Ransomware Negotiator Pleads Guilty to BlackCat Scheme
2026-04-22T14:51:45Z•6652818fc54c53d0462aaa6dec3e68a224244f5a28dcac5ab273a3d66a5c8a13
APT41Adobe-zero-dayBYOVDBlackCatBomgarCVE-2026-1731China-APTClickFixEDR-killersGoogle-AntigravityNGINXNorth-KoreaOAuth-tokensOT/ICS-vulnerabilities','WhatsApp-metadata-leak','NIST-CVE-handlVercelWindows-Defenderexploitnginx-uiprompt-injectionransomwareremote-code-executionsandbox-escapeserial-to-IPsupply-chain-riskunpatched
What happened
A batch of high-impact security stories: a critical RCE in Bomgar RMM (CVE-2026-1731) is being actively exploited and highlights supply-chain risk; multiple proof-of-concept exploits are turning Windows Defender into an attacker tool (two remain unpatched); Google patched a critical prompt-injection/sanitization flaw in its Antigravity AI agent that allowed sandbox escape and arbitrary code execution; Adobe fixed an actively exploited zero-day; and Microsoft released a large patch set dominated by privilege-elevation fixes including two zero-days. Threat actor activity remains intense—APT41, A
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- darkreading
- Record identifier
- 6652818fc54c53d0462aaa6dec3e68a224244f5a28dcac5ab273a3d66a5c8a13
- Enrichment time
- 2026-04-22T14:51:45Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.