← Carolina Clear Tech

Cyber Threat Brief

2026-04-07

Listen to this brief (21:59)

Download MP3
Show Notes

Show Notes - 2026-04-07

Stories Covered

CVEs Referenced

CVE-2023-27350, CVE-2023-27351, CVE-2023-46805, CVE-2024-1708, CVE-2024-1709, CVE-2024-21887, CVE-2024-27198, CVE-2024-27199, CVE-2024-57726, CVE-2024-57727, CVE-2024-57728, CVE-2025-10035, CVE-2025-26319, CVE-2025-31324, CVE-2025-59528, CVE-2025-8943, CVE-2026-1731, CVE-2026-21643, CVE-2026-23760, CVE-2026-3502, CVE-2026-35616, CVE-2026-5281

Read the full brief

Get tomorrow's brief in your inbox

Protect Your Business

Need a security assessment? See our cybersecurity packages.

View Services

Daily Cybersecurity Brief

April 7, 2026

Today: China-backed Storm-1175 is weaponizing zero-days to deploy Medusa ransomware against healthcare and SMBs, with attacks moving from breach to encryption in under 24 hours. Fortinet's FortiClient EMS has a critical zero-day (CVE-2026-35616) under active exploitation with a CISA deadline of April 9. REvil and GandCrab leaders are now publicly identified by German authorities after causing $40 million in damages.

Critical Alerts

China-Linked Storm-1175 Exploits Zero-Days to Deploy Medusa Ransomware

Storm-1175, a China-based financially motivated threat actor, is exploiting zero-day and recently disclosed vulnerabilities to deploy Medusa ransomware with extraordinary speed. The group moves from initial access to data exfiltration and ransomware deployment within days, and in some cases within 24 hours. Recent campaigns have heavily impacted healthcare, education, professional services, and finance sectors in Australia, the UK, and the US. Since 2023, Storm-1175 has weaponized over 16 vulnerabilities, including CVE-2025-10035 (GoAnywhere MFT, CISA-KEV, EPSS 98th percentile) and CVE-2026-23760 (SmarterMail, CISA-KEV, EPSS 99th percentile), both exploited as zero-days before public disclosure. Other exploited flaws include CVE-2023-46805 and CVE-2024-21887 (Ivanti Connect Secure, both CISA-KEV, EPSS 100th percentile), CVE-2024-1708 and CVE-2024-1709 (ConnectWise ScreenConnect, both CISA-KEV), CVE-2024-27198 and CVE-2024-27199 (JetBrains TeamCity, CISA-KEV), CVE-2024-57726, CVE-2024-57727 (CISA-KEV, EPSS 100th percentile), and CVE-2024-57728 (SimpleHelp), CVE-2026-1731 (BeyondTrust, CISA-KEV, EPSS 99th percentile), and CVE-2023-27350 and CVE-2023-27351 (Papercut, CISA-KEV). The group has demonstrated capability to chain multiple exploits together and has recently targeted Linux systems, including vulnerable Oracle WebLogic instances.

Fortinet FortiClient EMS Zero-Day Under Active Exploitation (CVE-2026-35616)

Fortinet released an emergency hotfix over the weekend for CVE-2026-35616, a critical 9.1 CVSS improper access control vulnerability in FortiClient Enterprise Management Server (EMS) versions 7.4.5 and 7.4.6. The flaw allows unauthenticated attackers to execute code or commands via crafted requests. Fortinet confirmed active exploitation in the wild. CISA added CVE-2026-35616 to the Known Exploited Vulnerabilities catalog on April 6 with a federal agency remediation deadline of April 9, 2026. WatchTowr honeypots captured initial exploitation attempts on March 31, 2026, with "low and slow" exploitation that ramped up significantly after Fortinet's hotfix disclosure on April 6. Shadowserver tracks nearly 2,000 FortiClient EMS instances exposed online, with over 1,400 in the US and Europe. VulnCheck notes a relatively small internet-facing footprint of approximately 100 instances, but the zero-day shares similarities with CVE-2026-21643, another unauthenticated FortiClient EMS flaw disclosed February 6 and exploited in the wild.

