Sweden Blames Pro-Russian Group for Cyberattack Last Year on Its Energy Infrastructure
2026-04-16T07:24:07Z•da8eb48ab7ccd78b88f8da294493e403597252385d492d036d523de768c5cb21
AI-supply-chainAndroidAnthropicCVE-2026-33032Ivanti NeuronsMCPMaaSMirax RATOTSwedenadwarebackdoorchrome-extensionscriticalenergy-infrastructureexfiltrationexploited-in-the-wildgovernmentnginxpro-Russianremote-takeovervulnerability
What happened
Feed highlights a critical actively exploited vulnerability (CVE-2026-33032) in the Nginx UI management tool enabling remote takeover, plus multiple other high-impact threats: a 'by-design' Model Context Protocol (MCP) flaw that can enable AI supply-chain/system compromise (Anthropic MCP), 100 malicious Chrome extensions that exfiltrate data and provide backdoors, Mirax RAT offered as MaaS targeting Android users in Europe, and a pro‑Russian group blamed for a cyberattack on Swedish energy infrastructure (heating plant). Also reported: two patched Ivanti Neurons for ITSM flaws (post-auth/pivot
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityweek
- Record identifier
- da8eb48ab7ccd78b88f8da294493e403597252385d492d036d523de768c5cb21
- Enrichment time
- 2026-04-16T07:24:07Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.