Censys finds 5,219 devices exposed to attacks by Iranian APTs, majority in U.S.
2026-04-11T20:51:47Z•df0bedd9c9e07af408051436c06df8ff4776edaedf790c5fa124233f700238cf
AndroidBitcoin Depot breachCVE-2026-39987ChipSoftEHREngageSDKGlassWormICSIDE extensionIranian APTsLucidRookMarimoOTRCERockwell PLCUAT-10362Zig droppercrypto walletsdata exposuredeveloper toolshealthcaremobilephishingransomwaresupply chain
What happened
Multiple high-impact incidents and vulnerabilities were reported: Censys found 5,219 internet-exposed Rockwell PLCs (majority in the U.S.) that Iran-linked APTs are exploiting against OT/critical infrastructure; GlassWorm evolved to use a Zig-based dropper hidden in fake IDE extensions to compromise developer toolchains; Marimo (CVE-2026-39987, CVSS 9.3) was exploited within hours of disclosure enabling RCE; a critical EngageLab/EngageSDK flaw exposed up to ~50M Android devices (including ~30M crypto wallet installs) allowing sandbox bypass; an Adobe Reader zero-day PDF exploit is active in‑‑‑
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- df0bedd9c9e07af408051436c06df8ff4776edaedf790c5fa124233f700238cf
- Enrichment time
- 2026-04-11T20:51:47Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.