logo

The Good, the Bad and the Ugly in Cybersecurity – Week 15

ID: 08d2f4af-2f97-5df8-ae9d-95c2ec934cc9

STIX ID: report--08d2f4af-2f97-5df8-ae9d-95c2ec934cc9

Feed Name: SentinelOne Blog

Threat Score
90/100

Date Published: 2026-04-10

Date Updated: 2026-04-30

Author: SentinelOne

...
...

This intelligence note covers three active threats: a US-authorized disruption of a GRU (APT28) DNS-hijacking network that abused TP-Link routers to intercept credentials and insert GRU-controlled infrastructure; macOS-focused ClickFix social-engineering campaigns using Script Editor to deliver AMOS/Atomic Stealer and exfiltrate browser data and wallets; and Iran-affiliated actors exploiting internet-facing PLCs (Rockwell/Allen-Bradley and others) to manipulate HMI/SCADA data and cause operational disruption across critical infrastructure sectors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.