CPUID Breach Distributes STX RAT via Trojanized CPU-Z and HWMonitor Downloads

2026-04-13T07:24:25Z31221a6e767139258eb3763ed9a525f473f596003b22b6658ffcff2a62c87379
APT28CPUIDCVE-2026-34040CVE-2026-34621CVE-2026-39987ComfyUIContagious-InterviewDockerEngageLab-SDKGlassWormIDE-compromiseIran-linked-threats','active-exploitation','zero-day'MarimoOT-PLC-attacksPRISMEXSTX-RATSmart-Slider-3-ProZig-dropperacrobat-readerbackdoored-pluginscryptomining-botnetmalicious-software-repossupply-chainthird-party-sdktrojanized-binaries

What happened

Multiple high-impact incidents reported: CPUID was briefly compromised (Apr 9–10, 2026) to serve trojanized CPU‑Z/HWMonitor installers that deployed the STX RAT, indicating a supply‑chain compromise of popular hardware tools. Adobe released emergency fixes for an actively exploited Acrobat Reader flaw (CVE‑2026‑34621, CVSS 8.6), and researchers observed an urgent Marimo pre‑auth RCE (CVE‑2026‑39987, CVSS 9.3) exploited within 10 hours of disclosure. Docker Engine patch (CVE‑2026‑34040, CVSS 8.8) addresses an AuthZ bypass allowing potential host access. Other notable threats: a backdoored Smart

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
31221a6e767139258eb3763ed9a525f473f596003b22b6658ffcff2a62c87379
Enrichment time
2026-04-13T07:24:25Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.