Researchers Uncover Pre-Stuxnet ‘fast16’ Malware Targeting Engineering Software
2026-04-26T19:24:17Z•bb24a6ee5f743c1fe3779dc1d9785ce3b0f2da3ec8fc03fc01f21fbd382e8aff
active-exploitationaptaspnet-corebackdoorcredential-theftcrypto-theftcvedockerioskeVmalwarenpmphishingransomwaresandbox-escapesoftware-supply-chainssrfsupply-chainvulnerability
What happened
A multi-story collection of active high-risk threats and supply-chain incidents: researchers uncovered a pre‑Stuxnet Lua sabotage framework (‘fast16’) targeting engineering software; CISA added exploited flaws (including CVE-2024-57726) to its KEV with a May 2026 federal mitigation deadline; and multiple high-severity vulnerabilities are being actively abused (notably CVE-2026-33626 in LMDeploy exploited within 13 hours, CVE-2026-5752 Terrarium sandbox escape, and CVE-2026-40372 ASP.NET Core privilege escalation). Ongoing supply‑chain compromises (Bitwarden CLI in a Checkmarx campaign, KICS/VS
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- bb24a6ee5f743c1fe3779dc1d9785ce3b0f2da3ec8fc03fc01f21fbd382e8aff
- Enrichment time
- 2026-04-26T19:24:17Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.