Researchers Uncover Pre-Stuxnet ‘fast16’ Malware Targeting Engineering Software

2026-04-27T01:24:18Za5783f3ed8b821248b40dcf4a9cb767a907a669c9151ccd58545dbe001702e1a
APTCISA-KEVLLMbackdoorcredential-theftdockerincident-responsemalwarenpmphishingprivilege-escalationremote-accesssandbox-escapesupply-chainwiperzero-day

What happened

A multi-article roundup from The Hacker News (Apr 22–25, 2026) covering active exploitation, supply‑chain compromises, APT activity, and high‑severity vulnerabilities. Highlights include the discovery of a pre‑Stuxnet Lua sabotage framework dubbed “fast16”; CISA adding four actively exploited flaws (including CVE‑2024‑57726) to its KEV list; the FIRESTARTER backdoor compromising a federal Cisco Firepower/ASA device; rapid in‑the‑wild exploitation of LMDeploy CVE‑2026‑33626; the Bitwarden CLI package compromise tied to a Checkmarx supply‑chain campaign; malicious Checkmarx/KICS Docker images &恶

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
a5783f3ed8b821248b40dcf4a9cb767a907a669c9151ccd58545dbe001702e1a
Enrichment time
2026-04-27T01:24:18Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.