Ransomware Negotiator Pleads Guilty to BlackCat Scheme

2026-04-22T14:51:45Z6652818fc54c53d0462aaa6dec3e68a224244f5a28dcac5ab273a3d66a5c8a13
APT41Adobe-zero-dayBYOVDBlackCatBomgarCVE-2026-1731China-APTClickFixEDR-killersGoogle-AntigravityNGINXNorth-KoreaOAuth-tokensOT/ICS-vulnerabilities','WhatsApp-metadata-leak','NIST-CVE-handlVercelWindows-Defenderexploitnginx-uiprompt-injectionransomwareremote-code-executionsandbox-escapeserial-to-IPsupply-chain-riskunpatched

What happened

A batch of high-impact security stories: a critical RCE in Bomgar RMM (CVE-2026-1731) is being actively exploited and highlights supply-chain risk; multiple proof-of-concept exploits are turning Windows Defender into an attacker tool (two remain unpatched); Google patched a critical prompt-injection/sanitization flaw in its Antigravity AI agent that allowed sandbox escape and arbitrary code execution; Adobe fixed an actively exploited zero-day; and Microsoft released a large patch set dominated by privilege-elevation fixes including two zero-days. Threat actor activity remains intense—APT41, A

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
darkreading
Record identifier
6652818fc54c53d0462aaa6dec3e68a224244f5a28dcac5ab273a3d66a5c8a13
Enrichment time
2026-04-22T14:51:45Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.