Week in review: Windows zero-day exploit leaked, Patch Tuesday forecast
2026-04-12T08:51:54Z•fbbda1cddadd38621158e85ffd5030b1028b9fde37d49ae4783dda1bcb2c6da6
ai-securityapiirochromeclickfixclient-side-encryptioncookie-theftdata-brokersdevice-bound-session-credentialsebpfgmail-e2eehealth-datalead-generationlinuxlittle-snitchmacosmalvertisingmalwarepatch-tuesdaypayroll-fraudphishingprivacyseo-poisoningsocial-engineeringstorm-2755vulnerability-disclosure
What happened
This feed summarizes multiple active security developments: a leaked Windows zero-day surfaced in the week-in-review; a ClickFix-style social engineering campaign targeting macOS users via a fake Apple page pushes victims to run malicious commands and install Mac malware; an SEO-poisoning/malvertising campaign (attributed to Microsoft-tracked group Storm-2755) redirects Canadian employees to fake Office 365 flows to hijack payroll deposits; Google expanded Gmail client-side end-to-end encryption to Android/iOS for eligible Enterprise customers; Chrome deployed Device-Bound Session Credentials(
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- helpnetsecurity
- Record identifier
- fbbda1cddadd38621158e85ffd5030b1028b9fde37d49ae4783dda1bcb2c6da6
- Enrichment time
- 2026-04-12T08:51:54Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.