Live Threats
[CVE-2026-1234]Windows CLFS Driver zero-day — privilege escalation to SYSTEM, CISA KEV confirmed, patch immediately|
[CVE-2026-0891]Fortinet FortiOS authentication bypass — unauthenticated admin access, active exploitation in the wild|
[CVE-2026-2201]Palo Alto PAN-OS command injection — remote code execution on firewall management plane, CISA KEV listed|
[PATCH]Microsoft April 2026 Patch Tuesday — 147 CVEs addressed including 3 zero-days, deploy immediately|
[BREACH]Healthcare sector breach — 2.3M patient records exposed, PHI including SSNs and medical histories compromised|
[CVE-2026-1887]Chrome V8 type confusion RCE — remote code execution via malicious web page, update Chrome immediately|
[COMPLIANCE]PCI DSS 4.0.1 MFA deadline — mandatory multi-factor authentication enforcement now in effect for all merchants|
[CVE-2026-3310]Cisco IOS XE privilege escalation — authenticated users gain root on affected switches and routers, patch now|
[RANSOMWARE]LockBit 4.0 SMB campaign — RDP brute-force targeting small businesses, double-extortion, 72-hour ransom window|
[ADVISORY]Adobe Acrobat PDF phishing wave — malicious PDFs bypassing email filters, credential harvesting at scale|
[CVE-2026-1234]Windows CLFS Driver zero-day — privilege escalation to SYSTEM, CISA KEV confirmed, patch immediately|
[CVE-2026-0891]Fortinet FortiOS authentication bypass — unauthenticated admin access, active exploitation in the wild|
[CVE-2026-2201]Palo Alto PAN-OS command injection — remote code execution on firewall management plane, CISA KEV listed|
[PATCH]Microsoft April 2026 Patch Tuesday — 147 CVEs addressed including 3 zero-days, deploy immediately|
[BREACH]Healthcare sector breach — 2.3M patient records exposed, PHI including SSNs and medical histories compromised|
[CVE-2026-1887]Chrome V8 type confusion RCE — remote code execution via malicious web page, update Chrome immediately|
[COMPLIANCE]PCI DSS 4.0.1 MFA deadline — mandatory multi-factor authentication enforcement now in effect for all merchants|
[CVE-2026-3310]Cisco IOS XE privilege escalation — authenticated users gain root on affected switches and routers, patch now|
[RANSOMWARE]LockBit 4.0 SMB campaign — RDP brute-force targeting small businesses, double-extortion, 72-hour ransom window|
[ADVISORY]Adobe Acrobat PDF phishing wave — malicious PDFs bypassing email filters, credential harvesting at scale|
View All
The MGM Hackers Are Back, SAP Has a Perfect 10 Vulnerability & AI Phishing Now Beats MFA
All Security News|ISSUE #18April 21 – April 27, 2026
Print / PDF

The MGM Hackers Are Back, SAP Has a Perfect 10 Vulnerability & AI Phishing Now Beats MFA

Scattered Spider is targeting your help desk. A CVSS 10.0 zero-day is dropping webshells on SAP servers. And the phishing kit on your employees' screens right now? It already has their session token.

#Scattered Spider#SAP#Ransomware#CISA#Social Engineering#Chrome
3
Critical
2
High Severity
1
Patch Updates
1
Breach Alerts
TL;DR — This Week's Key Takeaways

Scattered Spider is back targeting US retailers and hospitality with advanced social engineering. SAP NetWeaver has a critical zero-day under active exploitation — patch immediately. CISA released a free ransomware response playbook tailored for SMBs. Google Chrome and Android both received emergency security patches this week.

Trending This Week — Act Now
SMBs most at risk

Why these matter for your business: Both threats specifically target SMBs and require immediate action — social engineering attacks and MFA bypass techniques are being used together in coordinated campaigns this week.

Share This
SEVERITY:CRITICALHIGHMEDIUMLOWINFO

CLICK ANY ARTICLE TO READ THE FULL STORY

THREAT INTELCRITICAL

Scattered Spider Returns: Retail & Hospitality Firms Hit with Advanced Social Engineering

The notorious Scattered Spider threat group — responsible for the 2023 MGM Resorts and Caesars Entertainment breaches — has resumed operations targeting US retail and hospitality companies using AI-enhanced vishing and help desk impersonation attacks.

Read Full Article
5 min read
BREACHCRITICAL

SAP NetWeaver Zero-Day (CVE-2026-2030): Unauthenticated RCE Under Active Exploitation

SAP released an emergency patch for CVE-2026-2030, a critical unauthenticated remote code execution vulnerability in SAP NetWeaver Application Server Java. CVSS score 10.0. Attackers are actively deploying webshells on unpatched systems.

Read Full Article
4 min read
ADVISORYINFO

CISA Releases Free Ransomware Response Playbook Tailored for Small Businesses

CISA published a comprehensive, step-by-step ransomware response playbook specifically designed for small and medium-sized businesses without dedicated security teams. The free guide covers detection, containment, recovery, and reporting.

Read Full Article
4 min read
PATCH UPDATECRITICAL

Google Pushes Emergency Patches for Chrome and Android — Update Both Now

Google released out-of-band security updates for Chrome (CVE-2026-2211) and Android (CVE-2026-2198), both rated Critical and confirmed exploited in the wild. Chrome's flaw enables sandbox escape; Android's allows privilege escalation without user interaction.

Read Full Article
3 min read
COMPLIANCEHIGH

FTC Safeguards Rule: What Every SMB Needs to Know

The FTC Safeguards Rule isn't just for banks. Auto dealers, tax preparers, accountants, mortgage brokers, and dozens of other small businesses are legally required to have a comprehensive information security program — or face penalties up to $51,744 per day. Here's exactly who must comply and what the 9 required elements are.

Read Full Article
14 min read
THREAT INTELHIGH

AI-Powered Phishing Kits Now Bypassing MFA in Real Time — What SMBs Must Know

Security researchers documented a new generation of adversary-in-the-middle (AiTM) phishing kits using AI to generate convincing lure pages in real time and bypass SMS and app-based MFA. Over 40,000 businesses targeted in Q1 2026.

Read Full Article
4 min read

Need Help Addressing These Threats?

Our team monitors these vulnerabilities and can help you patch, assess, and protect your business before attackers strike.

Talk with Us