This 24-hour period ending April 6, 2026, is marked by urgent threats, including the active exploitation of a critical Fortinet zero-day (CVE-2026-35616) and a new Windows LPE zero-day leak. Microsoft reports the Medusa ransomware group is now weaponizing vulnerabilities within 24 hours of disclosure, while a separate AI-powered phishing campaign compromises hundreds of M365 organizations daily by abusing the device code flow. Other major incidents include a critical Cisco IMC flaw, an Iranian password-spraying campaign in the Middle East, and a cyberattack on toy giant Hasbro.
Help others stay informed about cybersecurity threats