Exploits Turn Windows Defender into Attacker Tool
2026-04-21T20:51:40Z•3130f9d435888063ea2b742e2b761ed0b7cac4d648b727373a5c01e1f8020e4f
APT41AdobeBomgar RMMCVE-2026-1731EDR-killer/BYOVDGoogleMicrosoftOAuth token theftOT/ICS vulnerabilitiesSalesforceWhatsApp metadata leakWindows Defenderagentic AIcloud credential theftdevice-code phishingprompt injectionproof‑of‑concept exploitsransomwareremote code executionsandbox escapesecure boot certificateserial-to-IP devicessupply chain riskunpatched vulnerabilitieszero-day
What happened
DarkReading digest (Apr 2026) highlighting a run of active, high-impact vulnerabilities and threat activity: proof‑of‑concept exploits are being used to abuse Windows Defender (including two unpatched issues); a critical RCE in Bomgar RMM (CVE-2026-1731) is being exploited for supply‑chain and ransomware spread; Google fixed a sandbox‑escape RCE in an agentic AI filesystem tool; Microsoft and Salesforce patched prompt‑injection/data‑leak flaws in AI agents; Adobe fixed an actively exploited PDF zero‑day; APT41 is deploying a stealth backdoor to harvest cloud credentials; stolen OAuth tokens at
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- darkreading
- Record identifier
- 3130f9d435888063ea2b742e2b761ed0b7cac4d648b727373a5c01e1f8020e4f
- Enrichment time
- 2026-04-21T20:51:40Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.