Researchers uncovered a sophisticated exploit embedded in PDF files that leverages an unpatched Acrobat Reader vulnerability, with activity traced back to late 2025. The exploit profiles systems and selectively delivers payloads, underscoring the need to enable Protected View, restrict JavaScript in PDFs, and closely monitor processes spawned by Reader. Organizations should tighten email and web controls around PDF handling while awaiting vendor guidance.
Source: SecurityWeek
Chrome rolls out device-bound cookies to blunt session theft
Google is deploying Device Bound Session Credentials (DBSC) to Windows users in Chrome 146, cryptographically tying session cookies to hardware-backed keys on the device. This makes exfiltrated cookies unusable by attackers and aims to curb widespread infostealer-driven account takeovers; macOS support is coming next. Security teams should coordinate with app owners to adopt DBSC server endpoints and reduce reliance on reactive cookie abuse heuristics.
Source: SecurityWeek
AI-assisted research unearths decade-old Apache ActiveMQ RCE (CVE-2026-34197)
A Horizon3.ai researcher used Claude to help discover a remote code execution flaw in Apache ActiveMQ that has lurked in the codebase for 13 years. The issue was patched in late March 2026; while no in-the-wild exploitation is reported, prior ActiveMQ bugs have been weaponized by ransomware groups. Patch immediately and review exposure of brokers to the internet.
Source: Help Net Security
Treasury launches cyber threat intel sharing program for crypto firms
The U.S. Treasury Department will provide eligible digital asset companies with the same actionable cybersecurity threat information it shares with traditional financial institutions, at no cost. The move signals that crypto platforms are being treated as core financial infrastructure—and prime targets for attackers—while aiming to raise sector-wide detection and response.
Source: Recorded Future News
Cryptocurrency ATM operator Bitcoin Depot hit; $3.6M stolen
Bitcoin Depot disclosed that a threat actor gained access to internal systems and seized credentials tied to digital asset settlement accounts, siphoning roughly $3.6 million. The incident highlights the outsized impact of credential theft in high-value payment flows and the need for robust segregation, transaction controls, and rapid anomaly detection.
Source: Recorded Future News
Supply chain alert: Backdoored Smart Slider 3 Pro update pushed via compromised servers
Attackers hijacked the update channel for the Smart Slider 3 Pro plugin (WordPress/Joomla), distributing version 3.5.1.35 laced with a backdoor. Website operators should verify installed versions against vendor advisories, roll back or patch as directed, rotate secrets, and audit logs for signs of post-compromise activity.
Source: The Hacker News
APT28 deploys PRISMEX malware in espionage ops targeting Ukraine and allies
Trend Micro reports that Russia-linked APT28 (Fancy Bear) is using PRISMEX malware in campaigns exploiting newly disclosed vulnerabilities (including CVE-2026-21509 and CVE-2026-21513) to gain initial access. Organizations supporting Ukraine or allied interests should accelerate patching, harden external services, and validate coverage for related TTPs.
Source: SC Media
You May Also Be Interested In...
Google Warns of New Campaign Targeting BPOs to Steal Corporate Data
FCC Proposes New Rule to Further Crack Down on Illegal Robocalls
Chrome 147 Patches 60 Vulnerabilities, Including Two Critical