Apple Patches Exploited Notification Flaw, (Thu, Apr 23rd)
2026-04-23T13:23:51Z•6db6073733a6a0d5b80dc68244f283984eb71801d8b6c8fa2110c59ddfe7b3d8
.wavCVE-2026-28950appleaudio-malwarecredential-harvestingepssexploitediosipadoslumma-stealermalwarenotification-servicespatchsans-iscsectop-rattelegramvulnerability-management
What happened
SANS ISC diary roundup: Apple released iOS/iPadOS 26.4.2 and 18.7.8 to address an actively exploited Notification Services vulnerability (CVE-2026-28950). Other entries cover malware trends and incidents including .wav files used to deliver payloads, Telegram tdata credential-harvesting from a honeypot incident, a Lumma Stealer infection paired with Sectop RAT, and guidance on handling large numbers of new CVEs using EPSS.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- 6db6073733a6a0d5b80dc68244f283984eb71801d8b6c8fa2110c59ddfe7b3d8
- Enrichment time
- 2026-04-23T13:23:51Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.