Critical roundup Trending

Weekly Threat Roundup: APT28 DNS Hijacking (Apr 6-12

Cybersecurity roundup for 2026-04-06 to 2026-04-12. 10 CVE advisories, 2 breach reports, 4 threat news stories.

This Week at a Glance

Russian state-linked APT28 is exploiting SOHO routers in a widespread DNS hijacking campaign, threatening credential theft across global organizations. Meanwhile, a cluster of critical, maximum-severity vulnerabilities in ubiquitous software and hardware—from the Axios HTTP library to Samsung Exynos chips—demands immediate patching attention.

Top Vulnerabilities

This week’s critical vulnerabilities pose severe risks, including remote code execution (RCE) and sandbox escapes.

Data Breaches

Threat Intelligence

State-sponsored and criminal threat actors were highly active this week.

Key Takeaway

The convergence of software supply chain and hardware vulnerabilities is creating a perfect storm. Critical flaws in foundational components like the Axios library (software) and Samsung Exynos chips (hardware) provide attackers with deep, persistent access points. This week underscores that security teams must expand their threat models beyond application-layer flaws to include the underlying libraries and hardware firmware in their asset management and patching cycles.

Share:

Never miss a security update

Get real-time security alerts delivered to your preferred platform.

Related News

Related Across Yazoul

Never Miss a Critical Alert

CVE advisories, breach reports, and threat intel — delivered daily to your inbox.