6-Year Ransomware Campaign Targets Turkish Homes & SMBs

2026-04-16T14:51:44Z19f47deb97d1afcc2181c4c9cf2ccfd4cd9ed0558db0c54f0bdc52fa475e8ec5
adobe-acrobat-zero-dayai-securityapt28apt41bluehammerbyovdcloud-credentialsedr-killergithub-prt-scanmcp-integration-flawmedusamicrosoft-copilotnginxnginx-uinpm-axiosot-plc-exploitationpost-quantum-riskprivilege-escalationprompt-injectionransomwaresalesforce-agentforcesoho-router-compromisestorm-1175supply-chain-attackwindows-zero-day

What happened

The DarkReading roundup highlights multiple high-impact active threats and widespread systemic risks: long-running ransomware and high-velocity Medusa campaigns exploiting n-/zero-day flaws; a near-maximum-severity MCP integration flaw in nginx-ui that allows remote manipulation of NGINX configs; an actively exploited Adobe Acrobat/Reader zero-day (malicious PDFs); and a Windows local-privilege zero-day/PoC (BlueHammer). Nation-state and organized groups (APT41, APT28/Fancy Bear) are harvesting cloud credentials and abusing SOHO router DNS changes, while Iranian actors have disrupted OT via un

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
darkreading
Record identifier
19f47deb97d1afcc2181c4c9cf2ccfd4cd9ed0558db0c54f0bdc52fa475e8ec5
Enrichment time
2026-04-16T14:51:44Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.