Researchers Uncover Pre-Stuxnet ‘fast16’ Malware Targeting Engineering Software

2026-04-26T07:24:11Zafc19ac956193162c3daeaa73b9998b361ee326c70c988db4605139a538be149
APTCISA-KEVLLM-securitybackdoorexploited-in-the-wildmalwarenetwork-devicesphishingransomwaresandbox-escapesupply-chain-attackvulnerabilitiesweb-application

What happened

A broad set of security incidents and disclosures were reported, ranging from active-exploitation vulnerabilities added to CISA's KEV list to multiple high‑severity product and supply‑chain compromises. Notable items include CISA adding CVE-2024-57726 to KEV (evidence of active exploitation), rapid in‑the‑wild exploitation of LMDeploy CVE-2026-33626, a critical Cohere Terrarium sandbox escape (CVE-2026-5752), a high‑impact ASP.NET Core privilege escalation (CVE-2026-40372), and an Apple notification retention fix (CVE-2026-28950). The week also saw numerous supply‑chain and malware incidents —

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
afc19ac956193162c3daeaa73b9998b361ee326c70c988db4605139a538be149
Enrichment time
2026-04-26T07:24:11Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Researchers Uncover Pre-Stuxnet ‘fast16’ Malware Targeting Engineering Software · Baitaphish