← Carolina Clear Tech

Cyber Threat Brief

2026-04-03

Listen to this brief (24:00)

Download MP3
Show Notes

Show Notes - 2026-04-03

Stories Covered

CVEs Referenced

CVE-2025-10492, CVE-2025-30208, CVE-2025-55182, CVE-2025-7741, CVE-2026-20093, CVE-2026-20160, CVE-2026-26135, CVE-2026-27663, CVE-2026-27664, CVE-2026-32173, CVE-2026-32213, CVE-2026-34073, CVE-2026-3502, CVE-2026-5276, CVE-2026-5277, CVE-2026-5279, CVE-2026-5283, CVE-2026-5289

Indicators of Compromise

Domains: sfrclak[.]com, 206[.]73

Read the full brief

Get tomorrow's brief in your inbox

Protect Your Business

Need a security assessment? See our cybersecurity packages.

View Services

Daily Cyber Threat Brief - April 3, 2026

Today: Akira ransomware reaches encryption in under an hour. CISA adds TrueConf client vulnerability to KEV catalog with April 16 deadline. Mass credential harvesting hits 766 Next.js hosts via React2Shell exploit. Cisco patches critical 9.8 CVSS authentication bypass in IMC and SSM products.

Critical Alerts

CVE-2026-3502 TrueConf Client Code Download Without Integrity Check

CISA added this vulnerability to the Known Exploited Vulnerabilities catalog based on evidence of active exploitation. The flaw allows download of code without integrity verification in TrueConf Client software. EPSS scoring shows 0.000 (1st percentile), indicating low observed exploitation probability despite KEV listing.

CVE-2025-55182 React2Shell Mass Credential Theft Campaign

Attackers exploited the React2Shell vulnerability (CVSS 10.0) to compromise 766 Next.js hosts across multiple cloud providers and geographic regions. Threat cluster UAT-10608 deployed NEXUS Listener framework to harvest database credentials, SSH private keys, AWS secrets, shell history, Stripe API keys, and GitHub tokens. The campaign targets publicly exposed Next.js applications through automated scanning. NEXUS Listener V3 provides attackers with password-protected web GUI to browse stolen credentials, search by host, and view statistics. EPSS score is 0.651 (98th percentile), confirming widespread active exploitation. CISA KEV due date was December 12, 2025.

Axios Supply Chain Attack Deploys Cross-Platform RAT

North Korean state actor (UNC1069/Sapphire Sleet) compromised npm credentials of Axios maintainer and published two backdoored releases on March 31, 2026. Malicious versions 1.8.1 (tagged "latest") and 1.7.10 (tagged "legacy") were live for three hours. Approximately 600,000 downloads occurred during that window. Each version introduced dependency [email protected], a purpose-built trojan deploying WAVESHAPER.V2 RAT communicating with sfrclak[.]com (142.11.206[.]73). First infection observed 89 seconds after publication. Axios has 100 million weekly downloads and exists in roughly 80% of cloud and code environments. The attack bypassed OIDC Trusted Publishing because a legacy npm access token coexisted with modern controls, and npm prioritizes environment variable tokens over OIDC.

Ransomware Claims (Last 48h)

No ransomware victim claims data available for this reporting period.

Ransomware & Extortion

Akira Ransomware Achieves Encryption in Under One Hour

Akira ransomware group has reduced attack lifecycle from initial access to encryption to less than four hours, with some incidents completing in under one hour. The group has compromised hundreds of victims over the past year and collected at least $245 million in ransom payments through September 2025. Akira likely includes former Conti affiliates and uses zero-day exploits, initial access brokers, and VPNs lacking MFA for entry. The group employs intermittent encryption to encrypt large files faster in smaller blocks. Unlike most ransomware operators who spend 90-95% of development time on encryption malware, Akira invests heavily in functional decryptors, including auto-save features for large files with custom .akira extensions to ensure recovery if encryption is interrupted. This increases victim payment rates. Akira exploits vulnerabilities in Veeam backup servers, Cisco VPNs, and SonicWall appliances. FBI and CISA identified Akira as a top ransomware group targeting SMBs in manufacturing, education, IT, healthcare, financial, and agricultural sectors.

