08BA 71D7 84FF F6B7 17A0 FBA6 71BA 1673 5DBA 4C70

Infosec bits for 2026 week 16

Heloise Meyer | April 17, 2026, 11:12 a.m.

Cybersecurity News:

  • The Phishing-as-a-Service Pipeline: How a Scalable Fraud Ecosystem Is Driving Global Attacks [Flashpoint, Flashpoint]
  • War Game Exercise Demonstrates How Social Media Manipulation Works [Elizabeth Montalbano, Dark Reading]
  • The n8n n8mare: How threat actors are misusing AI workflow automation [Sean Gallagher, Talos Intelligence]
  • Two-Factor Authentication Breaks Free from the Desktop [Arielle Waldman, Dark Reading]
  • Vulnerabilities & Patches:

  • Adobe Patches Actively Exploited Acrobat Reader Flaw CVE-2026-34621 [Ravie Lakshmanan, The Hacker News]
  • Juniper Networks Patches Dozens of Junos OS Vulnerabilities [Ionut Arghire, Security Week]
  • Patch these critical Fortinet sandbox bugs that let attackers bypass login, run commands over HTTP [Jessica Lyons, The Register]
  • Cisco Patches Four Critical Identity Services, Webex Flaws Enabling Code Execution [Ravie Lakshmanan, The Hacker News]
  • Cyberattacks:

  • Critical Nginx UI auth bypass flaw now actively exploited in the wild [Bill Toulas, Bleeping Computer]
  • Recently leaked Windows zero-days now exploited in attacks [Sergiu Gatlan, Bleeping Computer]
  • Tooling:

  • Little Snitch for Linux shows what your apps are connecting to [Mirko Zorz, Help Net Security]