Patch Tuesday, April 2026 Edition
2026-04-16T13:23:38Z•c6b00573091806d052e3f9041f4e9283cc1dcfbb1a3a511bc361509d717f33cf
adobe readeraisurubluehammercanisterwormchrome zero-dayddosgoogle chromeiot botnetiran-backed actors','ransomware','revil','gandcrab','unkn','doxjackskidkimwolfmicrosoftmicrosoft office tokensmilitary intelligencemossadpatch tuesdayremote code executionrouter vulnerabilitiesrussiasharepointstrykertoken theftwindows defenderwiperzero-day
What happened
KrebsOnSecurity roundup covering multiple high-impact incidents: Microsoft’s April Patch Tuesday addressed 167 vulnerabilities including a SharePoint Server zero-day and a publicly disclosed Windows Defender flaw nicknamed “BlueHammer”; Google fixed a fourth Chrome zero-day of 2026 and Adobe issued an emergency Reader RCE patch. Separately, Russian military-linked actors exploited known router vulnerabilities to harvest Microsoft Office authentication tokens from over 18,000 networks. Law enforcement doxxed Daniil Shchukin (“UNKN”), alleged former leader of REvil/GandCrab. New destructive and勒
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- krebs_on_security
- Record identifier
- c6b00573091806d052e3f9041f4e9283cc1dcfbb1a3a511bc361509d717f33cf
- Enrichment time
- 2026-04-16T13:23:38Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.