CERT-UA Impersonation Campaign Spread AGEWHEEZE Malware to 1 Million Emails
2026-04-02T07:24:07Z•96ee8e4f1d33f25e6ea82ec2f233538469dbd415f7b10a371edb005766533179
AGEWHEEZEAnthropicAtlasCrossCasbaneiroCitrixDeepLoadF5RATTrueConfUAC-bypassUNC1069VBSVertexAIbrowser-exploitchromedata-exposuremalwarenpmphishingremote-access-trojansupply-chainzero-day
What happened
A batch of high-impact security incidents was reported, including large-scale phishing and supply-chain attacks, active zero-day exploitation, and cloud/AI exposure risks. CERT-UA was impersonated in a campaign distributing AGEWHEEZE to ~1 million emails; WhatsApp-delivered VBS malware with a UAC bypass has been observed; Google Chrome patched an actively exploited zero-day (CVE-2026-5281); TrueConf’s zero-day (CVE-2026-3502) was exploited against Southeast Asian government networks; Citrix NetScaler (CVE-2026-3055) is under active reconnaissance; and F5 BIG‑IP APM’s CVE-2025-53521 was addedto
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 96ee8e4f1d33f25e6ea82ec2f233538469dbd415f7b10a371edb005766533179
- Enrichment time
- 2026-04-02T07:24:07Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.