Chinese APT Targets Indian Banks, Korean Policy Circles

2026-04-21T14:51:43Z10e06fc1777e145a2bf7ae9894b3f2707e8cc686bd78ad0d5467b9b04524e1ed
AI‑vulnerabilitiesAPTBYOVDEDR‑bypassOT/ICSPHIcloud‑securitycredential‑theftdevice‑code‑phishingnation‑stateoauth/tokenpatchingprivacyransomwaresecure‑bootserial‑to‑IPsupply‑chainzero‑day

What happened

A roundup of mid‑April 2026 cyber news: multiple nation‑state APT campaigns (China, North Korea, Russia) targeting banks, cloud environments, and macOS users; active zero‑days and high‑impact flaws (Adobe, Windows, nginx integrations) being exploited or patched; growing cloud credential theft via OAuth/token abuse and AI‑related exposures; widespread OT/ICS and serial‑to‑IP device vulnerabilities; and emerging tactics like device‑code phishing, EDR‑killer BYOVD attacks, and emoji‑based command signaling. Policy and ecosystem shifts (NIST CVE handling changes, new US maritime OT rules, and AI‑v

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
darkreading
Record identifier
10e06fc1777e145a2bf7ae9894b3f2707e8cc686bd78ad0d5467b9b04524e1ed
Enrichment time
2026-04-21T14:51:43Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.