Researchers Uncover Pre-Stuxnet ‘fast16’ Malware Targeting Engineering Software

2026-04-26T13:24:06Z306f5cb9f6ca2d3bdb1e9db6a28e450200bc76fa7cfc1ea8d971313189882f48
APTCISA KEVIoT/routersLLM/AI securitySSRFactive exploitationbackdoorcredential theftdockermalwarenpmphishingprivilege escalationsandbox escapesupply chainvs-codevulnerabilitieswiper

What happened

A broad set of cybersecurity incidents and disclosures: researchers uncovered a previously undocumented pre‑Stuxnet Lua sabotage framework (“fast16”); CISA added four actively exploited flaws (including CVE-2024-57726) to its KEV list; multiple high‑severity vulnerabilities are being actively exploited (LMDeploy CVE-2026-33626 SSRF, Terrarium CVE-2026-5752 sandbox escape, ASP.NET Core CVE-2026-40372 privilege escalation, Apple notification logging CVE-2026-28950). Significant supply‑chain compromises and evasive campaigns were reported — Bitwarden CLI and Checkmarx-related packages, maliciousK

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
306f5cb9f6ca2d3bdb1e9db6a28e450200bc76fa7cfc1ea8d971313189882f48
Enrichment time
2026-04-26T13:24:06Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.