CVE-2025-55182, CVE-2026-20045, CVE-2026-21643, CVE-2026-35616
Get tomorrow's brief in your inbox
2026-04-06
Today: Fortinet pushed an emergency weekend patch for CVE-2026-35616, a FortiClient EMS zero-day under active exploitation. Germany identified two REvil leaders responsible for 130 ransomware attacks and $40M in damages. Hackers are exploiting React2Shell (CVE-2025-55182) to harvest credentials from 766 Next.js hosts in 24 hours.
Fortinet FortiClient EMS Zero-Day Under Active Exploitation (CVE-2026-35616)
Fortinet released an emergency weekend patch for CVE-2026-35616, a critical improper access control vulnerability in FortiClient Enterprise Management Server that allows unauthenticated attackers to execute code remotely. The flaw was discovered by Defused, who observed zero-day exploitation in the wild earlier this week before responsible disclosure. FortiClient EMS versions 7.4.5 and 7.4.6 are affected. Shadowserver has found over 2,000 exposed instances online, with the majority in the USA and Germany. This is the second actively exploited FortiClient EMS zero-day in a week, following CVE-2026-21643.
Mass Credential Theft via React2Shell Next.js Exploit (CVE-2025-55182)
A large-scale automated campaign is exploiting React2Shell (CVE-2025-55182) in vulnerable Next.js applications to harvest credentials. Cisco Talos attributes the activity to threat cluster UAT-10608, which compromised at least 766 hosts across various cloud providers in a 24-hour period. The attackers use a framework called NEXUS Listener to exfiltrate database credentials, AWS keys, SSH private keys, API tokens, cloud credentials, and Kubernetes secrets. CVE-2025-55182 is on CISA KEV with a 99th percentile EPSS score (0.663), indicating widespread exploitation. The stolen data enables cloud account takeover, database access, and supply chain attacks.
Cisco Exploit Developer Burned by Forum Marketplace Dynamics (CVE-2026-20045)
A Cisco remote code execution vulnerability (CVE-2026-20045) is under active exploitation by government-backed threat actors. The bug was discovered by an exploit developer using the handle cortana9000, who attempted to sell it on a forum for $70,000 after it was already known and exploited. CVE-2026-20045 is on CISA KEV with a due date of 2026-02-11, indicating federal civilian agencies must patch by that deadline. EPSS is 0.013 (80th percentile). The vulnerability was featured in Trellix's Dark Web Roast series highlighting criminal marketplace failures.
Germany Unmasks REvil Leaders Behind 130 Ransomware Attacks
Germany's Federal Criminal Police (BKA) identified two REvil ransomware leaders responsible for 130 attacks across Germany between 2019 and 2021. The BKA named 31-year-old Russian Kirill Maksimovich Shchukin (alias UNKN, Oneillk2, GandCrab) as the group's representative and public face, and 43-year-old Anatoly Sergeevitsch Kravchuk as the REvil developer. UNKN functioned as the leader of both GandCrab and its successor REvil. The attacks resulted in 25 ransom payments totaling 1.9 million euros ($2.19M) and caused over 35.4 million euros ($40.8M) in total damages. Shchukin's name previously appeared in a February 2023 U.S. DOJ filing seeking seizure of cryptocurrency accounts containing over $317,000 in REvil proceeds. REvil was one of the most prolific ransomware groups, counting JBS and Kaseya among its victims, before law enforcement disrupted operations in October 2021. Russia's FSB arrested several REvil members in January 2022, with four receiving prison sentences in October 2024.
Do Ransomware Gangs Keep Their Promises to Delete Data?
DataBreaches.net surveyed incident response firms, negotiators, and law enforcement to determine how often ransomware gangs default on promises to delete victim data after payment. BakerHostetler reported that threat actors who are paid "very rarely default and publish data." Of BakerHostetler's 1,250 ransomware clients in 2025, 34% paid ransom, with data deletion being the most common motivation. The FBI declined to provide data on default rates, stating only that paying ransom does not guarantee decryption, rewards criminal activity, and does not prevent future extortion or data release. The FBI emphasized that even after payment, organizations should assume data may still be released or that they may be extorted again. Despite LockBit being caught retaining data it promised to delete, concrete evidence of widespread defaults remains sparse.
