Daily Threat Briefing – April 8, 2026
ID: 0f198429-3ed2-5574-a431-4f664de31814
STIX ID: report--0f198429-3ed2-5574-a431-4f664de31814
Feed Name: defend.network
### Executive Summary The briefing reports multiple critical, actively exploited threats: APT28 is hijacking MikroTik/TP-Link routers to harvest Microsoft 365 tokens; Iranian-linked actors are targeting internet-exposed Rockwell/Allen-Bradley PLCs; Docker (CVE-2026-34040) and Flowise (CVE-2025-59528) vulnerabilities are under active exploitation; ComfyUI instances have been co-opted into a cryptomining/proxy botnet; and healthcare organizations have suffered ransomware and wiper incidents—accompanied by urgent mitigation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
