Mirai Variant Nexcorium Exploits CVE-2024-3721 to Hijack TBK DVRs for DDoS Botnet

2026-04-18T07:24:07Z1f2214f84e502d14b8d1272f96ca0f0b3d86e29535da82db1df669e638ea4d23
Android-RATApache ActiveMQCISA-KEVCiscoDDoSMicrosoft DefenderMiraiNexcoriumOperation-PowerOFFPHANTOMPULSERATSAPShowDocactive-exploitationbotnetcomposerlaw-enforcementmalicious-extensionsmalwaren8nnginx-uipatchingvulnerabilitieszero-day

What happened

The Hacker News roundup highlights numerous active campaigns, disclosures, and patching events: a Mirai variant named Nexcorium is exploiting CVE-2024-3721 to hijack TBK DVRs for DDoS botnets; multiple high- and critical-severity flaws (including nginx-ui CVE-2026-33032 and Apache ActiveMQ CVE-2026-34197) are under active exploitation and have been flagged by CISA and vendors; three Microsoft Defender zero-days (BlueHammer, RedSun, UnDefend) are being abused for privilege escalation with two still unpatched; Cisco, SAP, Microsoft and others released emergency patches for several critical RCE/​

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
1f2214f84e502d14b8d1272f96ca0f0b3d86e29535da82db1df669e638ea4d23
Enrichment time
2026-04-18T07:24:07Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.