Security Affairs newsletter Round 572 by Pierluigi Paganini – INTERNATIONAL EDITION
2026-04-12T08:51:48Z•c4b8ae840d5fbc698b75b7c1db026c21d2746716eb27e583758a6d362bd50cef
Adobe ReaderAndroid data exposureBitcoin DepotCensysChipSoftEHR outageEngageLab SDKEurail data breachGlassWormIranian APTLucidRookMarimoOT/ICSRCERockwell PLCUAT-10362Zig droppercrypto walletscryptocurrency theftdeveloper toolsmalicious PDFphishingransomwaresupply chainzero-day
What happened
This feed aggregates multiple high-impact incidents: Censys discovered 5,219 internet-exposed Rockwell PLCs (majority in the U.S.) amid warnings that Iran-linked APTs are actively targeting internet-connected OT/ICS. The GlassWorm campaign evolved to use a Zig-based dropper hidden in fake IDE extensions to infect developer tooling and deliver RATs. A critical Marimo RCE (CVE-2026-39987, CVSS 9.3) was exploited within hours of disclosure. Other notable events include a ransomware outage at Dutch EHR vendor ChipSoft, an EngageLab SDK flaw exposing private data on up to 50M Android installs (incl
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- c4b8ae840d5fbc698b75b7c1db026c21d2746716eb27e583758a6d362bd50cef
- Enrichment time
- 2026-04-12T08:51:48Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.