The Good, the Bad and the Ugly in Cybersecurity – Week 16

2026-04-17T20:51:49Z94df1744add2ed9df24cf71759d8bcb3842be91ed9db8a7bed832b505ec84dad
AD compromiseAI EDRActive exploitationAgingFlyCPU-ZFortiGateNginx exploitationSSO compromiseW3LLcpuid.comidentity-theftmalwarephishingsupply-chainwatering-hole

What happened

SentinelOne blog roundup (Apr 2026) highlights multiple active threats and supply-chain incidents: law enforcement disrupted the W3LL phishing ring; AgingFly malware has been used to steal Ukrainian government data; threat actors exploited an Nginx vulnerability to hijack servers. SentinelOne also describes a CPU‑Z watering‑hole compromise (cpuid.com) that redirected legitimate downloads to attacker infrastructure for ~19 hours, and several supply‑chain attempts (LiteLLM/Axios/Anthropic/Claude) that were autonomously blocked by its AI EDR. Additional coverage warns of FortiGate SSO flaws and S

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sentinelone_blog
Record identifier
94df1744add2ed9df24cf71759d8bcb3842be91ed9db8a7bed832b505ec84dad
Enrichment time
2026-04-17T20:51:49Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · The Good, the Bad and the Ugly in Cybersecurity – Week 16 · Baitaphish