Shrinking the IAM Attack Surface through Identity Visibility and Intelligence Platforms (IVIP)

2026-04-08T13:24:11Z505228067434d561ba9d2eb12235bddf5701bed3a257739d377875d437af0e75
APT28BYOVDCVE-2025-59528CVE-2026-34040CVE-2026-35616DPRKEDR-bypassGPU RowHammerIran-linkedPLC/OTPyPIactive-exploitationcredential attackscryptomining-botnetnpmopen-source compromisepassword-sprayingphishingransomwarerouter compromisestate-sponsoredsupply-chainvulnerabilityweb-shellszero-day

What happened

A broad set of active threats and research impacting enterprise and open-source ecosystems: multiple high-severity and actively exploited vulnerabilities (notably Docker CVE-2026-34040, FortiClient CVE-2026-35616, and Flowise CVE-2025-59528) plus references to a prior Docker fix (CVE-2024-41110). Widespread supply-chain abuse and malicious packages hit npm, PyPI, Go and Rust registries and an Axios maintainer compromise; a DPRK social‑engineering theft ($285M) and UNC1069/Contagious Interview activity were reported. State-linked campaigns from Russia (APT28) and China (Storm-1175/TA416) are in

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
505228067434d561ba9d2eb12235bddf5701bed3a257739d377875d437af0e75
Enrichment time
2026-04-08T13:24:11Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.