Russia-linked APT28 uses PRISMEX to infiltrate Ukraine and allied infrastructure with advanced tactics
2026-04-08T20:51:41Z•e7d2638e248e77f7bc3bb3bf3011e434990de53725bd36258500b7a3d09aecb1
AI securityAPT28BlueHammerCVE-2025-59528CVE-2026-35616Claude MythosFlowiseFortinetGPU RowHammerGPUBreachKnown Exploited VulnerabilityMedusa ransomwarePLC targetingPRISMEXProject GlasswingRussian banking outageSignature HealthcareStorm-1175Windows zero-daycritical infrastructurehealthcare attackoutageransomwarespear-phishingsteganography
What happened
Multiple high-risk cyber incidents and disclosures reported: Russia-linked APT28 (aka Fancy Bear) is running a spear-phishing campaign against Ukraine and allied infrastructure deploying a new malware suite named PRISMEX with advanced stealth (steganography) for espionage and C2. Active exploitation of a critical Flowise remote code execution vulnerability (CVE-2025-59528, CVSS 10) is observed; CISA added a Fortinet FortiClient EMS flaw (CVE-2026-35616, CVSS 9.1) to its KEV catalog and out-of-band patches were issued. Other notable events include Iran-linked actors targeting internet-exposed/
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- e7d2638e248e77f7bc3bb3bf3011e434990de53725bd36258500b7a3d09aecb1
- Enrichment time
- 2026-04-08T20:51:41Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.