Mirai Variant Nexcorium Exploits CVE-2024-3721 to Hijack TBK DVRs for DDoS Botnet
2026-04-18T07:24:07Z•1f2214f84e502d14b8d1272f96ca0f0b3d86e29535da82db1df669e638ea4d23
Android-RATApache ActiveMQCISA-KEVCiscoDDoSMicrosoft DefenderMiraiNexcoriumOperation-PowerOFFPHANTOMPULSERATSAPShowDocactive-exploitationbotnetcomposerlaw-enforcementmalicious-extensionsmalwaren8nnginx-uipatchingvulnerabilitieszero-day
What happened
The Hacker News roundup highlights numerous active campaigns, disclosures, and patching events: a Mirai variant named Nexcorium is exploiting CVE-2024-3721 to hijack TBK DVRs for DDoS botnets; multiple high- and critical-severity flaws (including nginx-ui CVE-2026-33032 and Apache ActiveMQ CVE-2026-34197) are under active exploitation and have been flagged by CISA and vendors; three Microsoft Defender zero-days (BlueHammer, RedSun, UnDefend) are being abused for privilege escalation with two still unpatched; Cisco, SAP, Microsoft and others released emergency patches for several critical RCE/
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 1f2214f84e502d14b8d1272f96ca0f0b3d86e29535da82db1df669e638ea4d23
- Enrichment time
- 2026-04-18T07:24:07Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.