New Chaos Variant Targets Misconfigured Cloud Deployments, Adds SOCKS Proxy
2026-04-09T01:24:15Z•6a8025e7c894dfc45a8b930f8a96b1ada2c33e8308a0f9b8e33ba3a381bfe796
APT28BYOVDChaosComfyUIDDoSDPRKEDR-bypassGPUBreachMasjesuOT-targetingPLCsPRISMEXPyPISOCKS-proxyactive-exploitationbotnetcloud-misconfigurationcryptominingmalwarenpmpackage-poisoningprivilege-escalationsupply-chainvulnerability
What happened
A broad set of high-impact threats and active vulnerabilities were reported: an evolved Chaos malware variant now targets misconfigured cloud deployments (adds SOCKS proxy), new botnets (Masjesu) and cryptomining/proxy campaigns are exploiting exposed IoT, ComfyUI and cloud instances, and APT28/PRISMEX and DPRK-linked actors are conducting espionage and supply-chain attacks. Multiple high-severity vulnerabilities are being actively exploited or widely exposed—most notably Flowise CVE-2025-59528 (CVSS 10.0, active RCE across ~12k instances), Fortinet CVE-2026-35616 (critical, exploited in the-w
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 6a8025e7c894dfc45a8b930f8a96b1ada2c33e8308a0f9b8e33ba3a381bfe796
- Enrichment time
- 2026-04-09T01:24:15Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.