← Carolina Clear Tech

Cyber Threat Brief

2026-04-04

Listen to this brief (17:54)

Download MP3
Show Notes

Show Notes - 2026-04-04

Stories Covered

CVEs Referenced

CVE-2026-33634, CVE-2026-5281

Indicators of Compromise

Domains: sfrclak[.]com., sfrclak[.]com

Hashes: e10b1fa84f1d6481625f741b69892780140d4e0e7769e7491e5f4d894c2e0e09, fcb81618bb15edfdedfb638b4c08a2af9cac9ecfa551af135a8402bf980375cf, 617b67a8e1210e4fc87c92d1d1da45a2f311c08d26e89b12307cf583c900d101, 92ff08773995ebc8d55ec4b8e1a225d0d1e51efa4ef88b8849d0071230c9645a, ed8560c1ac7ceb6983ba995124d5917dc1a00288912387a6389296637d5f815c

IP Addresses: 142.11.206.73

Read the full brief

Get tomorrow's brief in your inbox

Protect Your Business

Need a security assessment? See our cybersecurity packages.

View Services

Daily Security Brief - April 4, 2026

Today: TeamPCP supply chain campaign hits European Commission AWS infrastructure with 340GB data theft via compromised Trivy scanner, CISA KEV deadline April 9. North Korean UNC1069 socially engineered Axios maintainer through fake Microsoft Teams call, deploying trojan that stole npm credentials used to publish malware reaching 100 million weekly downloads. Die Linke German political party confirms Qilin ransomware data theft, with bqtlock threatening Metro Hospital USA over 5.3TB medical records and SonicWall VPN access.

Critical Alerts

TeamPCP Supply Chain Campaign: European Commission Cloud Breach (CVE-2026-33634)

CERT-EU confirmed the European Commission's Europa web hosting platform on AWS was breached through the Trivy supply chain compromise. Initial access occurred March 19 with AWS API key theft. Detection took 5 days (March 24), with 340GB uncompressed data (91.7GB compressed) exfiltrated including 52,000 email files from 42 internal Commission departments and 29 other EU entities. ShinyHunters published the data on their dark web leak site March 28. The breach demonstrates high-value credential usage with no lateral movement detected. CVE-2026-33634 has EPSS score 0.212 (96th percentile) and is on CISA KEV with deadline April 9, 2026.

SentinelOne Blocks LiteLLM Supply Chain Attack (CVE-2026-5281)

SentinelOne AI EDR stopped trojanized LiteLLM versions hours after compromise using behavioral detection. Attackers obtained PyPi credentials to publish malicious packages deploying cross-platform payloads. An AI coding assistant with unrestricted permissions installed the infected package. Malware attempted obfuscated Python execution, data stealing, persistence, Kubernetes lateral movement, and encrypted data exfiltration. Platform terminated process chain in under 44 seconds. CVE-2026-5281 has CISA KEV deadline April 15, 2026, EPSS 0.030 (87th percentile).

Axios npm Supply Chain Attack via Social Engineering

North Korean UNC1069 socially engineered Axios maintainer through fake company founder, cloned Slack workspace, and fake Microsoft Teams meeting. When maintainer joined fake call, error message prompted "system update" deploying remote access trojan. Attackers stole npm credentials, published trojanized Axios versions 1.14.1 and 0.30.4 with WAVESHAPER.V2 implant via hidden "[email protected]" dependency. Malicious versions available 3 hours, reaching 100 million weekly download base. Post-install script downloads platform-specific malware for macOS, Windows, Linux. Windows variant establishes persistence via registry. SilentSiphon stealer captured credentials from browsers, password managers, GitHub, GitLab, Bitbucket, npm, Yarn, pip, RubyGems, cargo, NuGet.

Ransomware Claims (Last 48h)

Group Victim Sector Country
bqtlock Metro Hospital USA Healthcare USA
Qilin Die Linke Government/Political Germany

2 claims tracked from 2 groups in the last 48 hours. These are unverified claims from ransomware leak sites, not confirmed breaches.

