Latest Internet & Cybersecurity News

๐Ÿ“…April 15, 2026 at 1:00 PM
IBM unveils AI defenses against agentic attacks; Microsoft patches 167 flaws amid Russian router spying; global botnet takedown; ransomware surges in manufacturing and infrastructure.
1

IBM Announces New Cybersecurity Measures Against Agentic Attacks

IBM launched a cybersecurity assessment to identify risks from frontier AI models enabling autonomous attacks and introduced IBM Autonomous Security using AI agents for rapid vulnerability remediation. These tools help enterprises counter weaponized AI threats at machine speed.Source 1 The announcement was made on April 15, 2026.Source 1

2

Microsoft Patches 167 Vulnerabilities Including SharePoint Zero-Day

Microsoft released updates fixing 167 security flaws in Windows, including a SharePoint Server zero-day and Windows Defender's 'BlueHammer' weakness. Google Chrome addressed its fourth zero-day of 2026, while Adobe Reader patched an exploited remote code execution flaw.Source 2 These updates are critical amid ongoing threats.Source 2

3

Russian Hackers Harvest Microsoft Tokens via Vulnerable Routers

Russia's Forest Blizzard group exploited flaws in over 18,000 outdated routers to steal Microsoft Office authentication tokens from 200+ organizations and 5,000 devices without malware. The campaign peaked in December 2025, targeting governments and email providers.Source 2 Black Lotus Labs at Lumen reported the surveillance dragnet.Source 2

4

Global Operation Dismantles Four Major IoT Botnets

US, Canada, and Germany disrupted botnets Aisuru, Kimwolf, JackSkid, and Mossad infecting 3 million IoT devices like routers and cameras for massive DDoS attacks. Targets included US defense systems.Source 2Source 3 The operation highlights international cooperation against cyber threats.Source 3

5

Trivy Vulnerability Scanner Hit by Supply Chain Attack

TeamPCP injected credential-stealing malware into Aqua Security's Trivy scanner releases on GitHub, targeting SSH keys, cloud credentials, and wallets. Aqua removed the malicious files, but impacts persist.Source 2 Wiz noted the broad reach of the attack.Source 2

6

Cyberattacks Target US Infrastructure Amid Geopolitical Tensions

Threat actors are hitting US industrial control systems in a shift toward physical disruption, influenced by Middle East conflicts and geopolitics. 64% of organizations now integrate geopolitical risks into cybersecurity plans per Global Cybersecurity Outlook 2026.Source 3 This reflects evolving cyber warfare tactics.Source 3

7

Ransomware Activity Stable but Elevated in Q1 2026

GuidePoint Security's report shows sustained high ransomware volumes, with US as top target (51%) and construction sector up 44% YoY to 131 victims. New groups like The Gentlemen surged, while data extortion rises without encryption.Source 5 Manufacturing remains most impacted.Source 5

8

FBI Reports 2,100 Ransomware Incidents on US Critical Infrastructure in 2025

IC3 logged over 2,100 ransomware attacks on sectors like healthcare, energy, and manufacturing, far exceeding data breaches. Top groups Akira, Qilin, and Lynx use double extortion and compromised credentials.Source 6 State and local governments face ripple effects.Source 6

9

AI-Driven Pushpaganda Scam Poisons Google Discover Feed

Attackers use AI-generated content and SEO poisoning to push scam notifications via Google Discover, peaking at 240 million bid requests across 113 domains. Now global beyond India, Google deployed a fix.Source 7 HUMAN's CISO highlighted abuse of trusted surfaces.Source 7

10

Manufacturing Faces 56% Ransomware Surge in 2025

Sector saw 1,466 incidents, half of global attacks, driven by RaaS, legacy OT, and supply chains. Groups like Akira, Qilin, and Clop used double extortion and AI malware; US, Europe hardest hit.Source 8 Operations faced major disruptions.Source 8

11

Basic-Fit Data Breach Exposes 1 Million Gym Members

Europe's largest gym chain disclosed hackers accessed systems, compromising personal data of around 1 million members. The incident underscores risks to consumer data in non-tech sectors.Source 12 Investigations are ongoing.Source 12

12

Anthropic Launches Project Glasswing AI Cybersecurity Initiative

Anthropic's initiative lets partners like Amazon, Microsoft, Google test unreleased Claude Mythos Preview for vulnerability detection, identifying thousands already. Supports open-source security groups.Source 3 Aims to bolster defensive AI use.Source 3