CISA added CVE-2026-33017 (Langflow code injection RCE in an AI agent framework) and CVE-2026-33634 (malicious code embedded in Aqua Security’s Trivy scanner) to its Known Exploited Vulnerabilities catalog following swift in-the-wild abuse. US federal agencies must remediate by April 8–9, underscoring how AI tooling and software supply chains are being weaponized within hours of disclosure. Teams should update to safe versions, remove any tainted builds, and rotate exposed credentials.
Source: Help Net Security
TeamPCP strikes Telnyx SDK on PyPI; stealer payload hidden in WAV file
Attackers backdoored the popular “telnyx” Python SDK (versions 4.87.1 and 4.87.2) on PyPI, abusing the software supply chain to deploy a credential stealer concealed within a WAV file. The package, used with Telnyx’s AI Voice Agent service, could exfiltrate sensitive data from developer environments. Organizations should yank the affected versions, scan build systems for compromise, and rotate tokens and keys.
Source: The Hacker News
Unpatched critical PTC Windchill/FlexPLM flaw (CVE-2026-4681) prompts urgent warnings
A critical vulnerability (CVSS 10.0) in PTC’s Windchill and FlexPLM has no patch yet, triggering advisories from CISA and even physical outreach by German police to at-risk organizations. The flaw could enable severe compromise across engineering and product lifecycle systems. Until fixes arrive, defenders should restrict exposure, enforce network segmentation, and monitor aggressively for exploitation attempts.
Source: SecurityWeek
F5 BIG-IP APM flaw added to KEV amid active exploitation
CISA added CVE-2025-53521 (CVSS v4 9.3) affecting F5 BIG-IP Access Policy Manager to its KEV list following confirmed active exploitation leading to potential remote code execution. Organizations should prioritize vendor patches or mitigations and validate internet exposure, access controls, and logging around APM instances.
Source: The Hacker News
European Commission confirms cyberattack on cloud infrastructure
The European Commission said a cyberattack hit cloud infrastructure hosting Europa.eu sites, was contained quickly, and did not impact internal networks. The incident highlights ongoing risks to public-sector cloud workloads and the importance of rapid detection, containment, and resilient hosting models.
Source: TechCrunch
EU Parliament rejects extension of CSAM scanning rules for tech platforms
Lawmakers voted down a proposal to extend client- and server-side scanning for child sexual abuse material, a move with major implications for privacy, encryption, and platform safety tooling across the EU. The decision resets the policy debate over detection mandates and end-to-end encryption, with industry and regulators bracing for the next legislative chapter.
Source: Recorded Future News
Apple pushes lock-screen alerts to outdated iPhones amid active web-based exploits
Apple is notifying users on older iOS/iPadOS versions directly on the Lock Screen about active web exploit activity, urging immediate updates. The alerts reflect ongoing targeting of unpatched devices via drive-by attacks and raise the urgency of keeping mobile fleets current.
Source: The Hacker News
Hundreds of exposed API keys found across public websites
Researchers scanning 10 million sites uncovered hundreds of valid API keys granting access to services including AWS, GitHub, Stripe, and OpenAI. The findings underscore persistent secrets management gaps in web apps and marketing sites, with risks ranging from data exfiltration to financial fraud.
Source: CyberNews
You May Also Be Interested In... - Citrix NetScaler under active recon for CVE-2026-3055 memory overread - “Coruna” iOS exploit kit likely updates Operation Triangulation - Bogus Avast site drops Venom Stealer under guise of a virus scan