The vulnerability, identified as CVE-2026-28950, was patched on April 22, 2026, in iOS 26.4.2 and iPadOS 26.4.2, as well as in iOS 18.7.8 and iPadOS 18.7.8.
The Harvester group, believed to be state-sponsored, has been active since at least 2021, targeting telecommunications, government, and IT organizations in South Asia with custom tools.
Asia-centric booking platform Agoda has denied the alleged theft of 82 million records from its systems just a week after its parent firm Booking Holdings disclosed having been subjected to a Booking.com data breach that exposed user reservation details, according to Cybernews.
Three healthcare providers across the U.S. were noted by the Department of Health and Human Services' breach tracker to have been impacted by separate cyberattacks last year, which have collectively compromised data from about 600,000 individuals, SecurityWeek reports.
Cybernews reports that major U.S. banks Citizens Financial Group and Frost Bank were allegedly compromised by the Everest ransomware-as-a-service operation, which has threatened to expose troves of data pilfered from both financial institutions by Apr. 26.
Misconfigured Perforce servers remain widespread, threaten sensitive data exposure Improperly secured internet-exposed Perforce P4 servers continue to be prevalent, with 72% of 6,122 online instances enabling read-only source code access through a remote user account activated by default, according to SecurityWeek.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.