← Carolina Clear Tech

Cyber Threat Brief

2026-04-05

Listen to this brief (17:28)

Download MP3
Show Notes

Show Notes - 2026-04-05

Stories Covered

CVEs Referenced

CVE-2026-21643, CVE-2026-23442, CVE-2026-23444, CVE-2026-23468, CVE-2026-23472, CVE-2026-23473, CVE-2026-27447, CVE-2026-27456, CVE-2026-31394, CVE-2026-34978, CVE-2026-34979, CVE-2026-34980, CVE-2026-34990, CVE-2026-35414, CVE-2026-35616

Read the full brief

Get tomorrow's brief in your inbox

Protect Your Business

Need a security assessment? See our cybersecurity packages.

View Services

Daily Security Brief - April 5, 2026

Today: Fortinet's FortiClient EMS faces its second critical zero-day in weeks (CVE-2026-35616, CVSS 9.1) with active exploitation over Easter weekend. North Korean hackers used fake Microsoft Teams errors to hijack the Axios npm package and deploy RATs. Device code phishing attacks surged 37x as PhaaS kits democratize OAuth abuse.

Critical Alerts

Fortinet Patches Actively Exploited CVE-2026-35616 in FortiClient EMS

Fortinet released emergency patches for CVE-2026-35616 (CVSS 9.1), a pre-authentication API access bypass in FortiClient EMS versions 7.4.5 through 7.4.6. The flaw allows unauthenticated attackers to execute unauthorized code via crafted requests. watchTowr recorded exploitation attempts starting March 31, 2026, with active exploitation confirmed by Fortinet this week. This is the second unauthenticated vulnerability in FortiClient EMS in weeks, following CVE-2026-21643 (CVSS 9.1). Attackers exploited the Easter holiday weekend to maximize impact while security teams operated at reduced capacity.

Ransomware & Extortion

Axios npm Hack Used Fake Teams Error Fix to Hijack Maintainer Account

North Korean threat actors (UNC1069) compromised the Axios HTTP client npm package through a targeted social engineering campaign. The attackers created a fake company Slack workspace, staged employee profiles, and invited the lead maintainer into a Microsoft Teams meeting. During the call, a fabricated error prompted the maintainer to install what appeared to be a Teams update, which was actually WAVESHAPER.V2 RAT malware. The attackers obtained npm credentials and published malicious Axios versions 1.14.1 and 0.30.4 containing the plain-crypto-js dependency that installed RATs on macOS, Windows, and Linux. The malicious versions were live for approximately three hours. Google GTIG attributes this to UNC1069, a financially motivated North Korean group active since 2018.

36 Malicious npm Packages Exploited Redis, PostgreSQL to Deploy Persistent Implants

Cybersecurity researchers discovered 36 malicious npm packages disguised as Strapi CMS plugins that exploit Redis and PostgreSQL databases, deploy reverse shells, harvest credentials, and install persistent implants. All packages follow the "strapi-plugin-" naming convention to mimic legitimate Strapi v3 plugins (official plugins are scoped under "@strapi/"). The packages were uploaded by four sock puppet accounts over 13 hours. The postinstall script hook executes automatically on npm install, abusing root privileges in CI/CD environments and Docker containers. The payloads evolved to include Redis RCE via crontab injection, Docker container escape, PostgreSQL exploitation using hard-coded credentials, and credential harvesting targeting Guardarian databases and cryptocurrency wallets.

European Commission Confirms Data Breach Linked to Trivy Supply Chain Attack

Hackers stole over 300GB of data from the European Commission's AWS environment, including personal information. The breach is linked to a supply chain attack targeting Trivy, a popular open-source vulnerability scanner. Details about the attack vector remain limited.

Meta Pauses Work With Mercor After Data Breach Puts AI Industry Secrets at Risk

Meta suspended all work with data contracting firm Mercor following a major security breach. Mercor provides proprietary training data for AI labs including OpenAI, Anthropic, and Meta. The breach exposed bespoke datasets that AI companies consider highly confidential because they reveal model training techniques. Other major AI labs are reevaluating their relationships with Mercor. The breach could reveal competitive intelligence to rival AI labs in America and China.

Business & Infrastructure Threats

Device Code Phishing Attacks Surge 37x as New Kits Spread Online

Device code phishing attacks abusing the OAuth 2.0 Device Authorization Grant flow have surged 37 times in 2026. Attackers send device authorization requests and trick victims into entering codes on legitimate login pages, granting attackers valid access and refresh tokens that bypass MFA. The EvilTokens phishing-as-a-service (PhaaS) platform has driven mainstream adoption, but researchers identified at least 11 competing kits: VENOM, SHAREFILE, CLURE, LINKID, AUTHOV, DOCUPOLL, FLOW_TOKEN, PAPRIKA, DCSTATUS, and DOLCE. The kits use SaaS-themed lures (DocuSign, Microsoft Teams, Adobe, SharePoint), anti-bot protections, and cloud platform hosting (AWS S3, DigitalOcean, Cloudflare Workers, GitHub Pages).

LinkedIn Secretly Scans for 6,000+ Chrome Extensions, Collects Data

LinkedIn uses hidden JavaScript to scan visitors' browsers for 6,236 installed extensions and collect device data including CPU cores, available memory, screen resolution, timezone, battery status, and audio information. The script has grown from 2,000 extensions in 2025 to 6,236 extensions in 2026. LinkedIn scans for over 200 products that compete with its sales tools (Apollo, Lusha, ZoomInfo) and can map which companies use competitor products based on employee LinkedIn profiles. LinkedIn claims the scanning protects users and detects extensions that violate terms of service, but critics warn this fingerprinting builds unique browser profiles for cross-site tracking.

