Cybersecurity M&A Roundup: 33 Deals Announced in April 2026
2026-05-04T13:24:09Z•43979de9f607c8de49a2b979343353fd3e53be17ed5d4cff911cde59c6b06f9a
AI on classified systemsAI-assisted phishingBluekitCISA KEVCVE-2026-41940Copy FailDigiCertGoogleInstructureLinux vulnerabilityNSA tool vulnerabilityOpenAIScattered SpiderUS DoDaccount securitybug bountycPanelcredential theftdata breachmalwaremass compromisephishing kitproof-of-conceptsupport portal compromisezero-day
What happened
This SecurityWeek roundup covers multiple high-impact cybersecurity developments: DigiCert revoked certificates after a support-portal compromise in which malware was delivered via a customer chat channel and an analyst’s system was infected; exploitation of the Linux “Copy Fail” vulnerability has begun and was added to CISA’s KEV list (Microsoft observed limited exploitation, mainly PoC testing); more than 40,000 servers have been compromised in active cPanel exploitation likely targeting CVE-2026-41940 (a recently patched zero-day leading to administrative access); edtech vendor Instructure披
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityweek
- Record identifier
- 43979de9f607c8de49a2b979343353fd3e53be17ed5d4cff911cde59c6b06f9a
- Enrichment time
- 2026-05-04T13:24:09Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.