Iran claims US used backdoors to knock out networking equipment during war
2026-04-21T07:23:59Z•001b42dda2f6b0be49077cc92111c0966cb925716d5f8e5cfbfb144121637f8c
CISAKEVactive-exploitationai-securityanthropicapache-activemqbrowser-fingerprintingcredential-compromisecritical-vulnerabilitiesdata-leakexcelfortinetgithub-agentsmacos-malwarepatchingprompt-injectionransomwaresupply-chainvulnerability-managementzero-day
What happened
A broad set of security stories: CISA says a 13‑year‑old Apache ActiveMQ flaw is under active exploitation and on the KEV list; a 17‑year‑old critical Excel vulnerability is being actively abused; two critical Fortinet sandbox bugs allow auth bypass and remote command execution. Multiple AI-related risks surfaced — Anthropic’s MCP design flaw potentially endangers many servers, AI models (including Claude/Mythos) are being used to find or craft exploits, prompt‑injection and GitHub‑agent attacks can steal tokens/credentials, and Claude Desktop/agent behaviors raise privacy and consent concerns
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- theregister_security
- Record identifier
- 001b42dda2f6b0be49077cc92111c0966cb925716d5f8e5cfbfb144121637f8c
- Enrichment time
- 2026-04-21T07:23:59Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.