Exploits Turn Windows Defender into Attacker Tool

2026-04-21T20:51:40Z3130f9d435888063ea2b742e2b761ed0b7cac4d648b727373a5c01e1f8020e4f
APT41AdobeBomgar RMMCVE-2026-1731EDR-killer/BYOVDGoogleMicrosoftOAuth token theftOT/ICS vulnerabilitiesSalesforceWhatsApp metadata leakWindows Defenderagentic AIcloud credential theftdevice-code phishingprompt injectionproof‑of‑concept exploitsransomwareremote code executionsandbox escapesecure boot certificateserial-to-IP devicessupply chain riskunpatched vulnerabilitieszero-day

What happened

DarkReading digest (Apr 2026) highlighting a run of active, high-impact vulnerabilities and threat activity: proof‑of‑concept exploits are being used to abuse Windows Defender (including two unpatched issues); a critical RCE in Bomgar RMM (CVE-2026-1731) is being exploited for supply‑chain and ransomware spread; Google fixed a sandbox‑escape RCE in an agentic AI filesystem tool; Microsoft and Salesforce patched prompt‑injection/data‑leak flaws in AI agents; Adobe fixed an actively exploited PDF zero‑day; APT41 is deploying a stealth backdoor to harvest cloud credentials; stolen OAuth tokens at

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
darkreading
Record identifier
3130f9d435888063ea2b742e2b761ed0b7cac4d648b727373a5c01e1f8020e4f
Enrichment time
2026-04-21T20:51:40Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Exploits Turn Windows Defender into Attacker Tool · Baitaphish