Russia's 'Fancy Bear' APT Continues Its Global Onslaught

2026-04-10T02:51:47Z74bf6c4843e9f328342997e55e59265241e14b7236792d2036b10c2babfdf2c3
AI-securityAPTAPT28BlueHammerCVE-2026-35616Fancy BearFortinetGenAIHackerOneMaaSMedusaOT/ICSPLC compromiseReact2ShellSOHO routerscredential-harvestingransomwaresocial-engineeringsupply-chainzero-day

What happened

DarkReading roundup highlights a surge in active, diverse threats: nation-state APT activity (Fancy Bear/APT28 using SOHO router DNS manipulation), Iranian actors disrupting OT via exposed PLCs, and fast-moving ransomware campaigns (Storm-1175/Medusa) exploiting n-day and zero-day flaws. Multiple zero-days and PoCs surfaced (FortiClient emergency patch CVE-2026-35616; a BlueHammer Windows local takeover PoC), alongside automated credential-harvesting (React2Shell exploitation), AI-related supply-chain and data-leak risks (Grafana GenAI issue, AI-assisted GitHub attacks, Claude source leak), as

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
darkreading
Record identifier
74bf6c4843e9f328342997e55e59265241e14b7236792d2036b10c2babfdf2c3
Enrichment time
2026-04-10T02:51:47Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.