Ransomware & Extortion

Die Linke German Political Party Confirms Qilin Data Theft

Die Linke (Left Party) confirmed Qilin ransomware stole data from internal party organization and employee personal information following March 26 network compromise. The party has 64 Bundestag members and 123,000 registered members. Membership database was not impacted. Qilin publicly claimed the attack April 1 on their leak site without publishing data samples. Die Linke describes Qilin as Russian-speaking, financially and politically motivated cybercriminals, stating the attack "does not appear to be coincidental." The party filed criminal complaint with German police and is working with independent IT experts for restoration.

University of Mississippi Medical Center Ransomware Impact

February 2026 ransomware attack took Epic EHR offline across 35 clinics and 200+ telehealth sites, forcing cancellation of chemotherapy appointments and postponement of non-emergency surgeries. Staff reverted to paper workflows. Healthcare organizations experienced 93% attack rate in 2025 with 72% reporting incidents that disrupted patient care directly. BridgePay payment processor suffered February 2026 attack taking APIs, virtual terminals, payment pages offline. Publicly disclosed ransomware attacks surged 49% year-over-year in 2025 to 1,174 confirmed incidents.

Apex, NC Data Recovery via Court Order

Town of Apex in North Carolina recovered stolen data from July 2024 attempted ransomware attack after Wake County Superior Court issued October 2024 restraining order compelling Bublup, Inc. to provide full access. Approximately 22,000 residents' data had never appeared on dark web. Threat actors stored data on U.S.-based Bublup servers. Exposed data types include name, SSN, driver's license, passport, financial accounts, credit/debit cards, email, username/password, DOB, health insurance, medical conditions/treatment, medical record numbers, patient account numbers, telephone numbers. Data stored on U.S. servers subject to court jurisdiction enabled recovery. Questions remain about whether threat actors maintained other copies.

BakerHostetler 2026 Data Breach Report Findings

Law firm represented 1,250 breach clients in 2025 (27% healthcare, 18% finance/insurance, 15% business/professional services). Average initial ransom demand spiked 70% to $4.2 million. Average payment up 36% to $682,702. Healthcare sector averaged $18.2 million initial demands (6x other sectors), highest single demand $98 million. Healthcare victims paid average $1.2 million (highest $5 million). Payment motivation flipped: 2025 saw 43% pay primarily to prevent data publication vs 31% for decryptor, reversing 2024 trend. Class action lawsuits filed in 14% of incidents (up from 9% in 2024). Phishing remained top cause at 30%. Vendors responsible for 25% of incidents. Faster forensics reduced notification time by 3 days.

Hasbro Confirms Cyberattack, Weeks to Recover

Hasbro detected March 28 intrusion, took down systems, estimates "several weeks" for recovery per SEC disclosure April 3. Company owns Transformers, Peppa Pig, Dungeons & Dragons properties. Attack type and attribution not disclosed. No ransomware group has claimed responsibility as of April 3.

IOCs & Detection

Axios npm Supply Chain Attack

TeamPCP Supply Chain

Business & Infrastructure Threats

TeamPCP Campaign: Sportradar AG Breach Confirmed

VECERT confirmed Sportradar AG ($4.98 billion Swiss sports technology company) "systemic compromise" jointly operated by TeamPCP and Vect ransomware via Trivy supply chain (CVE-2026-33634). Data exposed: 26,000 users' personal information, 23,169 athlete records (names, DOB, gender, nationality), 161 client organizations including ESPN, Nike, NBA Asia, IMG Arena, 8 production RDS passwords, 328 platform API key/secret pairs, Kafka SASL credentials, New Relic monitoring tokens.

Supply Chain Attacks: 25% of Top 100 Vulnerabilities

Cisco Talos 2025 Year in Review reports nearly 25% of top 100 targeted vulnerabilities affect widely used frameworks and libraries. React2Shell (React Server Components vulnerability) became top-targeted vulnerability of 2025 despite December disclosure. Log4j vulnerabilities persist, showing deeply embedded utilities create difficult-to-reduce attack surface. Supply chain attacks enable downstream impacts from ransomware to espionage by state-sponsored groups and teenage cybercriminals.

