SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 93

2026-04-19T14:51:50Z397b790f6b2ad30ede1f6a8cf57a66284cbe681e727cd87101e7b54ff6adfbe8
Apache ActiveMQBlueHammerCISACVE-2026-34197DDoSDDoS-for-hire','credential-stuffing','DraftKings','law-enforcemeGrinexIoTKnown-Exploited-VulnerabilitiesMicrosoft DefenderMiraiNexcoriumOperation PowerOFFQEMURedSunTBK DVRTP-LinkUnDefendZionSiphoncrypto-heistindustrial-control-systemsmalwarevirtual-machine-evasionwater-sectorzero-day

What happened

Feed of Security Affairs headlines: researchers report attackers abusing QEMU to hide malware inside virtual machines for stealthy data theft and ransomware deployment; a Nexcorium Mirai variant is exploiting a TBK DVR flaw (and outdated TP‑Link routers) to build DDoS botnets; three Microsoft Defender zero‑days (BlueHammer, RedSun, UnDefend) are being exploited with at least two still unpatched; ZionSiphon is a politically motivated malware targeting Israeli water systems (attempting to alter pressure/chlorine); CISA added Apache ActiveMQ CVE-2026-34197 (CVSS 8.8) to its Known Exploited Vulner

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
397b790f6b2ad30ede1f6a8cf57a66284cbe681e727cd87101e7b54ff6adfbe8
Enrichment time
2026-04-19T14:51:50Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 93 · Baitaphish