Microsoft warns that Forest Blizzard (APT28) has been compromising small‑office/home‑office routers and modifying their settings to hijack DNS, enabling adversary‑in‑the‑middle attacks that steal passwords and authentication tokens. Defenders should patch or replace end‑of‑life routers, disable remote administration, enforce strong unique credentials, lock down DNS/DHCP settings, and monitor for unexpected resolver changes.
Source: Microsoft Security Blog
Iran‑linked hackers disrupt US critical infrastructure by targeting internet‑exposed PLCs
Federal agencies report that Iranian actors are manipulating PLC/SCADA systems across water, energy, and local government sectors, causing operational impacts and safety concerns. Organizations should immediately remove PLCs from the public internet, enforce strong authentication and network segmentation, review vendor advisories, and harden remote access pathways.
Source: SecurityWeek
Anthropic’s ‘Claude Mythos’ preview can autonomously find and exploit zero‑days—industry coalition limits access
Anthropic unveiled a powerful model under Project Glasswing that can discover and weaponize software flaws across major platforms, prompting a controlled preview with select partners to accelerate defensive remediation while reducing dual‑use risk. Expect vulnerability discovery and exploit development cycles to compress; teams should boost secure SDLC, SBOM coverage, rapid patch pipelines, and pre‑deployment hardening.
Source: SecurityWeek
CISA orders emergency fixes for Fortinet FortiClient EMS pre‑auth API bypass (CVE‑2026‑35616)
Following active exploitation, CISA directed federal agencies to remediate vulnerable FortiClient EMS instances by April 9 and added the flaw to the Known Exploited Vulnerabilities catalog. Enterprises should apply Fortinet’s out‑of‑band patches immediately, audit EMS logs for suspicious API activity, rotate credentials/tokens managed via EMS, and restrict management plane exposure.
Source: SC Media
Critical RCE in Flowise AI agent builder (CVE‑2025‑59528) is under active exploitation
A validation flaw in Flowise allows attackers to execute arbitrary JavaScript and access the underlying file system; thousands of internet‑exposed instances are at risk and being targeted. Patch to the latest secure release, place Flowise behind authentication and network controls, disable untrusted code execution, rotate any exposed API keys, and review deployment inventories for shadow AI instances.
Source: SecurityWeek
AI‑enabled device code phishing abuses OAuth flow to mass‑takeover accounts
Microsoft researchers observed a campaign that automates device code generation and consent to bypass the 15‑minute window, compromising organizations at scale to loot mailboxes and financial data. Mitigations include disabling the OAuth Device Code flow where not needed, enforcing conditional access and step‑up MFA, restricting app consent, monitoring risky OAuth grants, and revoking abused refresh tokens.
Source: Help Net Security
Trump budget would cut CISA funding and election security efforts
The FY27 proposal trims roughly $700 million from CISA programs and eliminates hundreds of positions, including funding tied to election security. If enacted, reduced federal capacity could slow advisories, incident response, and grants—raising the burden on state/local entities and private‑sector operators to maintain resilience.
Source: Nextgov/FCW
You May Also Be Interested In...