Patch Tuesday, April 2026 Edition

2026-04-18T13:23:26Zd525457befbb060a0560ca025955805525f648a245fdda61e25f44162cb23cd7
APTAdobe ReaderAisuruBlueHammerCanisterWormDDoSDaniil ShchukinGandCrabGoogle ChromeIoT botnetsIran-targeted attacksJackSkidKimwolfMicrosoft Office token theftMicrosoft Patch TuesdayMossadREvilRussian military intelligenceSharePointStryker incident','starkiller','phishing-as-a-service','MFA-reléUNKNWindows Defenderrouter compromisewiper malwarezero-day

What happened

A collection of KrebsOnSecurity reports from early 2026 covering multiple high-impact cyber events: Microsoft’s April Patch Tuesday fixed 167 vulnerabilities (including a SharePoint zero-day and a publicly disclosed Windows Defender flaw called “BlueHammer”), Google Chrome and Adobe issued emergency zero-day fixes, and March had 77 Microsoft fixes. Russian military-linked actors exploited legacy router flaws to mass-harvest Microsoft Office authentication tokens from over 18,000 networks. German authorities identified and doxxed Daniil Shchukin (“UNKN”), alleged leader of GandCrab and REvil. A

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
krebs_on_security
Record identifier
d525457befbb060a0560ca025955805525f648a245fdda61e25f44162cb23cd7
Enrichment time
2026-04-18T13:23:26Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.