Mirai Variant Nexcorium exploits CVE-2024-3721 to hijack TBK DVR and attack DDoS botnet

Ravi LakshmananApril 18, 2026IoT security/vulnerabilities According to research from Fortinet FortiGuard Labs and Palo Alto Networks Unit 42, threat actors are exploiting security flaws in TBK DVRs and End of Life (EoL) TP-Link Wi-Fi routers to deploy Mirai botnet variants on compromised devices. The attack targeting TBK DVR devices was found to exploit CVE-2024-3721 (CVSS […]

Three Microsoft Defender zero-days were actively exploited. 2 are not yet patched

Ravi LakshmananApril 17, 2026Vulnerabilities / Endpoint Security Huntress warns that attackers are exploiting three recently disclosed security flaws in Microsoft Defender to gain elevated privileges on compromised systems. This activity included exploitation of three vulnerabilities codenamed BlueHammer (GitHub sign-in required), RedSun, and UnDefend, all of which were released as zero-days by researchers known as Chaotic […]

NIST limits CVE enrichment after vulnerability submissions spike by 263%

Ravi LakshmananApril 17, 2026Vulnerability management The National Institute of Standards and Technology (NIST) announced changes to how it handles cybersecurity vulnerabilities and exposures (CVEs) listed in the National Vulnerability Database (NVD), saying that due to a sharp increase in CVE submissions, it will enrich only those that meet certain criteria. “CVEs that do not meet […]

Operation PowerOFF seizes 53 DDoS domains and exposes 3 million criminal accounts

Ravi LakshmananApril 17, 2026DDoS/Cybercrime An international law enforcement operation resulted in the closure of 53 domains and four arrests in connection with a commercial distributed denial of service (DDoS) operation used by more than 75,000 cybercriminals. An ongoing effort dubbed “Operation PowerOFF” has disrupted access to the DDoS rental service, taken down the technical infrastructure […]

Apache ActiveMQ CVE-2026-34197 added to CISA KEV amid active exploitation

Ravi LakshmananApril 17, 2026Vulnerabilities / Enterprise Security According to the US Cybersecurity and Infrastructure Security Agency (CISA), a recently disclosed high-severity security flaw in Apache ActiveMQ Classic is being exploited in the wild. To that end, the agency is adding this vulnerability, tracked as CVE-2026-34197 (CVSS score: 8.8), to its Known Exploited Vulnerabilities (KEV) catalog […]

Newly discovered PowMix botnet uses randomized C2 traffic to attack Czech workers

Ravi LakshmananApril 16, 2026Botnet/Cryptomining Cybersecurity researchers have warned that a previously undocumented botnet called PowMix has been active in a malicious campaign targeting workers in the Czech Republic since at least December 2025. “PowMix employs randomized command and control (C2) beacon intervals rather than persistent connections to C2 servers to evade detection of network signatures,” […]

Defender 0-Day, SonicWall Brute-Force, 17-Year-Old Excel RCE and 15 More Stories

Ravie LakshmananApr 16, 2026Hacking News / Cybersecurity News You know that feeling when you open your feed on a Thursday morning and it’s just… a lot? Yeah. This week delivered. We’ve got hackers getting creative in ways that are almost impressive if you ignore the whole “crime” part, ancient vulnerabilities somehow still ruining people’s days, and enough supply […]

[Webinar] Find and eliminate isolated non-human identities in the environment

mohit kumarApril 16, 2026Artificial Intelligence/Enterprise Security In 2024, 68% of cloud breaches were due to compromised service accounts and forgotten API keys. It’s not phishing. It’s not a weak password. An unmanaged non-human identity that no one saw. Each employee in your organization has 40-50 automated credentials, such as service accounts, API tokens, AI agent […]

Cisco patches four critical identity services, Webex flaw that allows code execution

Ravi LakshmananApril 16, 2026Vulnerability/Network Security Cisco has announced patches that address four critical security flaws affecting Identity and Webex services. These flaws could allow an attacker to execute arbitrary code and impersonate any user within the service. The vulnerability details are below. CVE-2026-20184 (CVSS Score: 9.8) – Improper certificate validation in the Control Hub and […]