New Chaos Variant Targets Misconfigured Cloud Deployments, Adds SOCKS Proxy

2026-04-09T07:24:20Z93bd1933e7e58896fc5c8d4d001eada68654ed699c0636082dbab608b7abbce6
APT28COM hijackingCVE-2025-59528CVE-2026-34040CVE-2026-35616Chaos malwareComfyUIDDoS-for-hireDocker EngineFlowiseFortinetGoMasjesuPRISMEXPyPIRust packages malware','GPUBreach','rowhammer','privilege-escalaSOCKS proxyactive exploitationbotnetcloud misconfigurationcloud service abusecryptomining botnetnpm malwaresteganographysupply chain

What happened

A broad set of active threats and vulnerabilities were reported across cloud, IoT, developer, and OT environments. Key developments include: a new Chaos malware variant targeting misconfigured cloud deployments (adds SOCKS proxy); Masjesu DDoS-for-hire targeting diverse IoT architectures; APT28 campaigns deploying a new PRISMEX malware leveraging steganography, COM hijacking and cloud-service abuse; Flowise (CVE-2025-59528) under active CVSS 10.0 RCE exploitation with thousands of exposed instances; Docker Engine authZ bypass (CVE-2026-34040) allowing host access; FortiClient EMS pre-auth API/

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
93bd1933e7e58896fc5c8d4d001eada68654ed699c0636082dbab608b7abbce6
Enrichment time
2026-04-09T07:24:20Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.