CVE-2023-33538 under attack for a year, but exploitation still unsuccessful
2026-04-20T14:51:47Z•2b0b24f618b89368da9e66edb8de9fb21c6dae4114261f2d88836eff353423ee
AI-exploit-generationBlueHammerCVE-2023-33538Chrome exploitClaude OpusContext.aiGrinexIoTMicrosoft DefenderMiraiNexcoriumQEMURedSunTBK DVRTP-LinkUnDefendVercelcargo-theftcrypto-theftdata-breachhidden-VMslogisticssupply-chainthird-party-riskzero-day
What happened
Multiple high-impact security developments: attackers have been probing CVE-2023-33538 in outdated TP-Link routers for over a year without confirmed successful exploitation; a third‑party AI tool (Context.ai) compromise led to a Vercel breach via a hijacked employee Google Workspace account; an AI service (Claude Opus) was demonstrated to produce a working Chrome exploit at low cost, highlighting accelerating weaponization of LLMs. Other notable items include a Mirai variant (Nexcorium) exploiting TBK DVRs and end‑of‑life TP‑Link routers for DDoS botnets, Sophos findings of attackers hiding in
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- 2b0b24f618b89368da9e66edb8de9fb21c6dae4114261f2d88836eff353423ee
- Enrichment time
- 2026-04-20T14:51:47Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.