Don’t just fight fraud, hunt it

2026-04-09T14:51:47Z478b1bb97c5fa567d837a60766d45f3f6eff3d2e68f14f3b36a2fdb7d77bd3d6
APT28BitterCVE-2026-35616Forest BlizzardFortiClient EMSFortinetICSIranian-actorsMENAProSpyRussiaSCADAactively-exploitedcredential-theftenergy-sectorhack-for-hirehotfixjournalistsprompt-injection','grafanaghost'routersspywarestate-backed-espionagetoken-theftwater-sectorzero-day

What happened

A collection of CyberScoop stories (Apr 2026) highlighting a high-risk operating environment: a Russia-linked group (Forest Blizzard/APT28) hijacked ~18,000 devices to steal credentials and tokens; Fortinet FortiClient EMS suffers actively exploited zero-day (CVE-2026-35616) with an immediate hotfix advised while a full patch is pending; a hack-for-hire spyware campaign (suspected Bitter, ProSpy) targeted journalists across the Middle East and North Africa; Iranian-state actors conducted disruptive attacks against U.S. energy and water ICS/SCADA systems; Noma Security disclosed ‘GrafanaGhost’—

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cyberscoop
Record identifier
478b1bb97c5fa567d837a60766d45f3f6eff3d2e68f14f3b36a2fdb7d77bd3d6
Enrichment time
2026-04-09T14:51:47Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Don’t just fight fraud, hunt it · Baitaphish