Security Affairs newsletter Round 572 by Pierluigi Paganini – INTERNATIONAL EDITION

2026-04-12T08:51:48Zc4b8ae840d5fbc698b75b7c1db026c21d2746716eb27e583758a6d362bd50cef
Adobe ReaderAndroid data exposureBitcoin DepotCensysChipSoftEHR outageEngageLab SDKEurail data breachGlassWormIranian APTLucidRookMarimoOT/ICSRCERockwell PLCUAT-10362Zig droppercrypto walletscryptocurrency theftdeveloper toolsmalicious PDFphishingransomwaresupply chainzero-day

What happened

This feed aggregates multiple high-impact incidents: Censys discovered 5,219 internet-exposed Rockwell PLCs (majority in the U.S.) amid warnings that Iran-linked APTs are actively targeting internet-connected OT/ICS. The GlassWorm campaign evolved to use a Zig-based dropper hidden in fake IDE extensions to infect developer tooling and deliver RATs. A critical Marimo RCE (CVE-2026-39987, CVSS 9.3) was exploited within hours of disclosure. Other notable events include a ransomware outage at Dutch EHR vendor ChipSoft, an EngageLab SDK flaw exposing private data on up to 50M Android installs (incl

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
c4b8ae840d5fbc698b75b7c1db026c21d2746716eb27e583758a6d362bd50cef
Enrichment time
2026-04-12T08:51:48Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.