Lotus Wiper Attack Targets Venezuelan Energy Firms, Utilities
2026-04-29T14:51:56Z•f83b412225101544b057c1c309f96c8af7d503b640a6090f64e8a3432af69f72
CVE-2026-1731RCEagentic AIai phishingblue noroffbomgarbotnetschina aptglasswormgoogle antigravityinfostealerlazaruslotus wipernorth koreaphantomrpcprivilege escalationransomwareremote code executionsapphire sleetsupply chainvidarvs code extensionswindows rpcwiperzoom phishing/fake calls/clickfix','windows defender exploits','
What happened
A DarkReading roundup highlighting a broad surge in high-impact attacks and exploitable flaws: destructive Lotus Wiper operations against Venezuelan energy firms; North Korean groups (BlueNoroff, Lazarus/Sapphire Sleet) using AI-generated avatars, fake Zoom/ClickFix lures and macOS-focused theft; supply-chain campaigns via malicious VS Code extensions (GlassWorm); the Vidar infostealer rising amid market churn; and multiple critical/unpatched vulnerabilities enabling privilege escalation or remote code execution. Notable technical risks include active exploitation of a critical Bomgar RMM RCE,
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- darkreading
- Record identifier
- f83b412225101544b057c1c309f96c8af7d503b640a6090f64e8a3432af69f72
- Enrichment time
- 2026-04-29T14:51:56Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.