Cyber attacks fuel surge in cargo theft across logistics industry

2026-04-19T20:51:48Z9d84ba9d01c86001801fb2107a8633f25db275a34c82f0b81e55f521a48593c2
bluehammercargo-theftcredential-stuffing (draftkings)critical-infrastructurecryptocurrency-heistddosiot-botnetjanelaRATlogisticsmicrosoft-defendermirainexcoriumorganized-crimepayment-diversionqemuredsunremote-access-trojansandbox-evasiontbk-dvrtp-linkundefendvm-evasionwater-icszero-dayzion­siphon

What happened

This feed aggregates multiple active threats and trends: coordinated cyberattacks on logistics firms to steal cargo and divert payments (linked to organized crime); attackers abusing QEMU VMs to hide malware and evade detection; an IoT-focused Mirai variant “Nexcorium” exploiting TBK DVRs and EOL TP‑Link routers for DDoS; three Microsoft Defender zero‑days (BlueHammer, RedSun, UnDefend) being exploited with at least two still unpatched; a $13.7M theft from Kyrgyz exchange Grinex; politically‑motivated ZionSiphon malware targeting Israeli water systems/ICS; law‑enforcement takedown Operation “P

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
9d84ba9d01c86001801fb2107a8633f25db275a34c82f0b81e55f521a48593c2
Enrichment time
2026-04-19T20:51:48Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.