SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 93
2026-04-19T14:51:50Z•397b790f6b2ad30ede1f6a8cf57a66284cbe681e727cd87101e7b54ff6adfbe8
Apache ActiveMQBlueHammerCISACVE-2026-34197DDoSDDoS-for-hire','credential-stuffing','DraftKings','law-enforcemeGrinexIoTKnown-Exploited-VulnerabilitiesMicrosoft DefenderMiraiNexcoriumOperation PowerOFFQEMURedSunTBK DVRTP-LinkUnDefendZionSiphoncrypto-heistindustrial-control-systemsmalwarevirtual-machine-evasionwater-sectorzero-day
What happened
Feed of Security Affairs headlines: researchers report attackers abusing QEMU to hide malware inside virtual machines for stealthy data theft and ransomware deployment; a Nexcorium Mirai variant is exploiting a TBK DVR flaw (and outdated TP‑Link routers) to build DDoS botnets; three Microsoft Defender zero‑days (BlueHammer, RedSun, UnDefend) are being exploited with at least two still unpatched; ZionSiphon is a politically motivated malware targeting Israeli water systems (attempting to alter pressure/chlorine); CISA added Apache ActiveMQ CVE-2026-34197 (CVSS 8.8) to its Known Exploited Vulner
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- 397b790f6b2ad30ede1f6a8cf57a66284cbe681e727cd87101e7b54ff6adfbe8
- Enrichment time
- 2026-04-19T14:51:50Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.