Russian State-Linked APT28 Exploits SOHO Routers in Global DNS Hijacking Campaign

2026-04-07T19:24:20Z605e0c5d2d4f789fd589c2650c8226c7e65f7f05314ce62535b6022c850d0a8a
APT28Axios npm supply-chain compromise`,`GitHub C2`,`BYOVD`,`Qilin`,`CVE-2025-59528CVE-2026-34040CVE-2026-35616ComfyUIDNS hijackingDPRKDockerFlowiseFortinetGDDR6GPUBreachIran password sprayingMedusa ransomwareMicrosoft 365MikroTikRCESOHO router compromiseStorm-1175TP-LinkUNC1069cryptomining botnetrowhammerzero-day

What happened

Multiple high-impact, active exploitation trends observed across infrastructure, supply chains, and developer tooling. Notable campaigns include a Russian state-linked APT28 operation hijacking insecure MikroTik and TP‑Link SOHO routers for global DNS hijacking (since May 2025); Flowise RCE (CVE-2025-59528, CVSS 10.0) under active exploitation with 12,000+ exposed instances; Docker Engine authorization-bypass (CVE-2026-34040, CVSS 8.8) enabling host access; and Fortinet FortiClient EMS pre-auth access bypass (CVE-2026-35616, CVSS 9.1) being exploited in the wild. Additional activity: large Com

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
605e0c5d2d4f789fd589c2650c8226c7e65f7f05314ce62535b6022c850d0a8a
Enrichment time
2026-04-07T19:24:20Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Russian State-Linked APT28 Exploits SOHO Routers in Global DNS Hijacking Campaign · Baitaphish