Week in review: Windows zero-day exploit leaked, Patch Tuesday forecast
2026-04-12T14:51:48Z•9838aa3f3f0083a8363ddcf96375cd81ae8d5ca2d4ad72df98c66a969af1f3de
ai-assisted securityaitmapiiro clichrome dbscclickfixcookie theft mitigationdata-brokersebpfgmail e2eejamflead-gen privacylittle snitch linuxmac malwaremalvertisingpatch-tuesdaypayroll fraudseo poisoningstorm-2755vibe-huntingwindows zero-day
What happened
This week’s roundup covers a mix of active threats, product security updates, and privacy research. Notable items: a Windows zero-day exploit was leaked (raising urgent Patch Tuesday implications); a ClickFix social-engineering campaign is delivering Mac malware via a fake Apple page; Microsoft-tracked group Storm-2755 is using SEO poisoning, malvertising and AiTM techniques to hijack Canadian payrolls; Google rolled Gmail client-side E2EE out to mobile and shipped Device-Bound Session Credentials (DBSC) in Chrome to mitigate cookie theft; Objective Development released Little Snitch for Linux
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- helpnetsecurity
- Record identifier
- 9838aa3f3f0083a8363ddcf96375cd81ae8d5ca2d4ad72df98c66a969af1f3de
- Enrichment time
- 2026-04-12T14:51:48Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.