Third-Party Risk: 30% of Breaches

Verizon 2025 DBIR found third parties involved in 30% of breaches. IBM 2025 Cost of Data Breach Report puts average remediation cost at $4.91 million for third-party breaches. Global TPRM spending projected to grow from $8.3 billion (2024) to $18.7 billion (2030). Regulatory frameworks (CMMC, NIS2, DORA) require demonstrable, ongoing oversight of third-party controls. Cyber insurers scrutinize supply chain hygiene before writing policies.

Cookie-Controlled PHP Web Shells Persist via Cron

Microsoft reports threat actors using HTTP cookies as control channel for PHP-based web shells on Linux servers. Web shells rely on $_COOKIE superglobal variable for threat actor-supplied cookie values that gate execution and pass instructions. Cookies blend into normal web traffic, reduce visibility. Threat actors obtain initial access via valid credentials or known vulnerabilities, establish cron job invoking shell routine to execute obfuscated PHP loader. "Self-healing" architecture recreates PHP loader via scheduled task even after removal. PHP loader remains inactive during normal traffic, activates on specific cookie values.

LinkedIn Scans for 6,000+ Chrome Extensions

"BrowserGate" report claims LinkedIn uses hidden JavaScript to scan visitors' browsers for 6,236+ installed extensions, collect device data (CPU cores, memory, screen resolution, timezone, language, battery status, audio, storage features). BleepingComputer independently confirmed script with randomized filename checking extension IDs. Script previously detected 2,000 extensions (2025), grew to 3,000 (February 2026), now 6,236. Extensions scanned include LinkedIn competitors (Apollo, Lusha, ZoomInfo), grammar tools, tax professional tools. LinkedIn claims detection used to protect platform, identify scraping violations, inform technical defenses, not to infer sensitive information about members. Technique can build unique browser profiles enabling cross-site tracking.

Hims & Hers Zendesk Data Breach

Telehealth company (nearly $1 billion annual revenue) suffered February 4-7, 2026 breach after Zendesk support tickets stolen. ShinyHunters compromised Okta SSO accounts to access Hims & Hers Zendesk instance, stole millions of support tickets. Exposed data includes names, contact information, other unspecified support request data. No medical records or doctor communications compromised. Company detected suspicious activity February 5, determined unauthorized access March 3. Offering 12 months free credit monitoring.

Windows / AD Security

TA416 Targets European Governments with PlugX and OAuth-Based Phishing

China-aligned TA416 (overlaps with DarkPeony, RedDelta, Red Lich, SmugX, UNC6384, Vertigo Panda) targets European government and diplomatic organizations since mid-2025 after two-year minimal European activity. Multiple waves of web bug and malware delivery campaigns against EU and NATO diplomatic missions. December 2025 attacks leveraged third-party Microsoft Entra ID cloud applications for OAuth redirects. Phishing emails contain link to Microsoft's legitimate OAuth authorization endpoint, clicking redirects to attacker domain, deploys PlugX. February 2026 campaigns linked to archives on Google Drive or compromised SharePoint with legitimate Microsoft MSBuild executable and malicious C# project file. MSBuild searches directory for project file, automatically builds it. CSPROJ file decodes Base64-encoded URLs, fetches DLL side-loading triad, executes PlugX. Middle East campaigns target diplomatic and government entities following U.S.-Israel-Iran conflict (late February 2026).

TrueConf Zero-Day Exploited in Asian Government Attacks

Chinese threat actor exploited video conferencing platform zero-day to perform reconnaissance, escalate privileges, execute additional payloads targeting Asian government entities.

General Security News

CISA Budget Cut: Trump Proposes $707M Reduction

Trump's fiscal 2027 budget proposes cutting CISA by $707 million. Agency already lost millions in funding and close to 1,000 employees (about one-third of workforce) during Trump's first year of second term. Fiscal 2026 budget proposed $491 million cut, Congress approved $135 million reduction. Proposal claims CISA "more focused on censorship than on protecting the Nation's critical systems." Plan eliminates offices duplicative of state and federal programs (school safety), programs focused on "misinformation and propaganda," external engagement offices (council management, stakeholder engagement, international affairs). Many programs already axed: Cyber Safety Review Board (investigating Salt Typhoon), advisory committees, AI Safety and Security Board, Critical Infrastructure Partnership Advisory Council, National Security Telecommunications Advisory Committee, National Infrastructure Advisory Council, Secret Service Cyber Investigations Advisory Board. March 2025: cut $10 million (nearly half budget) from Multi-State ISAC. Six months later: cut ties and funding for Center for Internet Security. Former CISA official: "This would weaken the system for managing cyber risk, increasing the likelihood that preventable incidents escalate into disruptions."

