Chinese APT Abuses Multiple Cloud Tools to Spy on Mongolia

2026-04-23T14:51:48Z277c8a9a2b7914df2cb971cb5249979913a82a5798e12d6b377e44b20911a1b4
CVE-2026-1731adobe-zero-dayai-securityanthropicaptapt41bomgarchinacloud-espionagedprkedr-killer-byovd','phishing','device-code-phishing','oauth-tokengentlemen-ransomwaregoogle-antigravitymcp-integration-flawmicrosoft-copilotnginxot-icsprompt-injectionransomwarercesalesforce-agentforceserial-to-ipsupply-chain-riskwindows-defenderzero-day

What happened

This DarkReading feed highlights a wave of high-risk activity: China-linked APTs abusing cloud collaboration tools for espionage and APT41 deploying stealthy cloud backdoors; multiple actively exploited vulnerabilities and zero-days (including a critical Bomgar RCE, Adobe zero-day, and Windows Defender exploits); AI/agent security failures (Anthropic memory flaw, prompt-injection/data-leak bugs in Microsoft and Salesforce, Google Antigravity RCE); growing ransomware and supply-chain threats; OT/ICS and device vulnerabilities (serial-to-IP, NGINX MCP integration flaw); and evolving phishing and

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
darkreading
Record identifier
277c8a9a2b7914df2cb971cb5249979913a82a5798e12d6b377e44b20911a1b4
Enrichment time
2026-04-23T14:51:48Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.