Apple released iOS/iPadOS 26.4.2 and 18.7.8 to fix CVE-2026-28950, a Notification Services logging issue that allowed notifications marked for deletion to remain on devices. The bug, reportedly leveraged in forensic cases to retrieve Signal and other messaging alerts, posed a serious privacy risk to users. Organizations should prioritize updates across device fleets and review retention policies for lock-screen and notification data.
Source: SecurityWeek
Microsoft Defender zero-day lets attackers grab NTLM hashes and escalate to System
A recently disclosed Microsoft Defender vulnerability is being exploited in the wild to access the Windows SAM database, extract NTLM hashes, and achieve System-level privileges. The flaw underscores the risk of endpoint protection components being abused as escalation pathways. Immediate patching and monitoring for anomalous SAM access on endpoints are advised.
Source: SecurityWeek
Emergency patch: Critical ASP.NET Core privilege escalation (CVE-2026-40372)
Microsoft released out-of-band fixes for a critical ASP.NET Core vulnerability (CVSS 9.1) that can enable privilege escalation in affected applications. Developers should update to the latest ASP.NET Core versions without delay and review app authentication and deployment footprints for potential exposure.
Source: BleepingComputer
Self-spreading npm supply-chain worm steals developer tokens via compromised packages
A new worming campaign in the npm ecosystem compromises accounts, injects malicious code into packages, and self-propagates while exfiltrating authentication tokens. The attack highlights the cascading blast radius of compromised developer credentials and CI secrets. Teams should rotate tokens, audit recent package publishes, and enable stronger package signing and MFA.
Source: BleepingComputer
China-linked “GopherWhisper” hides C2 in Slack, Discord, Outlook drafts and file-sharing
ESET detailed a new APT group, GopherWhisper, that blends command-and-control traffic into everyday SaaS platforms including Slack, Discord, Outlook drafts, and file.io, evading traditional network defenses. The campaign, tied to an intrusion at a Mongolian government entity, deploys Go-based loaders and backdoors. Organizations should scrutinize high-risk SaaS API usage and tighten egress controls for chat and sharing apps.
Source: Help Net Security
Destructive “Lotus Wiper” hits Venezuelan energy sector, targeting recovery mechanisms
Researchers uncovered Lotus Wiper, a new data-wiping malware used against Venezuela’s energy and utilities sector. The tool disables defenses, targets backups and recovery, overwrites drives, and systematically deletes files—signaling intent to disrupt operations rather than extort. Critical infrastructure defenders should validate backup isolation and practice restoration under attack conditions.
Source: SecurityWeek
Phishing returns as top initial access vector in Q1 2026, with public sector in the crosshairs
Cisco Talos IR reports phishing accounted for over one-third of observed initial access cases in Q1, reclaiming the lead for the first time since mid‑2025. The team also notes persistent targeting of public administration and growing experimentation with AI tools by threat actors. Security leaders should redouble phishing controls and user resilience while monitoring AI-enabled tradecraft shifts.
Source: Cisco Talos
You May Also Be Interested In...
Progress Software fixes sneaky WAF bypass vulnerability (CVE-2026-21876)
UK NCSC endorses passkeys as the default for consumers
Oracle issues April CPU with 481 security fixes across 28 product families