Microsoft drops its second-largest monthly batch of defects on record
2026-04-14T20:51:43Z•dd277b8380ef7eb73ed8a324551cf7b37f4b38744da40fce43dbc0e0b5679b7f
actively-exploitedai-securityapt28axiosblack-bastacensyscisaclaude-mythoscommercecritical-infrastructureexport-controlsfbiiranian-operationsmicrosoftopenaipatch-tuesdayquantum-proofingransomwarerouter-takedownsharepointsocial-engineeringsupply-chainvulnerabilityzero-day
What happened
CyberScoop roundup: Microsoft’s April Patch Tuesday is its second-largest on record and includes an actively exploited zero-day in Microsoft Office SharePoint that can expose and modify disclosed information. Other notable stories: former Black Basta affiliates are running a fast-scale social-engineering intrusion campaign; OpenAI’s macOS apps require updates after an Axios supply‑chain compromise of a popular library; Censys warns an Iranian campaign has put ~3,900 U.S. energy, water and government-facing devices at risk; the FBI disrupted APT28 by taking down compromised routers; and several
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- cyberscoop
- Record identifier
- dd277b8380ef7eb73ed8a324551cf7b37f4b38744da40fce43dbc0e0b5679b7f
- Enrichment time
- 2026-04-14T20:51:43Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.