Hidden VMs: how hackers leverage QEMU to stealthily steal data and spread malware
2026-04-19T02:51:47Z•aba79cf1f522f7c38aba6969f950480da8be352854ddb6481e599476a49fe973
CVE-2026-34197apache-activemqbluehammercisaciscocookeville-medical-center','zionsiphon','ics-water-systems','cybdata-breachddosdvridentity-servicesiotknown-exploited-vulnerabilitiesmicrosoft-defendermirainexcoriumqemuransomwareredsunrhysidastealth-malwaretp-linkundefendvirtual-machineswebexzero-day
What happened
This feed aggregates multiple active and high-impact cyber incidents: attackers are abusing QEMU to run hidden VMs for stealthy malware, and a Mirai variant “Nexcorium” is exploiting TBK DVRs and EOL TP‑Link routers for large-scale DDoS infections. Three Microsoft Defender zero‑days (BlueHammer, RedSun, UnDefend) are being exploited to gain elevated privileges, with at least two still unpatched. CISA added a critical Apache ActiveMQ flaw (CVE-2026-34197, CVSS 8.8) to its Known Exploited Vulnerabilities catalog; Cisco patched four critical flaws in Identity Services and Webex. Other notable事件s:
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- aba79cf1f522f7c38aba6969f950480da8be352854ddb6481e599476a49fe973
- Enrichment time
- 2026-04-19T02:51:47Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.