Claude Code Leak Used to Push Infostealer Malware on GitHub

Threat actors are exploiting the recent Claude Code source code leak by creating fake GitHub repositories that deliver Vidar information-stealing malware. On March 31, Anthropic accidentally exposed the full client-side source code via a 59.8 MB JavaScript source map in an npm package. Attackers are using fake repositories themed around the leaked code to target developers.

'Serious Cyberattack' Impacts Phones, Public Safety Systems in Several Massachusetts Towns

A cyberattack affected the Patriot Regional Emergency Communications Center in Massachusetts, impacting phone systems and public safety systems in Ashby, Dunstable, Pepperell, and Townsend. Police and fire departments were affected. The attack was identified early Tuesday. No gang has claimed responsibility.

UK: School IT System Targeted in Cyber Attack Ahead of Exam Season

The Northern Ireland Education Authority's IT system was targeted in a cyberattack, forcing password resets for all users. Schools and pupils were logged out of their accounts, preventing access to exam preparation resources. The EA took immediate containment steps and launched a full investigation but could not confirm whether personal data was affected.

Hong Kong Hospital Authority Apologises for Data Breach Involving 56,000 Patients

Hong Kong's Hospital Authority reported unauthorized retrieval of patient information affecting over 56,000 patients served by Kowloon East hospitals. The breach compromised names, identity card numbers, genders, dates of birth, hospital visit dates, and surgical procedure details. The monitoring system detected suspicious retrieval and a leak on a third-party platform at 2am Friday. Internal network review did not indicate a cyberattack. Hong Kong's privacy watchdog and police are investigating.

The Breach Lasted 25 Minutes. How Long Will the Litigation Last?

Unauthorized access to North Carolina personal injury law firm Auger & Auger's network lasted 25 minutes on February 17, 2026. The breach affected 5,102 people and exposed names, dates of birth, social security numbers, driver's license numbers, government-issued IDs, and medical information. The firm notified victims on March 30 and offered one year of identity protection. Within days, at least five law firms began investigating and seeking plaintiffs for class-action lawsuits. No gang has claimed responsibility.

General Security News

Ex-Microsoft Engineer Believes Azure Problems Stem from Talent Exodus

Axel Rietschin, a former Azure Core Compute and Windows Base Kernel engineer, published essays arguing that Azure's reliability problems stem from rushed launch decisions in 2008, post-launch talent exodus, lack of software quality discipline, and persistently poor execution. He points to OpenAI's $11.9 billion compute deal with CoreWeave in March 2025 as a vote of no confidence in Azure's ability to meet demanding requirements at scale. Rietschin argues Microsoft should focus on bringing back senior technical leaders to improve developer training and mentoring rather than cutting staff. The rise of AI coding agents has created massive spikes in CI/CD compute demand for testing and deploying AI-generated code, with one analysis showing a 4x increase in commits authored by Anthropic's Claude Code agent in the past three months.

Patch Priority

Vulnerability Disclosures

Microsoft Security Update Guide (Linux/Open Source CVEs)

Microsoft published advisories for multiple Linux and open-source vulnerabilities affecting Windows Subsystem for Linux (WSL) and related components. Notable CVEs include OpenPrinting CUPS path traversal (CVE-2026-34978, EPSS 0.001), authorization bypass (CVE-2026-27447, EPSS 0.000), heap overflow (CVE-2026-34979, EPSS 0.000), and RCE via shared PostScript queues allowing anonymous Print-Job requests to reach lp code execution over the network (CVE-2026-34980, EPSS 0.000). Additional vulnerabilities include local print admin token disclosure using temporary printers (CVE-2026-34990, EPSS 0.000) and util-linux TOCTOU race condition in mount loop device setup (CVE-2026-27456, EPSS 0.000).

Microsoft Security Update Guide (Kernel CVEs)

Microsoft published advisories for Linux kernel vulnerabilities: io_uring/poll multishot recv EOF handling (CVE-2026-23473, EPSS 0.000), mac80211 crash for AP_VLAN stations (CVE-2026-31394, EPSS 0.000), drm/amdgpu BO list exhaustion (CVE-2026-23468, EPSS 0.000), IPv6 SRv6 NULL checks (CVE-2026-23442, EPSS 0.000), serial core infinite loop (CVE-2026-23472, EPSS 0.000), and wifi mac80211 skb handling (CVE-2026-23444, EPSS 0.000). All have very low EPSS scores (10th percentile or lower).

CVE-2026-35414

Microsoft published advisory for CVE-2026-35414 (EPSS 0.000, 4th percentile). No description or affected product details provided.

Trends & Context

Supply chain attacks remain the dominant threat vector, with attackers targeting developer toolchains through social engineering (Axios npm hack), malicious package uploads (36 fake Strapi plugins), and leaked source code exploitation (Claude Code). The North Korean UNC1069 group demonstrates increasing sophistication in developer-targeted social engineering, using realistic fake workspaces and staged Teams meetings. Device code phishing has industrialized with 11 competing PhaaS kits, making OAuth abuse accessible to low-skill attackers. Fortinet's second unauthenticated FortiClient EMS zero-day in weeks highlights persistent security issues in enterprise management tools, particularly those exposed to the internet.