More Cisco SD-WAN bugs battered in attacks

2026-04-21T19:24:02Zb020131fcfee3bfded08dfdcd47722f1579b47384a274279b6b40a802abbceac
AdaptavistAnthropicApache ActiveMQAppleScript infostealerCISACisco SD‑WANClaudeClickFixKEVMCP design flawOAuth abuseSIM swapVercelWindows Serverbrowser cookiescrypto walletsmacOSout-of-band updateprompt injectionransomwarescattered spider

What happened

Aggregated security news: CISA warned that three Cisco Catalyst SD‑WAN Manager vulnerabilities are under active attack and gave federal agencies four days to patch; CISA also placed a long‑standing Apache ActiveMQ flaw on the KEV list with active exploitation. Vercel reported customer credential compromise via OAuth abuse and a pilfered employee account (attackers reportedly used AI to move quickly). A macOS ClickFix campaign delivers an AppleScript infostealer that harvests credentials, session cookies, browser data and cryptocurrency wallets. Additional items include Adaptavist breach and a

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
theregister_security
Record identifier
b020131fcfee3bfded08dfdcd47722f1579b47384a274279b6b40a802abbceac
Enrichment time
2026-04-21T19:24:02Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · More Cisco SD-WAN bugs battered in attacks · Baitaphish