CISA flags new SD-WAN flaw as actively exploited in attacks
2026-04-21T13:23:32Z•7aae96ae233fcc01a43cc5f8e35baa20b490c0eaf9fdfd87d579cc43a1f7192b
ALPHVAndroid malwareApache ActiveMQBlackCatCISACatalystGentlemen ransomwareHandyPayKelpDAOLazarusMicrosoft TeamsNFC payment theftNGateSD-WANSystemBCVercelactive exploitationbotnetcode injectioncrypto theftdata breachhelpdesk impersonationmalicious app storeransomwarewallet phishing
What happened
Multiple high-risk security incidents and actively exploited vulnerabilities reported: CISA issued an urgent four-day remediation directive for a Catalyst SD‑WAN Manager flaw being actively exploited; Shadowserver found over 6,400 public Apache ActiveMQ servers vulnerable to an ongoing high‑severity code‑injection exploit; a former ransomware negotiator pleaded guilty for BlackCat/ALPHV attacks; NGate Android malware is trojanizing the HandyPay NFC app to steal payment card data; KelpDAO suffered a ~$290M DeFi heist likely tied to North Korean Lazarus actors; 26 malicious crypto‑wallet apps (e
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 7aae96ae233fcc01a43cc5f8e35baa20b490c0eaf9fdfd87d579cc43a1f7192b
- Enrichment time
- 2026-04-21T13:23:32Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.