Backdoored Smart Slider 3 Pro Update Distributed via Compromised Nextend Servers

2026-04-10T07:24:13Z74c0336798e552154a49e135e0ab23942eefb293a9ba581e2ceae8c73d29bd96
adobe-readerandroid-sdkapt28auth-bypasscloud-misconfigurationcrypto-walletsdockerflowisegpu-rowhammeriot-botnetmalwarenpm-pypi-supply-chainplugin-backdoorransomwareremote-code-executionsandbox-bypasssupply-chainupdate-poisoningwordpresszero-day

What happened

The Hacker News digest highlights multiple high-impact incidents: a backdoored Smart Slider 3 Pro update pushed via compromised Nextend servers (plugin supply-chain compromise); a now-patched EngageLab Android SDK flaw that could bypass the Android sandbox and expose ~50M users (including ~30M crypto wallet installs); an active Adobe Reader zero-day exploited since Dec 2025; a maximum-severity Flowise RCE (CVE-2025-59528) with widespread exposure; and a high-severity Docker Engine auth bypass (CVE-2026-34040). Additional notable activity includes new malware families and APT campaigns (LucidR​

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
74c0336798e552154a49e135e0ab23942eefb293a9ba581e2ceae8c73d29bd96
Enrichment time
2026-04-10T07:24:13Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.