Serial-to-IP Devices Hide Thousands of Old and New Bugs
2026-04-20T20:51:46Z•66239c8070177a81042dc8e34e9f69e24622f77f779a6b04fb30ee478336fca1
APT28APT41AdobeBYOVDBlueHammerCVE-processClickFixEDR-killerICSMFA-bypassNISTOTWhatsAppWindowsactive-exploitationcloud-credentialsdevice-code-phishingmacOSnginxnginx-uiprivacyransomwaresupply-chainvulnerabilitieszero-day
What happened
A set of DarkReading reports (Apr 2026) highlights broad, high-impact security trends and active threats: thousands of vulnerable OT/serial-to-IP devices and industrial controllers, multiple actively exploited zero-days (Adobe, Windows/BlueHammer) and a critical nginx-ui MCP integration flaw, ongoing APT campaigns (APT41 targeting cloud credentials; APT28 router DNS manipulation), macOS-focused ClickFix implants from DPRK actors, and rising tactics that undermine authentication (device‑code phishing) and endpoint defenses (EDR‑killer/BYOVD ecosystem). Privacy and data‑leak issues include Whats
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- darkreading
- Record identifier
- 66239c8070177a81042dc8e34e9f69e24622f77f779a6b04fb30ee478336fca1
- Enrichment time
- 2026-04-20T20:51:46Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.