New Chaos Variant Targets Misconfigured Cloud Deployments, Adds SOCKS Proxy

2026-04-08T19:24:08Z6935d7987b45276c2ea8c3742739582dbbc28197669c5cf4b21f65543468847a
APT28BYOVDCOM hijackingCVEComfyUIDDoSDockerFlowiseFortinetGPUBreachPLC/OT attacksPyPIRCESOCKS proxyactive exploitationbotnetcloud misconfigurationcredential sprayingespionagemalwarenpmransomwaresteganographysupply chain

What happened

A broad set of active threats and high-severity vulnerabilities were reported: a new Chaos malware variant now targets misconfigured cloud deployments and adds a SOCKS proxy; Masjesu botnet is offered as DDoS‑for‑hire targeting diverse IoT architectures; APT28 is deploying a novel PRISMEX malware leveraging steganography, COM hijacking and cloud abuse; multiple supply‑chain and repo poisoning campaigns (npm/PyPI/Go/Rust) and exposed AI platforms (Flowise, ComfyUI) are being actively exploited for RCE and cryptomining; Fortinet and Docker disclosed serious authorization/privilege‑escalation/EMS

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
6935d7987b45276c2ea8c3742739582dbbc28197669c5cf4b21f65543468847a
Enrichment time
2026-04-08T19:24:08Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.