Cybersecurity M&A Roundup: 33 Deals Announced in April 2026

2026-05-04T13:24:09Z43979de9f607c8de49a2b979343353fd3e53be17ed5d4cff911cde59c6b06f9a
AI on classified systemsAI-assisted phishingBluekitCISA KEVCVE-2026-41940Copy FailDigiCertGoogleInstructureLinux vulnerabilityNSA tool vulnerabilityOpenAIScattered SpiderUS DoDaccount securitybug bountycPanelcredential theftdata breachmalwaremass compromisephishing kitproof-of-conceptsupport portal compromisezero-day

What happened

This SecurityWeek roundup covers multiple high-impact cybersecurity developments: DigiCert revoked certificates after a support-portal compromise in which malware was delivered via a customer chat channel and an analyst’s system was infected; exploitation of the Linux “Copy Fail” vulnerability has begun and was added to CISA’s KEV list (Microsoft observed limited exploitation, mainly PoC testing); more than 40,000 servers have been compromised in active cPanel exploitation likely targeting CVE-2026-41940 (a recently patched zero-day leading to administrative access); edtech vendor Instructure披

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityweek
Record identifier
43979de9f607c8de49a2b979343353fd3e53be17ed5d4cff911cde59c6b06f9a
Enrichment time
2026-05-04T13:24:09Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Cybersecurity M&A Roundup: 33 Deals Announced in April 2026 · Baitaphish