Backdoored Smart Slider 3 Pro Update Distributed via Compromised Nextend Servers
2026-04-10T07:24:13Z•74c0336798e552154a49e135e0ab23942eefb293a9ba581e2ceae8c73d29bd96
adobe-readerandroid-sdkapt28auth-bypasscloud-misconfigurationcrypto-walletsdockerflowisegpu-rowhammeriot-botnetmalwarenpm-pypi-supply-chainplugin-backdoorransomwareremote-code-executionsandbox-bypasssupply-chainupdate-poisoningwordpresszero-day
What happened
The Hacker News digest highlights multiple high-impact incidents: a backdoored Smart Slider 3 Pro update pushed via compromised Nextend servers (plugin supply-chain compromise); a now-patched EngageLab Android SDK flaw that could bypass the Android sandbox and expose ~50M users (including ~30M crypto wallet installs); an active Adobe Reader zero-day exploited since Dec 2025; a maximum-severity Flowise RCE (CVE-2025-59528) with widespread exposure; and a high-severity Docker Engine auth bypass (CVE-2026-34040). Additional notable activity includes new malware families and APT campaigns (LucidR
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 74c0336798e552154a49e135e0ab23942eefb293a9ba581e2ceae8c73d29bd96
- Enrichment time
- 2026-04-10T07:24:13Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.