Iran claims US used backdoors to knock out networking equipment during war

2026-04-21T07:23:59Z001b42dda2f6b0be49077cc92111c0966cb925716d5f8e5cfbfb144121637f8c
CISAKEVactive-exploitationai-securityanthropicapache-activemqbrowser-fingerprintingcredential-compromisecritical-vulnerabilitiesdata-leakexcelfortinetgithub-agentsmacos-malwarepatchingprompt-injectionransomwaresupply-chainvulnerability-managementzero-day

What happened

A broad set of security stories: CISA says a 13‑year‑old Apache ActiveMQ flaw is under active exploitation and on the KEV list; a 17‑year‑old critical Excel vulnerability is being actively abused; two critical Fortinet sandbox bugs allow auth bypass and remote command execution. Multiple AI-related risks surfaced — Anthropic’s MCP design flaw potentially endangers many servers, AI models (including Claude/Mythos) are being used to find or craft exploits, prompt‑injection and GitHub‑agent attacks can steal tokens/credentials, and Claude Desktop/agent behaviors raise privacy and consent concerns

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
theregister_security
Record identifier
001b42dda2f6b0be49077cc92111c0966cb925716d5f8e5cfbfb144121637f8c
Enrichment time
2026-04-21T07:23:59Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Iran claims US used backdoors to knock out networking equipment during war · Baitaphish