Patch Tuesday, April 2026 Edition
2026-04-18T01:23:41Z•a7a326c5cb954a0462f5bab183736c18b002d50a4cdea6d347706fca422ae8f4
adobe-readeraisurubluehammercredential-theftddosdoxing','canisterworm','wiper','iran','stryker','phishing-as-a‑-gandcrabgoogle-chromeiot-botnetjackskidkimwolfmicrosoftmicrosoft-office-tokensmossadpatch-tuesdayransomwarercerevilrouter-exploitrussiarussian-military-intelsharepointtoken-harvestingwindows-defenderzero-day
What happened
KrebsOnSecurity's April 2026 coverage highlights multiple high-impact incidents: Microsoft released fixes for 167 vulnerabilities (including a SharePoint Server zero‑day and a publicly disclosed Windows Defender flaw dubbed “BlueHammer”); Google Chrome and Adobe Reader received emergency patches for actively exploited zero‑days/RCEs. Separately, Russian military-linked actors harvested Microsoft Office authentication tokens at scale by exploiting known flaws in older routers (affecting >18,000 networks); U.S./Canadian/German authorities disrupted four massive IoT botnets (Aisuru, Kimwolf, Jack
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- krebs_on_security
- Record identifier
- a7a326c5cb954a0462f5bab183736c18b002d50a4cdea6d347706fca422ae8f4
- Enrichment time
- 2026-04-18T01:23:41Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.