Adobe shipped emergency patches for a critical Acrobat/Reader flaw, CVE‑2026‑34621, that attackers have been exploiting for months to execute arbitrary code. Organizations should prioritize updates, scrutinize inbound PDFs, and watch for post‑exploitation activity that may predate patch deployment.
Source: SecurityWeek
CPUID website hijacked to deliver STX RAT via trojanized CPU‑Z and HWMonitor
Attackers briefly compromised CPUID’s official site, swapping legitimate installers for CPU‑Z, HWMonitor/Pro, and PerfMonitor with malware that dropped the STX remote access trojan. The window of exposure (Apr 9 15:00 UTC–Apr 10 10:00 UTC) means anyone downloading during this period should treat systems as compromised, reimage if needed, rotate credentials, and re‑obtain tools from verified hashes.
Source: TheHackerNews
Marimo notebook RCE (CVE‑2026‑39987) exploited within hours of disclosure
A critical Marimo vulnerability (CVSS 9.3) enabling remote code execution was weaponized roughly 10 hours after public disclosure. The rapid turnaround underscores shrinking exploit windows for developer tooling—patch immediately, restrict notebook exposure, and monitor for abnormal process launches from interpreter contexts.
Source: Security Affairs
GlassWorm campaign pivots to Zig‑based dropper to poison developer ecosystems
Active since 2025, the GlassWorm operation has escalated from malicious npm packages to multi‑platform supply chain intrusions across GitHub, npm, and VS Code, now hiding a Zig‑written dropper in fake IDE extensions. The campaign also uses rogue browser extensions to deploy RATs, making strict extension provenance checks and package integrity verification essential.
Source: Security Affairs
5,219 Rockwell PLCs exposed online amid warnings of Iranian APT targeting OT
Censys identified thousands of internet‑exposed Rockwell Automation PLCs—most in the U.S.—days after FBI, CISA, and NSA warned of Iran‑linked APT activity against OT devices. Operators should immediately remove PLCs from direct internet access, enforce IP allowlists/VPNs, and apply vendor hardening guidance to reduce the risk of disruptive impacts.
Source: Security Affairs
Hungarian government accounts exposed: weak credentials hit defense and NATO‑linked logins
Nearly 800 state logins tied to Hungary’s government appeared in breach data, including accounts linked to defense and NATO. The incident highlights the ongoing risks of password reuse and weak authentication—mandate phishing‑resistant MFA, vault‑managed unique passwords, and automated credential exposure monitoring.
Source: The Register
Chrome’s Device Bound Session Credentials aim to kill cookie theft at scale
Google is rolling out DBSC in Chrome 146 on Windows, binding session cookies to hardware‑backed keys so infostealers can’t reuse exfiltrated cookies on other machines. Enterprises should plan staged rollouts, ensure hardware key support, and prepare for changes to incident response focused on session hijacking.
Source: HackRead
You May Also Be Interested In...
Your Push Notifications Aren’t Safe From the FBITwo different attackers poisoned popular open source tools—what it means for supply chain security
Why Anthropic’s Mythos Is a Systemic Shift for Global Cybersecurity