Cambodia Passes Life Imprisonment Law for Scam Compound Operators
Cambodia passed sweeping legislation introducing prison sentences up to life imprisonment and fines up to $500,000 for scam compound operators. The law creates tiered penalties: 5-10 years for operating a compound, 20 years if torture or kidnapping occurred, and 30 years to life if deaths resulted. Willing participants face up to 10 years and $250,000 in fines. Recruiters, trainers, and data brokers supplying scam operations face 3-10 years depending on harm caused. The law follows international pressure from China and the U.S. to dismantle Cambodia's cyber scam ecosystem. In February, Cambodia raided 190 locations, detained 2,500 suspects, and freed 110,000 foreigners working in compounds. Officials also extradited two major figures, Chen Zhi (Prince Group) and Li Xiong (Huione Group), to China for running scam centers and laundering proceeds.
$285M Drift Hack Attributed to Six-Month DPRK Social Engineering Operation
The Solana-based decentralized exchange Drift attributed the April 1, 2026 theft of $285 million to a six-month North Korean state-sponsored operation by UNC4736 (aliases AppleJeus, Citrine Sleet, Golden Chollima, Gleaming Pisces). The attack began in fall 2025 when individuals posing as a quantitative trading company approached Drift contributors at cryptocurrency conferences across multiple countries. DPRK threat actors deployed third-party intermediaries for face-to-face relationship building, individuals with verifiable professional backgrounds who were technically fluent. Between December 2025 and January 2026, the group onboarded an Ecosystem Vault on Drift, depositing over $1 million while engaging contributors with detailed product questions. Drift attributed the attack with medium confidence based on on-chain fund flows tracing back to the October 2024 Radiant Capital hack ($53M) and operational overlaps with known DPRK activity.
Trellix Launches "Dark Web Roast" to Demystify Cybercriminals
Trellix VP of threat intelligence John Fokker announced a new approach to covering the criminal underground: mockery instead of glorification. The Dark Web Roast blog features ransomware gangs bulk-scheduling extortion posts like a content calendar, likely padding victim counts with fake sites. Fokker argues the security industry has glorified threat actors with names like Wizard Spider and Velvet Tempest, treating them as mythical entities when they are simply criminals stealing data for profit. The approach follows law enforcement tactics like the UK NCA's LockBit trolling operation, which publicly mocked the ransomware gang before revealing LockBitSupp's identity. Fokker argues public mockery and infiltration fracture trust among cybercriminals more effectively than infrastructure takedowns, which criminals simply rebuild.
Open Redirect Used in 21% of Q1 2026 Phishing Campaigns
SANS Internet Storm Center analysis of 350+ phishing emails from Q1 2026 found that 21% used redirect mechanisms to evade detection, including 32% in January, 18% in February, and 16.5% in March. Abused redirect mechanisms varied from "half-open" redirects (like Google-style token-based redirects with reusable, long-lived tokens) to fully open redirects, tracking/advertising systems, logout endpoints, and URL shorteners. Links pointing to legitimate domains like google.com evade simpler email scanners and appear benign to recipients. Bing and other platforms have similar redirect mechanisms being abused. SANS recommends ensuring applications do not expose redirect endpoints that can be misused, monitoring redirection functionality for abuse, and restricting it as necessary.
Traffic Violation Scams Switch to QR Codes
Scammers are sending fake "Notice of Default" traffic violation texts impersonating state courts across the U.S., pressuring recipients to scan QR codes leading to phishing sites. The campaign started a few weeks ago and targets residents in New York, California, North Carolina, Illinois, Virginia, Texas, Connecticut, and New Jersey. Unlike previous toll violation scams that included text links, this variation uses images of fake court notices with embedded QR codes. The QR code directs to an intermediary site with a CAPTCHA (to evade automated analysis), then redirects to phishing sites impersonating state DMVs claiming $6.99 in unpaid tolls or parking tickets. Forms collect name, address, phone, email, and credit card data for identity theft, financial fraud, and sale to other threat actors.
