A week in security (April 20 – April 26)

2026-04-28T08:52:07Za21a054453c26e907cf4141b3949f6250d854073c96874516ae5f18c152b9875
Alibabaai-abuseandroid-privacyanthropic-mythosbooking.com-breachchild-safetycredential-theftdata-breachfake-installerios-vulnerabilitymalwaremedical-data-leaknotification-exposurephishingpush-notifications-abuseransomwareremote-access-trojansignaltech-support-scamtrojanweekly-roundup

What happened

Malwarebytes Labs weekly roundup (April 20–26, 2026) covering multiple high-impact security stories: a dataset containing medical records for ~500,000 UK Biobank volunteers listed for sale on Alibaba; an iOS vulnerability that allowed recovery of deleted notifications (including Signal previews); numerous trojanized/fake installers and web lures (fake TradingView AI, Google Antigravity, Slack, DHL-themed phishing) that deliver browser/desktop takeover, credential theft, remote-access trojans and ransomware; exploitation of legitimate notifications for tech-support scams; the Pushpaganda AI‑dr

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
malwarebytes_labs
Record identifier
a21a054453c26e907cf4141b3949f6250d854073c96874516ae5f18c152b9875
Enrichment time
2026-04-28T08:52:07Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.