[Webinar] Eliminate Ghost Identities Before They Expose Your Enterprise Data
2026-04-18T13:24:09Z•40e1be7a20bd74d57bd1ddf142ab03e157973c43ec77c7ea6c78e1ab11380abf
Android-RATCISA-KEVDDoSObsidian-pluginRATactive-exploitationapache-activemqbotnetcredential-riskmirain8nnginx-uiphishingsupply-chainvulnerabilityzero-day
What happened
A broad set of high-impact incidents and vulnerabilities were reported: multiple actively exploited and high-severity CVEs (notably nginx-ui CVE-2026-33032 and Apache ActiveMQ CVE-2026-34197 added to CISA KEV), three Microsoft Defender zero-days under active exploitation, and Mirai variant Nexcorium abusing CVE-2024-3721 to conscript DVRs into DDoS botnets. Other notable threats include the PowMix and Mirax botnets, targeted delivery of the PHANTOMPULSE RAT via Obsidian plugin abuse, abuse of n8n webhooks for phishing and malware delivery, a large theft from sanctioned exchange Grinex, and the
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 40e1be7a20bd74d57bd1ddf142ab03e157973c43ec77c7ea6c78e1ab11380abf
- Enrichment time
- 2026-04-18T13:24:09Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.