CPUID Breach Distributes STX RAT via Trojanized CPU-Z and HWMonitor Downloads
2026-04-13T07:24:25Z•31221a6e767139258eb3763ed9a525f473f596003b22b6658ffcff2a62c87379
APT28CPUIDCVE-2026-34040CVE-2026-34621CVE-2026-39987ComfyUIContagious-InterviewDockerEngageLab-SDKGlassWormIDE-compromiseIran-linked-threats','active-exploitation','zero-day'MarimoOT-PLC-attacksPRISMEXSTX-RATSmart-Slider-3-ProZig-dropperacrobat-readerbackdoored-pluginscryptomining-botnetmalicious-software-repossupply-chainthird-party-sdktrojanized-binaries
What happened
Multiple high-impact incidents reported: CPUID was briefly compromised (Apr 9–10, 2026) to serve trojanized CPU‑Z/HWMonitor installers that deployed the STX RAT, indicating a supply‑chain compromise of popular hardware tools. Adobe released emergency fixes for an actively exploited Acrobat Reader flaw (CVE‑2026‑34621, CVSS 8.6), and researchers observed an urgent Marimo pre‑auth RCE (CVE‑2026‑39987, CVSS 9.3) exploited within 10 hours of disclosure. Docker Engine patch (CVE‑2026‑34040, CVSS 8.8) addresses an AuthZ bypass allowing potential host access. Other notable threats: a backdoored Smart
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 31221a6e767139258eb3763ed9a525f473f596003b22b6658ffcff2a62c87379
- Enrichment time
- 2026-04-13T07:24:25Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.