EngageLab SDK Flaw Exposed 50M Android Users, Including 30M Crypto Wallets
2026-04-10T01:24:11Z•0aa7b27ece9d9a61cd10d40f9880fd9799113cf5d992c73d05fd093990f4e2f7
APT28LucidRookPRISMEXUAT-10362adobe-readerandroidauthz-bypassbotnetchaos-malware','comfyui-exposure','cryptomining-botnet','GPUBREacrypto-walletscve-2025-59528cve-2026-34040dockerengagelabflowisegomalicious-packagesmasjesumobile-sdknpmpypirustsandbox-bypasssupply-chainzero-day
What happened
A wave of high-impact security incidents and active campaigns was reported: a now-patched EngageLab Android SDK flaw potentially exposed ~50M users (including ~30M crypto wallets) by allowing apps to bypass the Android sandbox; Flowise’s CVE-2025-59528 (CVSS 10.0) is under active exploitation with 12,000+ exposed instances enabling RCE; an Adobe Reader zero-day has been exploited in the wild since late 2025; Docker Engine suffers a high-severity AuthZ bypass (CVE-2026-34040, CVSS 8.8); new malware and targeted campaigns include UAT-10362/LucidRook (Lua-based stager) against Taiwanese NGOs, APT
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 0aa7b27ece9d9a61cd10d40f9880fd9799113cf5d992c73d05fd093990f4e2f7
- Enrichment time
- 2026-04-10T01:24:11Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.