The Good, the Bad and the Ugly in Cybersecurity – Week 16
2026-04-17T20:51:49Z•94df1744add2ed9df24cf71759d8bcb3842be91ed9db8a7bed832b505ec84dad
AD compromiseAI EDRActive exploitationAgingFlyCPU-ZFortiGateNginx exploitationSSO compromiseW3LLcpuid.comidentity-theftmalwarephishingsupply-chainwatering-hole
What happened
SentinelOne blog roundup (Apr 2026) highlights multiple active threats and supply-chain incidents: law enforcement disrupted the W3LL phishing ring; AgingFly malware has been used to steal Ukrainian government data; threat actors exploited an Nginx vulnerability to hijack servers. SentinelOne also describes a CPU‑Z watering‑hole compromise (cpuid.com) that redirected legitimate downloads to attacker infrastructure for ~19 hours, and several supply‑chain attempts (LiteLLM/Axios/Anthropic/Claude) that were autonomously blocked by its AI EDR. Additional coverage warns of FortiGate SSO flaws and S
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sentinelone_blog
- Record identifier
- 94df1744add2ed9df24cf71759d8bcb3842be91ed9db8a7bed832b505ec84dad
- Enrichment time
- 2026-04-17T20:51:49Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.