CISA flags new SD-WAN flaw as actively exploited in attacks

2026-04-21T13:23:32Z7aae96ae233fcc01a43cc5f8e35baa20b490c0eaf9fdfd87d579cc43a1f7192b
ALPHVAndroid malwareApache ActiveMQBlackCatCISACatalystGentlemen ransomwareHandyPayKelpDAOLazarusMicrosoft TeamsNFC payment theftNGateSD-WANSystemBCVercelactive exploitationbotnetcode injectioncrypto theftdata breachhelpdesk impersonationmalicious app storeransomwarewallet phishing

What happened

Multiple high-risk security incidents and actively exploited vulnerabilities reported: CISA issued an urgent four-day remediation directive for a Catalyst SD‑WAN Manager flaw being actively exploited; Shadowserver found over 6,400 public Apache ActiveMQ servers vulnerable to an ongoing high‑severity code‑injection exploit; a former ransomware negotiator pleaded guilty for BlackCat/ALPHV attacks; NGate Android malware is trojanizing the HandyPay NFC app to steal payment card data; KelpDAO suffered a ~$290M DeFi heist likely tied to North Korean Lazarus actors; 26 malicious crypto‑wallet apps (e

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
7aae96ae233fcc01a43cc5f8e35baa20b490c0eaf9fdfd87d579cc43a1f7192b
Enrichment time
2026-04-21T13:23:32Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · CISA flags new SD-WAN flaw as actively exploited in attacks · Baitaphish