Chinese APT Targets Indian Banks, Korean Policy Circles
2026-04-21T14:51:43Z•10e06fc1777e145a2bf7ae9894b3f2707e8cc686bd78ad0d5467b9b04524e1ed
AI‑vulnerabilitiesAPTBYOVDEDR‑bypassOT/ICSPHIcloud‑securitycredential‑theftdevice‑code‑phishingnation‑stateoauth/tokenpatchingprivacyransomwaresecure‑bootserial‑to‑IPsupply‑chainzero‑day
What happened
A roundup of mid‑April 2026 cyber news: multiple nation‑state APT campaigns (China, North Korea, Russia) targeting banks, cloud environments, and macOS users; active zero‑days and high‑impact flaws (Adobe, Windows, nginx integrations) being exploited or patched; growing cloud credential theft via OAuth/token abuse and AI‑related exposures; widespread OT/ICS and serial‑to‑IP device vulnerabilities; and emerging tactics like device‑code phishing, EDR‑killer BYOVD attacks, and emoji‑based command signaling. Policy and ecosystem shifts (NIST CVE handling changes, new US maritime OT rules, and AI‑v
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- darkreading
- Record identifier
- 10e06fc1777e145a2bf7ae9894b3f2707e8cc686bd78ad0d5467b9b04524e1ed
- Enrichment time
- 2026-04-21T14:51:43Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.