Qilin EDR Killer Disables 300+ Security Products

Cisco Talos analyzed malicious msimg32.dll deployed in Qilin ransomware attacks. The multi-stage infection chain targets and disables over 300 different EDR drivers from nearly every vendor. The loader uses SEH/VEH-based obfuscation to hide control flow and API invocation patterns, neutralizes user-mode hooks, and suppresses Event Tracing for Windows (ETW). Once active, the EDR killer loads rwdrv.sys (physical memory access) and hlpdrv.sys (process termination). Before loading the second driver, it unregisters EDR monitoring callbacks to ensure process termination proceeds without interference. The loader is likely side-loaded by legitimate applications importing functions from msimg32.dll.

AI-Enabled BEC Fraud Reaches 54% Click-Through Rate

AI-enhanced business email compromise campaigns achieve 54% click-through rates compared to 12% for traditional phishing, a 450% effectiveness increase. AI enables localization and role-specific targeting at scale, reducing friction in lure creation. Microsoft tracks Tycoon2FA operation (Storm-1747) as industrial-scale cybercrime subscription platform generating tens of millions of phishing emails monthly. Linked to nearly 100,000 compromised organizations since 2023, accounting for 62% of all phishing attempts Microsoft blocked at peak. Tycoon2FA specializes in adversary-in-the-middle attacks defeating MFA by intercepting credentials and session tokens in real time. The operation uses modular cybercrime structure: separate services for phishing templates, infrastructure, email distribution, and access monetization.

Insider Extortion Attempt Locks 254 Servers

Former core infrastructure engineer Daniel Rhyne pleaded guilty to locking Windows admins out of 254 servers in extortion plot against New Jersey industrial company. Between November 9-25, 2023, Rhyne remotely accessed the network using administrator account, scheduling tasks to delete domain admin accounts and change passwords for 13 domain admin accounts and 301 domain user accounts to "TheFr0zenCrew!". Tasks also changed passwords for local admin accounts affecting 3,284 workstations and 254 servers. On November 25, Rhyne emailed ransom demand titled "Your Network Has Been Penetrated" claiming all IT admins were locked out and backups deleted, demanding 20 bitcoin ($750,000 at the time). Forensic analysis showed web searches for clearing Windows logs, changing domain passwords, and deleting domain accounts.

IOCs & Detection

NEXUS Listener Framework (CVE-2025-55182 Campaign) - Domain: sfrclak[.]com - IP: 142.11.206[.]73 - Files: com.apple.act.mond (macOS), /tmp/ld.py (Linux), wt.exe (Windows renamed PowerShell binary in %PROGRAMDATA%) - Confidence: High (Cisco Talos attribution)

Axios Supply Chain Attack (WAVESHAPER.V2 RAT) - npm packages: [email protected], [email protected], [email protected] - Domain: sfrclak[.]com - IP: 142.11.206[.]73 - Files: wt.exe, /tmp/ld.py, com.apple.act.mond - Confidence: High (Google Threat Intelligence/Microsoft attribution to UNC1069/Sapphire Sleet)

Qilin Ransomware EDR Killer - File: msimg32.dll (malicious, side-loaded) - Drivers: rwdrv.sys (physical memory access), hlpdrv.sys (process termination) - Targets: 300+ EDR drivers across all major vendors - Confidence: High (Cisco Talos analysis)

Business & Infrastructure Threats

vSphere BRICKSTORM Malware Targets Virtualization Layer

Google Threat Intelligence Group analyzed BRICKSTORM malware targeting VMware vSphere ecosystem, specifically vCenter Server Appliance (VCSA) and ESXi hypervisors. Attackers establish persistence at the virtualization layer beneath guest OS where traditional EDR is ineffective. Intrusions exploit weak security architecture, identity design, lack of host-based configuration enforcement, and limited visibility within virtualization layer. vCenter compromise grants administrative control over every managed ESXi host and VM. Attackers gain centralized command (power off, delete, reconfigure any VM, reset root credentials on ESXi hosts) and total data access to underlying storage (VMDKs) bypassing OS permissions. Photon OS shell access via SSH has no remote logging of shell commands. Many organizations host AD domain controllers as VMs in same vSphere cluster managed by AD-integrated vCenter, creating circular dependency during encryption or wipe scenarios. Mandiant released vCenter Hardening Script to enforce security configurations at Photon Linux layer.

Cisco Source Code Theft via Malicious GitHub Action

Hackers claim to have stolen Cisco source code using malicious GitHub Action to steal credentials from development environment. Attackers obtained source code from internal systems and credentials for AWS servers. Extortion attempt in progress.

