CERT-UA Impersonation Campaign Spread AGEWHEEZE Malware to 1 Million Emails

2026-04-02T07:24:07Z96ee8e4f1d33f25e6ea82ec2f233538469dbd415f7b10a371edb005766533179
AGEWHEEZEAnthropicAtlasCrossCasbaneiroCitrixDeepLoadF5RATTrueConfUAC-bypassUNC1069VBSVertexAIbrowser-exploitchromedata-exposuremalwarenpmphishingremote-access-trojansupply-chainzero-day

What happened

A batch of high-impact security incidents was reported, including large-scale phishing and supply-chain attacks, active zero-day exploitation, and cloud/AI exposure risks. CERT-UA was impersonated in a campaign distributing AGEWHEEZE to ~1 million emails; WhatsApp-delivered VBS malware with a UAC bypass has been observed; Google Chrome patched an actively exploited zero-day (CVE-2026-5281); TrueConf’s zero-day (CVE-2026-3502) was exploited against Southeast Asian government networks; Citrix NetScaler (CVE-2026-3055) is under active reconnaissance; and F5 BIG‑IP APM’s CVE-2025-53521 was addedto

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
96ee8e4f1d33f25e6ea82ec2f233538469dbd415f7b10a371edb005766533179
Enrichment time
2026-04-02T07:24:07Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.