CPUID watering hole attack spreads STX RAT malware
2026-04-13T08:51:45Z•c0762b332bb650f09498b563238b47934fec7281dd190228ecbddd89d367384b
Adobe Acrobat ReaderCVE-2026-34621CVE-2026-39987CensysChipSoftEHRGlassWormICSLucidRookMarimoOTRockwell PLCSTX RATactive exploitationmalwareoperational technologyransomwaresupply chainthreat actorswatering hole
What happened
A batch of active cyber incidents and disclosures: threat actors conducted a watering‑hole compromise of the CPUID site to distribute STX RAT via fake CPU‑Z/HWMonitor installers; Adobe released emergency patches for an actively exploited Acrobat Reader vulnerability (CVE‑2026‑34621); Marimo notebook RCE (CVE‑2026‑39987) was exploited within hours of disclosure; attackers claimed control of Venice San Marco flood pumps while Censys found 5,219 internet‑exposed Rockwell PLCs at risk; Dutch EHR vendor ChipSoft suffered a disruptive ransomware attack; and supply‑chain/malware campaigns continue to
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- c0762b332bb650f09498b563238b47934fec7281dd190228ecbddd89d367384b
- Enrichment time
- 2026-04-13T08:51:45Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.