Russia's 'Fancy Bear' APT Continues Its Global Onslaught
2026-04-10T02:51:47Z•74bf6c4843e9f328342997e55e59265241e14b7236792d2036b10c2babfdf2c3
AI-securityAPTAPT28BlueHammerCVE-2026-35616Fancy BearFortinetGenAIHackerOneMaaSMedusaOT/ICSPLC compromiseReact2ShellSOHO routerscredential-harvestingransomwaresocial-engineeringsupply-chainzero-day
What happened
DarkReading roundup highlights a surge in active, diverse threats: nation-state APT activity (Fancy Bear/APT28 using SOHO router DNS manipulation), Iranian actors disrupting OT via exposed PLCs, and fast-moving ransomware campaigns (Storm-1175/Medusa) exploiting n-day and zero-day flaws. Multiple zero-days and PoCs surfaced (FortiClient emergency patch CVE-2026-35616; a BlueHammer Windows local takeover PoC), alongside automated credential-harvesting (React2Shell exploitation), AI-related supply-chain and data-leak risks (Grafana GenAI issue, AI-assisted GitHub attacks, Claude source leak), as
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- darkreading
- Record identifier
- 74bf6c4843e9f328342997e55e59265241e14b7236792d2036b10c2babfdf2c3
- Enrichment time
- 2026-04-10T02:51:47Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.