Russian APT28 Hackers Hijack Routers to Steal Credentials, UK Security Agency Warns
2026-04-07T20:52:26Z•d77d4978c262d74ad3bd559ae39658f05e35282eac32e6c5ffbb2d3305f9aa38
AI prompt injectionAPT28AiTM phishingAkiraDNS hijackingFortiClient EMSFortinetGPU RowhammerGPUBreachGrafanaGhostMedusaPhantom StealerTikTok phishingVenom StealerVenom platformaxios hijack','PyPI compromise','TeamPCP','GitHub C2','CitrixNetcyber-frauddata exfiltrationinfostealernpm compromisephishingransomwarerouter compromisesupply chain attackzero-day
What happened
InfoSecurity Magazine roundup: multiple active campaigns and exploited vulnerabilities were reported including APT28 hijacking home/office routers to operate malicious DNS, a GPU Rowhammer privilege-escalation (GPUBreach), GrafanaGhost AI-prompt-injection data exfiltration, and large-scale phishing/infostealer operations (Venom, Phantom, new Storm infostealer). Vendors and governments warned or patched urgent flaws — Fortinet issued an emergency FortiClient EMS patch, the NCSC urged immediate patching of F5 BIG-IP (CVE-2025-53521), and researchers observed active exploitation of a critical Cit
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- infosecurity_magazine
- Record identifier
- d77d4978c262d74ad3bd559ae39658f05e35282eac32e6c5ffbb2d3305f9aa38
- Enrichment time
- 2026-04-07T20:52:26Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.