CPUID watering hole attack spreads STX RAT malware

2026-04-13T08:51:45Zc0762b332bb650f09498b563238b47934fec7281dd190228ecbddd89d367384b
Adobe Acrobat ReaderCVE-2026-34621CVE-2026-39987CensysChipSoftEHRGlassWormICSLucidRookMarimoOTRockwell PLCSTX RATactive exploitationmalwareoperational technologyransomwaresupply chainthreat actorswatering hole

What happened

A batch of active cyber incidents and disclosures: threat actors conducted a watering‑hole compromise of the CPUID site to distribute STX RAT via fake CPU‑Z/HWMonitor installers; Adobe released emergency patches for an actively exploited Acrobat Reader vulnerability (CVE‑2026‑34621); Marimo notebook RCE (CVE‑2026‑39987) was exploited within hours of disclosure; attackers claimed control of Venice San Marco flood pumps while Censys found 5,219 internet‑exposed Rockwell PLCs at risk; Dutch EHR vendor ChipSoft suffered a disruptive ransomware attack; and supply‑chain/malware campaigns continue to

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
c0762b332bb650f09498b563238b47934fec7281dd190228ecbddd89d367384b
Enrichment time
2026-04-13T08:51:45Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · CPUID watering hole attack spreads STX RAT malware · Baitaphish