Chrome Zero-Day (CVE-2026-5281) Actively Exploited

Google patched CVE-2026-5281, a high-severity use-after-free bug in Dawn (WebGPU implementation) exploited in the wild. Chrome versions 146.0.7680.177/178 for Windows and macOS, and 146.0.7680.177 for Linux address the flaw. Google did not disclose exploitation details, threat actors, or attack methodology. CISA added CVE-2026-5281 to KEV with an April 15, 2026 remediation deadline. EPSS score is 0.030 (87th percentile).

TrueConf Zero-Day (CVE-2026-3502) Exploited in Government Attacks

Chinese threat actors exploited CVE-2026-3502, a 7.8 CVSS zero-day in TrueConf video conferencing software, targeting government entities in Southeast Asia. The vulnerability exists due to lack of integrity checks when fetching application update code, allowing distribution of tampered updates. The compromised TrueConf on-premises server was operated by a governmental IT department and served as a video conferencing platform for dozens of government entities across the country. CISA added CVE-2026-3502 to KEV with an April 16, 2026 deadline. EPSS is 0.013 (80th percentile).

Ransomware Claims (Last 48h)

2 claims tracked across 2 groups in the last 48 hours. These are unverified claims from ransomware leak sites, not confirmed breaches.

Group Victim Sector Country
cry0 Dini Transportation Italy
shadowbyt3$ University of Georgia Education United States

Ransomware & Extortion

German Authorities Identify REvil and GandCrab Leaders

Germany's Federal Criminal Police (BKA) publicly identified two Russian nationals as the leaders of GandCrab and REvil ransomware operations from 2019 to 2021. Kiril Maksimovich Shchukin (age 31, alias UNKN/UNKNOWN) and Anatoly Sergeevitsch Kravchuk (age 43) are accused of at least 130 extortion cases in Germany, with 25 victims paying $2.2 million in ransom and total economic damage exceeding $40 million. Shchukin operated as a representative of both ransomware groups on cybercrime forums. GandCrab started in early 2018 and the original leader claimed to have generated $2 billion in ransom payments before retiring in June 2019 with $150 million. REvil (Sodinokibi) emerged shortly after, formed from GandCrab affiliates and operators. Notable REvil victims include multiple Texas local governments, Acer, and the Kaseya supply-chain attack impacting approximately 1,500 downstream victims. Following the July 2021 Kaseya attack, law enforcement breached REvil servers and monitored operations before Russia arrested more than a dozen members in January 2022, who were released in 2025 after serving time on carding charges. BKA believes both suspects are in Russia and has requested public assistance in locating them, with entries created on the EU's Most Wanted portal.

Jones Day Law Firm Confirms Breach After Silent Ransom Group Attack

Jones Day, one of the top-ranked law firms in the US, confirmed a data breach after Silent Ransom Group (SRG, also known as Luna Moth, Chatty Spider, UNC3753) posted stolen data to their dark web leak site on March 30. The firm disclosed that limited files for 10 clients were obtained and all affected clients were notified. SRG's leak included a file tree and screenshots of negotiation chats dated March 20-28, showing a $13 million ransom demand. Jones Day did not make a counteroffer. The attack targeted Greg Castanias, who leads Jones Day's Federal Circuit team. SRG threatened to publish all data, contact every employee and client, and resume attacks if payment was not received by March 31 at 12pm Central time. The FBI warned in 2025 that SRG has been targeting law firms since early 2023 due to the highly sensitive nature of legal industry data. The negotiation screenshots reference Jones Day's connection to the Epstein files and ties to child predators. There is no indication SRG has resumed attacks or acquired additional data. This is not Jones Day's first breach; the firm was previously affected by the Clop Accellion file transfer vulnerability exploitation.

Iran-Linked Pay2Key Ransomware Returns with Upgraded Tactics

Pay2Key, an Iranian ransomware gang with ties to Fox Kitten (Lemon Sandstorm, PARISITE, Pioneer Kitten, UNC757), targeted a US healthcare organization in late February 2026 with an upgraded variant. The attack leveraged an undetermined access route, used legitimate remote access tools like TeamViewer for initial foothold, harvested credentials for lateral movement, disabled Microsoft Defender Antivirus by falsely signaling that a third-party antivirus product is active, inhibited recovery, deployed ransomware, and cleared logs at the end of execution to cover tracks. No data was exfiltrated during the attack, a shift from the group's typical double extortion playbook. The new variant features improved evasion, execution, and anti-forensics techniques compared to campaigns observed in July 2025. Following its return in 2025, Pay2Key increased affiliate ransom splits from 70% to 80% for attacks targeting Iran's enemies. A Linux variant was detected in August 2025.

