Security Daily Digest
?
← BACK TO TODAY

Cybersecurity news, daily.

2026.04.22

16 sources scanned
FEATURED
01

CISA Adds 8 Exploited Flaws to KEV Catalog

CISA has added eight new vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, including a critical SD-WAN flaw actively exploited in attacks. U.S. government agencies have been given a four-day deadline to secure their systems against these vulnerabilities. This addition underscores the importance of timely patch management and highlights the ongoing threat landscape that security teams must navigate to protect critical infrastructure.

SRC The Hacker NewsBleepingComputer
02

NGate Android Malware Targets NFC Payment Data

Security researchers have uncovered a new variant of the NGate Android malware that targets NFC payment data by trojanizing the HandyPay app. This iteration is designed to steal card data and PINs, posing a significant threat to Android users utilizing NFC payment systems. Organizations should enhance their mobile security posture by monitoring for unauthorized app installations and educating users on the risks of downloading apps from untrusted sources.

SRC The Hacker NewsBleepingComputer
03

Google Patches Critical RCE in Antigravity IDE

Google has released a patch for a critical remote code execution vulnerability in its Antigravity IDE, which was susceptible to prompt injection attacks. This vulnerability allowed attackers to execute arbitrary code on affected systems through crafted inputs. Security teams should prioritize applying this patch to prevent potential exploitation and ensure the integrity of development environments using Google's agentic AI tools.

SRC Dark ReadingThe Hacker News
SIGNAL

STAY UPDATED

Daily security digest, straight to your inbox.

ARCHIVE