Cookie-Controlled PHP Webshells in Linux Hosting

Microsoft reports threat actors increasingly use HTTP cookies as control channel for PHP-based webshells on Linux servers. Instead of exposing command execution through URL parameters or request bodies, webshells rely on cookie values to gate execution, pass instructions, and activate malicious functionality. This reduces visibility by allowing malicious code to remain dormant during normal application behavior, executing only when specific cookie conditions are met. Observed across web requests, scheduled tasks, and trusted background workers. Cookies blend into normal web traffic and receive less scrutiny than request paths or payloads. PHP $_COOKIE superglobal allows immediate access to attacker-supplied input without additional parsing. Implementations include loaders with execution gating and layered obfuscation (base64 decoding, runtime function reconstruction, character-by-character assembly) and direct cookie-driven payload stagers.

Mercor Hit by LiteLLM Supply Chain Attack

AI recruiting firm Mercor investigating security incident. Lapsus$ claimed theft of 4TB of Mercor data via LiteLLM supply chain attack.

Hasbro Attack Remediation May Take Weeks

Hasbro 8-K filing notes "unauthorized access" to systems. Company activated business continuity plans and took some systems offline. Remediation expected to take weeks.

Windows / AD Security

Microsoft Force-Upgrades Windows 11 24H2 to 25H2

Microsoft began force-upgrading unmanaged Windows 11 24H2 Home and Pro devices to Windows 11 25H2. Machine learning-based rollout expanded to all devices not managed by IT departments. Windows 11 24H2 reaches end of support October 13, 2026. Devices will automatically receive update when ready with option to postpone or pause. Updates can be paused from Settings > Windows Update. Since March 2026 Patch Tuesday, Microsoft issued several emergency updates including fix for sign-in issue with Microsoft accounts affecting Teams and OneDrive, and out-of-band updates for Bluetooth device visibility and RRAS security vulnerabilities.

Identity-Based Attacks Dominate Threat Landscape

Cisco Talos 2025 Year in Review shows identity-based attack techniques central to lateral movement, privilege escalation, and persistence. Fraudulent device registration increased 178% year-over-year. Attackers target administrator-managed registration flows at three times the rate of user-driven ones through vishing (voice phishing). Internal phishing incidents represent more than one-third of observed phishing, with attackers sending messages from already compromised accounts. Mailbox rules hide replies and suppress visibility. Attackers explore shared drives and collaboration platforms for sensitive information to expand access. 40% of top 100 exploited vulnerabilities effective because organizations run end-of-life devices. React2Shell weaponized within weeks of December disclosure, becoming most targeted vulnerability. 12-year-old vulnerability still in top 10 exploited list.

Azure Vulnerabilities Allow Privilege Escalation and Information Disclosure

Microsoft published advisories for CVE-2026-32213 (Azure AI Foundry elevation of privilege), CVE-2026-26135 (Azure Custom Locations RP SSRF leading to privilege escalation), and CVE-2026-32173 (Azure SRE Agent information disclosure). Details limited.

General Security News

US Bans All Foreign-Made Consumer Routers

Executive Branch determination bans foreign-produced consumer routers citing supply chain vulnerability that could disrupt US economy, critical infrastructure, and national defense. Routers pose severe cybersecurity risk that could be leveraged to immediately disrupt critical infrastructure and harm US persons. Ban applies to new routers only, existing devices do not require replacement.

Russia Tightening ISP Requirements to Force Small Providers Off Market

Russian government proposing new rules requiring higher license fees, larger minimum operational capital, and mandatory deployment of FSB SORM traffic interception equipment. Ministry of Digital Development will gain power to revoke licenses without court order for non-compliance. Providers losing license banned from obtaining new one for decade. Move targets smaller ISPs that delayed or refused SORM equipment deployment, choosing to pay fines but advertise uncensored services. Russia implementing China-style firewall with multiple disconnection tests, censorship reaching millions of domains, full VPN crackdown, and FSB power to cut internet access at will. Three major cities had mobile internet replaced with whitelist-based system allowing only approved websites.

Newspaper Archive Service Disrupted by Cyberattack

Cyberattack on Utah company NewspaperArchive disrupted access to digital newspaper archives across US libraries. Incident occurred late February, still ongoing. Service initially hoped to restore by end of March, timeline extended.

Python and PostgreSQL Growth Reflects AI-Driven Development

Chainguard report analyzing 2,200 container image projects shows Python remains most popular image (72.1% of customers). PostgreSQL usage grew 73% quarter-over-quarter, reflecting AI stack adoption. AI accelerating software development and vulnerability discovery: 300% more fixes applied, 145% increase in vulnerabilities discovered. 96% of vulnerabilities found and remediated occurred outside top 20 most popular projects.