Business & Infrastructure Threats

Axios npm Package Compromised by North Korean Hackers (UNC1069)

North Korean threat actors (UNC1069) seized control of the npm account belonging to the lead maintainer of Axios, a popular npm package with nearly 100 million weekly downloads, to push malicious versions containing cross-platform malware dubbed WAVESHAPER.V2. The malicious versions were available for only a few hours but Axios is deeply embedded across enterprise applications, meaning organizations may have unknowingly pulled compromised code through build pipelines or downstream dependencies. The malware includes self-deleting anti-forensic cleanup, pointing to a deliberate, planned operation. This incident demonstrates how quickly the compromise of a popular npm package can have ripple effects through the ecosystem.

AI-Enabled Device Code Phishing Campaign

Microsoft observed a widespread phishing campaign leveraging the Device Code Authentication flow to compromise organizational accounts at scale. This campaign is distinct from previous device code attacks because it moves away from static, manual scripts toward AI-driven infrastructure with multiple end-to-end automations. Threat actors used automation platforms like Railway.com to spin up thousands of unique, short-lived polling nodes running Node.js backend logic, bypassing signature-based detection. Generative AI created hyper-personalized lures aligned to victim roles (RFPs, invoices, manufacturing workflows). Dynamic code generation triggered at the moment of user interaction bypassed the standard 15-minute device code expiration window. Post-compromise activity included automated reconnaissance using Microsoft Graph to map organizational structure and permissions, creation of malicious inbox rules for persistence and data exfiltration, and targeting of high-value accounts in financial or executive roles.

Iran-Linked Password Spraying Campaign Targets Microsoft 365

An Iran-nexus threat actor conducted password-spraying attacks against Microsoft 365 environments in Israel and the UAE across three waves on March 3, March 13, and March 23, 2026. The campaign impacted over 300 organizations in Israel and over 25 in the UAE, with limited targeting in Europe, the US, the UK, and Saudi Arabia. Targeted sectors include government entities, municipalities, technology, transportation, energy, and private-sector companies. The campaign unfolds in three phases: aggressive scanning or password-spraying from Tor exit nodes, login process execution, and sensitive data exfiltration (mailbox content). Analysis of M365 logs shows similarities to Gray Sandstorm (formerly DEV-0343), including use of red-team tools via Tor exit nodes and commercial VPN nodes hosted at AS35758 (Rachamim Aviel Twito), aligning with recent Iran-nexus operations in the Middle East. The technique is also associated with Peach Sandstorm.

Qilin and Warlock Ransomware Use BYOVD to Disable 300+ EDR Tools

Qilin and Warlock ransomware operations use bring your own vulnerable driver (BYOVD) attacks to disable endpoint detection and response solutions. Qilin attacks deploy a malicious DLL named "msimg32.dll" via DLL side-loading, capable of terminating over 300 EDR drivers from almost every security vendor. The loader neutralizes user-mode hooks, suppresses Event Tracing for Windows (ETW) logs, and decrypts the EDR killer payload in memory. The malware uses two drivers: rwdrv.sys (renamed ThrottleStop.sys) to gain physical memory access, and hlpdrv.sys to terminate EDR processes. Both drivers have been used in Akira and Makop ransomware intrusions. Qilin is the most active ransomware group in recent months, linked to 22 of 134 incidents (16.4%) reported in Japan in 2025. Qilin primarily relies on stolen credentials for initial access and executes ransomware approximately six days after initial compromise. Warlock (Water Manaul) continues to exploit unpatched Microsoft SharePoint servers and has updated its toolset with TightVNC for persistence, a legitimate-but-vulnerable NSec driver (NSecKrnl.sys) for BYOVD attacks replacing the previous googleApiUtil64.sys driver, PsExec for lateral movement, RDP Patcher for concurrent RDP sessions, Velociraptor for C2, Visual Studio Code and Cloudflare Tunnel for tunneling C2, Yuze for intranet penetration and reverse proxy, and Rclone for data exfiltration. A Warlock attack was observed in January 2026.

