🏥 Medical Device Giant Medtronic Confirms Data Exfiltration Breach
Medtronic, the world’s largest medical device manufacturer, announced on April 24 that hackers breached a limited portion of its network and exfiltrated data.While the company stated that corporate IT, manufacturing, and hospital customer networks are segmented and remain unaffected, it is still investigating whether personal or protected health information (PHI) was accessed during the incident.
📉 Oracle Releases Massive April 2026 Update Addressing 450+ Vulnerabilities
Oracle’s April 2026 Critical Patch Update (CPU) addressed over 450 unique vulnerabilities across 28 product families.Notably, more than 300 of these flaws are remotely exploitable without authentication, including several critical defects in Oracle Communications and Financial Services Applications. This release follows a recent emergency patch for a remote code execution flaw in Identity Manager.
https://www.securityweek.com/oracle-patches-450-vulnerabilities-with-april-2026-cpu/
🍏 ‘DarkSword’ iPhone Zero-Day Framework Uncovered in Global Attacks
Security researchers have identified a sophisticated iPhone exploit framework called “DarkSword” being used in watering hole attacks across multiple countries.The exploit silently siphons iCloud Keychain passwords, messages, and cryptocurrency wallet contents from unpatched devices before erasing its own tracks; current estimates suggest over 200 million iPhones remain vulnerable to this specific toolset.
https://www.techrepublic.com/article/news-top-cyberattacks-2026-so-far/
🛡️ CISA Adds New Cisco and PaperCut Flaws to Exploited Vulnerabilities Catalog
The Cybersecurity and Infrastructure Security Agency (CISA) added eight new vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog this week.The list includes critical flaws in Cisco Catalyst SD-WAN Manager (CVE-2026-20133) and PaperCut NG/MF (CVE-2023-27351), signaling that threat actors are actively leveraging these bugs to bypass authentication and expose sensitive information.
💻 Microsoft SharePoint Zero-Day CVE-2026-32201 Widely Exposed
New research indicates that a recently disclosed medium-severity spoofing vulnerability in Microsoft SharePoint is currently exposed across approximately 1,370 IP addresses worldwide.Tracked as CVE-2026-32201, the flaw stems from improper input validation and allows unauthenticated attackers to conduct spoofing activity, leading to its inclusion in CISA’s “must-patch” list for federal agencies.



