Critical flaw in Protobuf library enables JavaScript code execution

2026-04-18T19:23:32Zdd7631207f72c6aca1537750a61d90648a5afae93b2e5281772d91e44d8fadf3
apache-activemqcisacriticalcrypto-heistgrinexjavascriptmarimomicrosoft-defendernkabuseoperational-technologypayouts-kingproof-of-conceptprotobuf.jsqemuransomwarerceredsunzero-dayzionsiphon

What happened

Multiple high-impact security stories: a critical remote code execution vulnerability in protobuf.js has a published proof-of-concept enabling JavaScript code execution; CISA warns of active exploitation of a high-severity Apache ActiveMQ flaw; several recently leaked Windows zero-days and a Microsoft Defender zero-day ("RedSun") PoC are being abused for privilege escalation; Marimo notebooks are being exploited to deliver NKAbuse malware from Hugging Face; Payouts King ransomware uses QEMU VMs to evade endpoint defenses; and ZionSiphon malware targets water-treatment OT environments. The feed

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
dd7631207f72c6aca1537750a61d90648a5afae93b2e5281772d91e44d8fadf3
Enrichment time
2026-04-18T19:23:32Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.