AI Agent Liability Remains Unclear as Vendors Push Automation
Enterprise application providers are promising AI agents capable of "actively running the business" with automation in HR, finance, and supply chain management, but liability for AI failures remains ambiguous. Oracle announced its AI Agent Studio for Fusion Applications would be "capable of reasoning, taking action across business systems, and continuously executing processes." However, UK technology lawyer Malcolm Dowden notes vendors are reluctant to provide warranties for non-deterministic AI behavior because it creates unpredictable liability. The UK Financial Reporting Council stated unequivocally that firms and Responsible Individuals remain accountable for audit quality when using AI: "You can't blame it on the box." Under UK data protection law, organizations deploying AI for automated decision-making (like job application screening) are liable as data controllers and must monitor for bias, maintain transparency, and provide recourse mechanisms.
CBP Facility Codes Leaked via Public Quizlet Flashcards
A Quizlet user created a public flashcard set in February exposing confidential security information about U.S. Customs and Border Protection facilities around Kingsville, Texas. The set, titled "USBP Review," contained specific four-digit codes for checkpoint doors and facility gates. The flashcards were publicly available until March 20, when they were made private 30 minutes after WIRED contacted a phone number potentially linked to the user. An individual with the user's name was listed at an address less than a mile from a Kingsville CBP facility, though WIRED could not verify whether the creator was an active CBP agent or contractor. CBP's Office of Professional Responsibility is reviewing the incident. If created by someone associated with CBP, this represents a serious security breach for an agency responsible for safeguarding the homeland.
Anthropic Claude Code Source Leak Creates IPO Headache
Anthropic accidentally released the complete source code for Claude Code on March 31, exposing 512,000+ lines of code. Previous attempts to understand Claude Code's internal workings required reverse-engineering or analyzing small code snippets, but this leak provided the entire codebase. The timing is particularly challenging as Anthropic prepares for its IPO. Security implications and surprises uncovered in the leaked code are being actively analyzed by researchers.
Fortinet FortiClient EMS (CVE-2026-35616, CVE-2026-21643)
Two critical FortiClient EMS vulnerabilities were discovered by Defused and exploited as zero-days within the past week. CVE-2026-35616 is an improper access control flaw affecting versions 7.4.5 and 7.4.6, allowing unauthenticated remote code execution via specially crafted requests. EPSS is 0.000 (10th percentile) for CVE-2026-35616 and 0.001 (21st percentile) for CVE-2026-21643, though both are confirmed exploited in the wild. Fortinet released emergency hotfixes Saturday and urges immediate patching. Version 7.4.7 will include permanent fixes. Over 2,000 exposed instances identified by Shadowserver.
Next.js React2Shell (CVE-2025-55182)
React2Shell vulnerability in Next.js applications is under mass exploitation for automated credential harvesting. CISA added it to KEV for ransomware connections (due date 2025-12-12). EPSS score is 0.663 (99th percentile), indicating extremely high exploitation probability. At least 766 hosts compromised in 24 hours by UAT-10608 using the NEXUS Listener framework. Stolen data includes database credentials, AWS/GCP/Azure keys, SSH private keys, API tokens, Kubernetes secrets, and command history.
Cisco RCE (CVE-2026-20045)
Cisco remote code execution vulnerability under active exploitation by government-backed threat actors. CISA KEV with due date 2026-02-11. EPSS is 0.013 (80th percentile). Discovered by exploit developer cortana9000, who attempted to sell it as a zero-day after it was already known and exploited.
Three critical zero-days under active exploitation demand immediate attention this week: FortiClient EMS, React2Shell in Next.js, and a Cisco RCE. The React2Shell campaign demonstrates the shift toward automated, large-scale credential harvesting targeting cloud infrastructure and supply chains. Germany's identification of REvil leaders responsible for $40M in damages highlights ongoing law enforcement efforts to attribute historical ransomware operations. The Drift hack illustrates North Korean threat actors' evolution toward sophisticated, months-long social engineering campaigns targeting high-value cryptocurrency targets with verifiable professional personas and in-person relationship building.