Hidden VMs: how hackers leverage QEMU to stealthily steal data and spread malware

2026-04-19T02:51:47Zaba79cf1f522f7c38aba6969f950480da8be352854ddb6481e599476a49fe973
CVE-2026-34197apache-activemqbluehammercisaciscocookeville-medical-center','zionsiphon','ics-water-systems','cybdata-breachddosdvridentity-servicesiotknown-exploited-vulnerabilitiesmicrosoft-defendermirainexcoriumqemuransomwareredsunrhysidastealth-malwaretp-linkundefendvirtual-machineswebexzero-day

What happened

This feed aggregates multiple active and high-impact cyber incidents: attackers are abusing QEMU to run hidden VMs for stealthy malware, and a Mirai variant “Nexcorium” is exploiting TBK DVRs and EOL TP‑Link routers for large-scale DDoS infections. Three Microsoft Defender zero‑days (BlueHammer, RedSun, UnDefend) are being exploited to gain elevated privileges, with at least two still unpatched. CISA added a critical Apache ActiveMQ flaw (CVE-2026-34197, CVSS 8.8) to its Known Exploited Vulnerabilities catalog; Cisco patched four critical flaws in Identity Services and Webex. Other notable事件s:

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
aba79cf1f522f7c38aba6969f950480da8be352854ddb6481e599476a49fe973
Enrichment time
2026-04-19T02:51:47Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Hidden VMs: how hackers leverage QEMU to stealthily steal data and spread malware · Baitaphish