Infiniti Stealer Targets macOS via ClickFix

Malwarebytes reports Infiniti Stealer malware targeting Mac users via social engineering. ClickFix tactic presents fake Cloudflare human verification captcha on phishing email or compromised page. User instructed to open Terminal app via Spotlight, paste provided code, hit return. Code delivers Infiniti Stealer to Mac. Malware difficult to detect once payload delivered.

Drift Protocol $285M Exploit Shows North Korea Indicators

Elliptic reports $285 million exploit of Solana-based Drift Protocol shows multiple indicators associated with North Korea state-sponsored hacking groups based on onchain behavior, laundering patterns, network-level signals. Largest crypto exploit in 2026. Drift token fell 40%+ following incident. If confirmed, would be eighteenth DPRK act tracked by Elliptic this year, over $300 million stolen so far in 2026.

Amazon Bedrock Multi-Agent Applications Prompt Injection Risk

Palo Alto Networks Unit 42 red-team research demonstrates prompt injection vulnerabilities in Amazon Bedrock Agents' multi-agent collaboration (Supervisor and Supervisor with Routing modes). Attack chain: determine operating mode, discover collaborator agents, deliver attacker payloads, execute malicious actions. Exploits included disclosing agent instructions and tool schemas, invoking tools with attacker-supplied inputs. No vulnerabilities in Amazon Bedrock itself. Bedrock's built-in prompt attack Guardrail stopped attacks when properly configured. LLMs cannot reliably differentiate between developer instructions and adversarial user input. Any agent processing untrusted text remains potentially vulnerable.

Patch Priority

Vulnerability Disclosures

Critical ShareFile Flaws Lead to Unauthenticated RCE

Vulnerabilities can be chained to bypass authentication and upload arbitrary files to server for unauthenticated remote code execution.

Apple Patches DarkSword for iOS 18

Apple broke precedent by patching older iOS version. Organizations with users unwilling or unable to adopt iOS 26 can now protect against severe mobile OS-cracking tool.

Healthcare Breaches

Nacogdoches Memorial Hospital Data Breach

Texas hospital notified 257,073 after January 15, 2026 breach (staff became aware January 31). Exposed data: name, address, phone, email, SSN, DOB, medical record number, account number, health plan beneficiary number, possible full face photograph. Incident not yet on HHS public breach tool. Unclear if 257,073 refers to patients only or patients and employees.

bqtlock Threatens Metro Hospital USA

Ransomware group claims 5.355TB sensitive medical files, 123,458 patient records (scripts, radiology, EKG, MRI, ultrasound, blood work), complete email archives, SonicWall VPN access credentials, network infrastructure information, internal backups. Payment status: unpaid, 400 XMR demanded via private negotiation. Group states "decryption key and deletion of stolen data available upon ransom fulfillment. Deadline strict."

Trends & Context

Supply chain compromises dominate this cycle with TeamPCP's Trivy breach reaching European Commission AWS (340GB theft, 5-day dwell time), North Korean UNC1069's social engineering of Axios maintainer deploying trojan to 100 million weekly downloads, and LiteLLM PyPi compromise. Two critical themes: credential theft from security tools creates high-value access (European Commission took 5 days to detect AWS key usage), and sophisticated social engineering bypasses technical controls (fake Microsoft Teams calls, cloned Slack workspaces). CISA KEV deadlines (April 9 for CVE-2026-33634, April 15 for CVE-2026-5281) create patching urgency. Healthcare sector remains high-value ransomware target with average $18.2 million initial demands and operational disruption (UMMC canceling chemotherapy, postponing surgeries). Payment motivation shift shows 43% now pay primarily to prevent data publication vs 31% for decryptors, reversing the 2024 trend.