EngageLab SDK Flaw Exposed 50M Android Users, Including 30M Crypto Wallets

2026-04-10T01:24:11Z0aa7b27ece9d9a61cd10d40f9880fd9799113cf5d992c73d05fd093990f4e2f7
APT28LucidRookPRISMEXUAT-10362adobe-readerandroidauthz-bypassbotnetchaos-malware','comfyui-exposure','cryptomining-botnet','GPUBREacrypto-walletscve-2025-59528cve-2026-34040dockerengagelabflowisegomalicious-packagesmasjesumobile-sdknpmpypirustsandbox-bypasssupply-chainzero-day

What happened

A wave of high-impact security incidents and active campaigns was reported: a now-patched EngageLab Android SDK flaw potentially exposed ~50M users (including ~30M crypto wallets) by allowing apps to bypass the Android sandbox; Flowise’s CVE-2025-59528 (CVSS 10.0) is under active exploitation with 12,000+ exposed instances enabling RCE; an Adobe Reader zero-day has been exploited in the wild since late 2025; Docker Engine suffers a high-severity AuthZ bypass (CVE-2026-34040, CVSS 8.8); new malware and targeted campaigns include UAT-10362/LucidRook (Lua-based stager) against Taiwanese NGOs, APT

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
0aa7b27ece9d9a61cd10d40f9880fd9799113cf5d992c73d05fd093990f4e2f7
Enrichment time
2026-04-10T01:24:11Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · EngageLab SDK Flaw Exposed 50M Android Users, Including 30M Crypto Wallets · Baitaphish