Microsoft drops its second-largest monthly batch of defects on record

2026-04-14T20:51:43Zdd277b8380ef7eb73ed8a324551cf7b37f4b38744da40fce43dbc0e0b5679b7f
actively-exploitedai-securityapt28axiosblack-bastacensyscisaclaude-mythoscommercecritical-infrastructureexport-controlsfbiiranian-operationsmicrosoftopenaipatch-tuesdayquantum-proofingransomwarerouter-takedownsharepointsocial-engineeringsupply-chainvulnerabilityzero-day

What happened

CyberScoop roundup: Microsoft’s April Patch Tuesday is its second-largest on record and includes an actively exploited zero-day in Microsoft Office SharePoint that can expose and modify disclosed information. Other notable stories: former Black Basta affiliates are running a fast-scale social-engineering intrusion campaign; OpenAI’s macOS apps require updates after an Axios supply‑chain compromise of a popular library; Censys warns an Iranian campaign has put ~3,900 U.S. energy, water and government-facing devices at risk; the FBI disrupted APT28 by taking down compromised routers; and several

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cyberscoop
Record identifier
dd277b8380ef7eb73ed8a324551cf7b37f4b38744da40fce43dbc0e0b5679b7f
Enrichment time
2026-04-14T20:51:43Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.