[Webinar] Eliminate Ghost Identities Before They Expose Your Enterprise Data

2026-04-18T13:24:09Z40e1be7a20bd74d57bd1ddf142ab03e157973c43ec77c7ea6c78e1ab11380abf
Android-RATCISA-KEVDDoSObsidian-pluginRATactive-exploitationapache-activemqbotnetcredential-riskmirain8nnginx-uiphishingsupply-chainvulnerabilityzero-day

What happened

A broad set of high-impact incidents and vulnerabilities were reported: multiple actively exploited and high-severity CVEs (notably nginx-ui CVE-2026-33032 and Apache ActiveMQ CVE-2026-34197 added to CISA KEV), three Microsoft Defender zero-days under active exploitation, and Mirai variant Nexcorium abusing CVE-2024-3721 to conscript DVRs into DDoS botnets. Other notable threats include the PowMix and Mirax botnets, targeted delivery of the PHANTOMPULSE RAT via Obsidian plugin abuse, abuse of n8n webhooks for phishing and malware delivery, a large theft from sanctioned exchange Grinex, and the

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
40e1be7a20bd74d57bd1ddf142ab03e157973c43ec77c7ea6c78e1ab11380abf
Enrichment time
2026-04-18T13:24:09Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.