Operation PowerOFF: 53 DDoS domains seized and 3 Million criminal accounts uncovered
2026-04-17T14:51:47Z•9518a5d3c29a58fd512dd136dd287e6709ef42504f84fa9079103b0bbc764b9e
Apache ActiveMQCISA KEVCVE-2026-33032CVE-2026-34197Cisco patchesDDoS-for-hireICS/OTRhysidaUAC-0247UkraineZionSiphonactive exploitationcritical vulnerabilitiesdata exposureenergy infrastructure attackhealthcare breachlaw enforcementn8n abusenginx-uiphishingransomwarewater sector malware
What happened
Multiple high-impact security events: international law enforcement Operation PowerOFF dismantled 53 DDoS-for-hire domains, arrested four suspects, seized infrastructure and exposed databases containing over 3 million criminal accounts; ZionSiphon is a new politically motivated malware targeting Israeli water treatment/desalination systems (capable of altering pressure and chlorine but currently hampered by a flaw); CISA added a critical Apache ActiveMQ flaw (CVE-2026-34197, CVSS 8.8) to its Known Exploited Vulnerabilities catalog; a separate critical nginx-ui vulnerability (CVE-2026-33032, CV
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- 9518a5d3c29a58fd512dd136dd287e6709ef42504f84fa9079103b0bbc764b9e
- Enrichment time
- 2026-04-17T14:51:47Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.