Your MTTD Looks Great. Your Post-Alert Gap Doesn't
2026-04-13T13:24:13Z•2f2312d6422041017d70388bd069f181b8bba948ccad10c21c7744acd5e2b132
APT28APT37Android SDKAnthropic Claude MythosChrome DBSCDDoS-for-hireEngageLabGlassWormIoTLucidRookPRISMEXRATRokRATSTX RATWeblocbotnetbrowser-extensionsmalicious-packagesnation-stateprivacy-surveillancerapid-exploitationremote-code-executionsoftware-update-backdoorsupply-chain-compromisezero-day
What happened
A broad set of high-impact security events: multiple actively exploited zero-days and RCEs (notably CVE-2026-34621 in Acrobat Reader and CVE-2026-39987 in Marimo), high-profile supply-chain compromises (CPUID serving STX RAT, backdoored Smart Slider 3 Pro, malicious packages across npm/PyPI/Go/Rust, and an Axios library incident affecting OpenAI macOS signing), and rapid proliferation of malware and nation-state activity (APT37 delivering RokRAT via Facebook, APT28 PRISMEX and router/DNS hijacking, Iran-linked PLC attacks). Other notable threats include GlassWorm infecting developer IDEs via a
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 2f2312d6422041017d70388bd069f181b8bba948ccad10c21c7744acd5e2b132
- Enrichment time
- 2026-04-13T13:24:13Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.