Critical Cisco IMC auth bypass gives attackers Admin access
2026-04-02T13:23:32Z•8ad5473a9ef4208330c9d2296357792a904d6b64603e90bf862fdea96c19a3bf
Android malwareCisco IMCCrystalRATDarkSwordEvilTokensF5 BIG‑IP APMGoogle Chrome zero‑dayGoogle DriveNoVoiceTrueConfWindows 11 updateauthentication bypassdevice‑code phishingexposed instancesiOS 18malware‑as‑a‑serviceransomware detectionremote code executionsupply‑chain attackzero‑day
What happened
Multiple high-impact security stories: Cisco patched a critical Integrated Management Controller (IMC) authentication bypass that could give attackers Admin access; Shadowserver found over 14,000 F5 BIG‑IP APM instances still exposed to an actively exploited critical RCE; attackers are exploiting a TrueConf zero‑day to push malicious updates; new malware and services (CrystalRAT, EvilTokens) add RAT/stealer/keylogging and device‑code phishing capabilities; NoVoice Android apps on Google Play infected ~2.3M devices; Apple broadened iOS 18 update coverage to block DarkSword exploits; Google rem
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 8ad5473a9ef4208330c9d2296357792a904d6b64603e90bf862fdea96c19a3bf
- Enrichment time
- 2026-04-02T13:23:32Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.