Russian State-Linked APT28 Exploits SOHO Routers in Global DNS Hijacking Campaign
2026-04-07T19:24:20Z•605e0c5d2d4f789fd589c2650c8226c7e65f7f05314ce62535b6022c850d0a8a
APT28Axios npm supply-chain compromise`,`GitHub C2`,`BYOVD`,`Qilin`,`CVE-2025-59528CVE-2026-34040CVE-2026-35616ComfyUIDNS hijackingDPRKDockerFlowiseFortinetGDDR6GPUBreachIran password sprayingMedusa ransomwareMicrosoft 365MikroTikRCESOHO router compromiseStorm-1175TP-LinkUNC1069cryptomining botnetrowhammerzero-day
What happened
Multiple high-impact, active exploitation trends observed across infrastructure, supply chains, and developer tooling. Notable campaigns include a Russian state-linked APT28 operation hijacking insecure MikroTik and TP‑Link SOHO routers for global DNS hijacking (since May 2025); Flowise RCE (CVE-2025-59528, CVSS 10.0) under active exploitation with 12,000+ exposed instances; Docker Engine authorization-bypass (CVE-2026-34040, CVSS 8.8) enabling host access; and Fortinet FortiClient EMS pre-auth access bypass (CVE-2026-35616, CVSS 9.1) being exploited in the wild. Additional activity: large Com
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 605e0c5d2d4f789fd589c2650c8226c7e65f7f05314ce62535b6022c850d0a8a
- Enrichment time
- 2026-04-07T19:24:20Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.