Patch Priority

Vulnerability Disclosures

CVE-2026-20093 and CVE-2026-20160 Cisco Critical Authentication Bypass and RCE

Cisco patched critical authentication bypass in Integrated Management Controller (CVE-2026-20093, CVSS 9.8) allowing unauthenticated remote attackers to bypass authentication and gain elevated privileges. Flaw stems from incorrect password change request handling. Attacker sends crafted HTTP request to alter passwords of any user including Admin, gaining system access. Affects 5000 Series ENCS (fixed 4.15.5), Catalyst 8300 Edge uCPE (fixed 4.18.3), UCS C-Series M5/M6 Rack Servers standalone mode (fixed 4.3(2.260007), 4.3(6.260017), 6.0(1.250174)), UCS E-Series M3 (fixed 3.2.17), UCS E-Series M6 (fixed 4.15.3). CVE-2026-20160 (CVSS 9.8) in Smart Software Manager On-Prem allows unauthenticated remote code execution via exposed internal service API. Fixed in SSM On-Prem 9-202601. No known exploitation, but recent Cisco vulnerabilities weaponized rapidly.

CVE-2025-30208 Vite File System Access Bypass

Vite development server vulnerability allows arbitrary file retrieval via /@fs/ prefix combined with ?raw suffix to bypass access restrictions. Attackers attempt to retrieve configuration files to extract secrets. Vite typically listens on port 5173. EPSS score 0.890 (100th percentile) indicates widespread exploitation attempts. Attacks target standard web server ports, not just default Vite port. Honeypots collected URLs like /@fs/../../../../../etc/environment?raw, /@fs/etc/environment?raw, /@fs/home/app/.aws/credentials?raw.

CVE-2025-10492 Hitachi Energy Ellipse Jasper Report RCE

Java deserialization vulnerability in Jaspersoft Library used for custom reports in Ellipse product versions 9.0.50 and prior. Improper handling of externally supplied data allows remote code execution. EPSS 0.004 (59th percentile).

CVE-2026-27663 and CVE-2026-27664 Siemens SICAM 8 Denial of Service

Multiple SICAM 8 products affected by DoS vulnerabilities. CVE-2026-27663 (CPCI85, RTUM85): resource exhaustion from high volume of requests in remote operation mode. CVE-2026-27664 (CPCI85, SICORE): out-of-bounds write via specially crafted XML inputs causing service crash. Affects critical manufacturing sector worldwide.

CVE-2025-7741 Yokogawa CENTUM VP Hardcoded Password

Hardcoded password for PROG user account in CENTUM Authentication Mode. Default PROG permission is S1 (equivalent to OFFUSER), limiting risk for properly permission-controlled systems. If PROG permissions changed, risk of critical operations or configuration changes increases. Exploitation requires attacker access to HIS screen controls. Affects CENTUM VP R5.01.00-R5.04.20, R6.01.00-R6.12.00, R7.01.00. EPSS 0.000 (4th percentile).

CVE-2026-34073 Cryptography Library DNS Name Constraint Enforcement

Incomplete DNS name constraint enforcement on peer names in cryptography library. Minimal details available. EPSS 0.000 (6th percentile).

Chromium Vulnerabilities in Microsoft Edge

Multiple Chromium vulnerabilities addressed in Microsoft Edge: CVE-2026-5289 (use after free in Navigation, EPSS 0.001/20th percentile), CVE-2026-5283 (inappropriate implementation in ANGLE, EPSS 0.000/2nd percentile), CVE-2026-5279 (object corruption in V8, EPSS 0.001/23rd percentile), CVE-2026-5277 (integer overflow in ANGLE, EPSS 0.001/20th percentile), CVE-2026-5276 (insufficient policy enforcement in WebUSB, EPSS 0.000/13th percentile).

Trends & Context

Today's stories highlight ransomware operational maturity, supply chain vulnerability at scale, and identity as the primary attack surface. Akira's sub-hour encryption timeline and investment in reliable decryptors show ransomware-as-a-business optimization. The Axios npm compromise demonstrates state actors can weaponize trust relationships in package ecosystems affecting hundreds of thousands of installations within hours. NEXUS Listener framework industrializes credential harvesting with attacker-friendly GUIs. AI-enabled BEC campaigns achieving 54% click-through rates show how automation scales social engineering to target small organizations previously considered unprofitable. Identity-based attacks dominate because valid credentials bypass most security controls, with fraudulent device registration up 178% and internal phishing from compromised accounts representing over one-third of incidents.