wolfSSL Vulnerability Hits IoT, Routers and Military Systems, Update to 5.9.1 Now
2026-04-14T20:51:47Z•6c8e009f337884a2e54ec0726fd562bfde0adea1bf1dcaa850cdef9fcfc9e08d
AxiosBITTER-APTBooking.comCVE-2026-5194DragonForceIoTKrakenOpenAIOpenSSFProSpySlack-malware-impersonationToSpyViperTunnelbackdoorcertificate-rotationdata-breachinsider-threatmessaging-luresmilitary-systemspatch-availabilityphishing-riskransomwarerouterssupply-chainwolfSSL
What happened
Multiple security incidents reported: a critical wolfSSL vulnerability (CVE-2026-5194) allows digital ID forgery across billions of devices (IoT, routers, some military systems) — vendors and users should update to wolfSSL 5.9.1 immediately. Other notable items: Kraken faces an extortion incident after an insider recorded system footage (~2,000 accounts impacted, no funds/systems breached); Booking.com confirms a customer-data breach (no payment data exposed but increased phishing risk); ViperTunnel, a Python backdoor linked to DragonForce ransomware, is targeting Windows servers in the US and
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- hackread
- Record identifier
- 6c8e009f337884a2e54ec0726fd562bfde0adea1bf1dcaa850cdef9fcfc9e08d
- Enrichment time
- 2026-04-14T20:51:47Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.