Infosec bits for 2026 week 16
Heloise Meyer
| April 17, 2026, 11:12 a.m.
Cybersecurity News:
The Phishing-as-a-Service Pipeline: How a Scalable Fraud Ecosystem Is Driving Global Attacks [Flashpoint, Flashpoint]
War Game Exercise Demonstrates How Social Media Manipulation Works [Elizabeth Montalbano, Dark Reading]
The n8n n8mare: How threat actors are misusing AI workflow automation [Sean Gallagher, Talos Intelligence]
Two-Factor Authentication Breaks Free from the Desktop [Arielle Waldman, Dark Reading]
Vulnerabilities & Patches:
Adobe Patches Actively Exploited Acrobat Reader Flaw CVE-2026-34621 [Ravie Lakshmanan, The Hacker News]
Juniper Networks Patches Dozens of Junos OS Vulnerabilities [Ionut Arghire, Security Week]
Patch these critical Fortinet sandbox bugs that let attackers bypass login, run commands over HTTP [Jessica Lyons, The Register]
Cisco Patches Four Critical Identity Services, Webex Flaws Enabling Code Execution [Ravie Lakshmanan, The Hacker News]
Cyberattacks:
Critical Nginx UI auth bypass flaw now actively exploited in the wild [Bill Toulas, Bleeping Computer]
Recently leaked Windows zero-days now exploited in attacks [Sergiu Gatlan, Bleeping Computer]
Tooling:
Little Snitch for Linux shows what your apps are connecting to [Mirko Zorz, Help Net Security]