Latest Internet & Cybersecurity News

๐Ÿ“…April 28, 2026 at 1:00 AM
Critical Windows patching flaws exploited by APT28, utility and med-tech firms Itron and Medtronic hacked, Firestarter malware persists post-patch, Chinese hacker extradited amid rising AI-driven threats.
1

Incomplete Windows Patch Enables Zero-Click Attacks by APT28

Microsoft's April 2026 patches fixed CVE-2026-32202, an authentication coercion flaw from an incomplete fix for CVE-2026-21510, allowing zero-click credential theft via LNK files.Source 1 Russia-linked APT28 exploited these chained with CVE-2026-21513 in attacks on Ukraine and EU since December 2025.Source 1 Akamai disclosed the issue after finding the patch incomplete.Source 1

2

Utilities Firm Itron Discloses Cybersecurity Breach

Itron, a utilities tech provider, reported an unauthorized breach of its IT systems on April 24 to the SEC, activating response plans with external advisors.Source 2 The company remediated the access, notified law enforcement, and saw no impact on customer systems or operations.Source 2 It expects insurance to cover most costs with no material financial effect.Source 2

3

Medtronic Admits Unauthorized Access to Corporate IT Systems

Medical device maker Medtronic disclosed an unauthorized party accessed certain corporate IT data in an SEC filing, separate from product and customer networks.Source 5 Hacker group ShinyHunters claimed to steal over 9M records of PII and internal data, issuing an extortion deadline.Source 5 The breach follows similar attacks on med-tech firms like Stryker.Source 5

4

US, UK Warn Firestarter Backdoor Survives Cisco Patching

CISA and UK authorities alerted that Firestarter malware persists on patched Cisco Firepower and Secure Firewall devices despite fixes for CVE-2025-20333 and CVE-2025-20362.Source 3 A US federal agency was hit by UAT-4356 actors deploying Line Viper implants via ArcaneDoor campaign.Source 3 Cisco issued mitigation guidance; FCEB agencies urged to check for compromise.Source 3

5

Chinese State-Sponsored Hacker Extradited to US from Italy

A prolific contract hacker linked to Chinese state-sponsored operations was extradited to the US from Italy on April 28, 2026.Source 4 The individual faces charges for cyber intrusions supporting Beijing's interests.Source 4 This marks a significant win in international cybercrime enforcement.Source 4

6

Anthropic's Mythos AI Uncovers 2000 Software Vulnerabilities in 7 Weeks

Anthropic's Mythos AI model identified over 2000 previously unknown software flaws in just seven weeks, raising alarms on AI's dual-use in cybersecurity.Source 7 The rapid discovery highlights both defensive potential and risks of AI automating vulnerability hunting.Source 7 Experts warn of escalated security challenges from such tools.Source 7

7

OpenSSH Flaw Allows Full Root Shell Access After 15 Years

A long-lurking OpenSSH vulnerability enabling full root shell access was disclosed after existing undetected for 15 years.Source 1 The flaw poses severe risks to SSH-dependent systems worldwide.Source 1 Immediate patching is recommended for all affected versions.Source 1

8

Malicious AI Prompt Injection Attacks Rising but Low Sophistication

Google reports increasing malicious AI prompt injection attacks, though attacker sophistication remains low.Source 1 These exploits target AI systems to manipulate outputs or extract data.Source 1 Defenses should focus on input validation and model hardening.Source 1

9

Taiwan Initiative Identifies 20 Critical ICT Security Risks

A cybersecurity initiative spotted 20 valid ICT loopholes in Taiwan, including three severe and six high-risk vulnerabilities.Source 8 The findings urge urgent remediation in government and critical infrastructure systems.Source 8 Administration officials emphasized proactive threat hunting.Source 8

10

UNC6692 Deploys 'Snow' Malware via Email Bombing and Social Engineering

Threat actor UNC6692 uses email flooding and social tactics to deliver Snow malware in targeted campaigns.Source 1 The group focuses on initial access for further exploitation.Source 1 Organizations should enhance email filters and user training.Source 1

11

Security Experts Warn AI Supercharges Cyber Threats to Jewish Philanthropy

Experts caution that AI amplifies cyber risks to philanthropic and Jewish organizations, urging advanced defenses.Source 6 Recent alerts highlight AI's role in sophisticated attacks.Source 6 Community networks recommend AI-aware security postures.Source 6