6-Year Ransomware Campaign Targets Turkish Homes & SMBs
2026-04-16T14:51:44Z•19f47deb97d1afcc2181c4c9cf2ccfd4cd9ed0558db0c54f0bdc52fa475e8ec5
adobe-acrobat-zero-dayai-securityapt28apt41bluehammerbyovdcloud-credentialsedr-killergithub-prt-scanmcp-integration-flawmedusamicrosoft-copilotnginxnginx-uinpm-axiosot-plc-exploitationpost-quantum-riskprivilege-escalationprompt-injectionransomwaresalesforce-agentforcesoho-router-compromisestorm-1175supply-chain-attackwindows-zero-day
What happened
The DarkReading roundup highlights multiple high-impact active threats and widespread systemic risks: long-running ransomware and high-velocity Medusa campaigns exploiting n-/zero-day flaws; a near-maximum-severity MCP integration flaw in nginx-ui that allows remote manipulation of NGINX configs; an actively exploited Adobe Acrobat/Reader zero-day (malicious PDFs); and a Windows local-privilege zero-day/PoC (BlueHammer). Nation-state and organized groups (APT41, APT28/Fancy Bear) are harvesting cloud credentials and abusing SOHO router DNS changes, while Iranian actors have disrupted OT via un
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- darkreading
- Record identifier
- 19f47deb97d1afcc2181c4c9cf2ccfd4cd9ed0558db0c54f0bdc52fa475e8ec5
- Enrichment time
- 2026-04-16T14:51:44Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.