Major outage cripples Russian banking apps and metro payments nationwide
2026-04-07T14:51:54Z•ed0379582f277ee9869f46d60b05ce081507adf6c2482ec5a90cdc2f8fd211c4
BlueHammerCISA KEVCVE-2025-53521CVE-2026-35616DPRKF5 BIG-IPFortiClient EMSFortinetGPU RowHammerGPUBreachGitHub C2MedusaREvilRussian banking outageStorm-1175Windows zero-dayactive exploitscritical vulnerabilitiesphishing LNKransomware
What happened
Multiple high-impact incidents and research disclosed: CISA added Fortinet FortiClient EMS flaw CVE-2026-35616 (CVSS 9.1) to its KEV catalog and Fortinet released emergency patches as the vulnerability is actively exploited. Over 14,000 F5 BIG-IP APM instances remain exposed and attackers are actively exploiting CVE-2025-53521 (RCE, CVSS 9.8). A leaked unpatched Windows local privilege-escalation zero-day dubbed “BlueHammer” was published by a researcher. New attack techniques and campaigns include GPUBreach (GPU GDDR6 RowHammer bit-flips enabling privilege escalation/full takeover), China-aln
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- ed0379582f277ee9869f46d60b05ce081507adf6c2482ec5a90cdc2f8fd211c4
- Enrichment time
- 2026-04-07T14:51:54Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.