91e44d8fadf3
- Enrichment time
- 2026-04-18T19:23:32Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.