Vulnerability Disclosures

Flowise AI Platform Under Active Exploitation (CVE-2025-59528)

CVE-2025-59528, a maximum-severity 10.0 CVSS code injection vulnerability in Flowise (open-source AI platform), is under active exploitation. The flaw exists in the CustomMCP node, which allows users to input configuration settings for connecting to an external MCP (Model Context Protocol) server. The node parses user-provided mcpServerConfig string to build the MCP server configuration but executes JavaScript code without security validation. Successful exploitation allows access to dangerous modules like child_process (command execution) and fs (file system) with full Node.js runtime privileges, leading to arbitrary JavaScript code execution, full system compromise, file system access, command execution, and sensitive data exfiltration. An API token is required for exploitation. VulnCheck observed exploitation from a single Starlink IP address. This is the third Flowise flaw with in-the-wild exploitation after CVE-2025-8943 (9.8 CVSS, OS command RCE, EPSS 99th percentile) and CVE-2025-26319 (8.9 CVSS, arbitrary file upload, EPSS 99th percentile). Over 12,000 Flowise instances are exposed on the internet. The vulnerability was disclosed in September 2025 and patched in version 3.0.6 of the npm package.

Windows Privilege Escalation Zero-Day (BlueHammer) Leaked

Exploit code was released for an unpatched Windows privilege escalation flaw dubbed BlueHammer. The vulnerability was reported privately to Microsoft but the researcher (Chaotic Eclipse / Nightmare-Eclipse) publicly released exploit code after expressing frustration with Microsoft Security Response Center (MSRC) handling. The flaw is a local privilege escalation combining a TOCTOU (time-of-check to time-of-use) and path confusion, allowing attackers to gain access to the Security Account Manager (SAM) database containing password hashes for local accounts. Successful exploitation enables escalation to SYSTEM privileges and complete machine compromise. The researcher noted the proof-of-concept code contains bugs that may prevent reliable exploitation. On Windows Server platforms, the exploit increases permissions from non-admin to elevated administrator. The flaw requires local access to exploit but poses significant risk as hackers can gain local access through social engineering, software vulnerabilities, or credential-based attacks. Microsoft's response states support for coordinated vulnerability disclosure to protect customers before public disclosure.

GPUBreach Attack Enables Full CPU Privilege Escalation via GDDR6 Bit-Flips

Academic research identified multiple RowHammer attacks against high-performance GPUs, including GPUBreach, GDDRHammer, and GeForge. GPUBreach demonstrates that RowHammer bit-flips in GPU memory can enable privilege escalation and full system compromise, not just data corruption. By corrupting GPU page tables via GDDR6 bit-flips, an unprivileged process can gain arbitrary GPU memory read/write, then chain that into full CPU privilege escalation by exploiting memory-safety bugs in the NVIDIA driver. GPUBreach works even with IOMMU enabled, bypassing protections entirely by corrupting trusted driver state within IOMMU-permitted buffers and triggering kernel-level out-of-bounds writes. The attack can leak secret cryptographic keys from NVIDIA cuPQC, stage model accuracy degradation attacks, and obtain CPU privilege escalation. GPUBreach extends GPUHammer (July 2025), the first practical RowHammer attack targeting NVIDIA GPUs using GDDR6 memory. GDDRHammer and GeForge are concurrent works also using GPU page-table corruption via GDDR6 RowHammer. GeForge requires IOMMU to be disabled, whereas GPUBreach and GDDRHammer work with IOMMU enabled. The compromise has serious implications for cloud AI infrastructure, multi-tenant GPU deployments, and HPC environments.

Patch Priority

General Security News

Gritman Medical Center Reopens After Cybersecurity Incident

Gritman Medical Center in Moscow, Idaho reopened clinics on Friday after a cybersecurity incident disrupted outpatient care beginning Wednesday. Multiple primary and specialty clinics were closed due to an electronic systems outage, including Downtown Clinic, Westside Clinic, general surgery, gastroenterology, orthopedic surgery, therapy, pain, sleep, urology, and family medicine locations. The hospital and emergency department remained open throughout. Electronic systems came back online Friday and normal clinic operations resumed Monday, April 6. The incident was publicly disclosed Thursday.

Maine House Advances Bill to Strengthen Hospital Cybersecurity

Maine House voted unanimously Thursday to advance LD 2103, a bill requiring Maine hospitals to adopt cybersecurity measures and ensure continuity of patient care when future cyberattacks occur. The bill aims to prevent cybersecurity attacks on Maine hospitals. The measure was introduced by Rep. Julie McCabe, D-Lewiston.

Microsoft Fixes Classic Outlook Bug Causing Email Delivery Issues

Microsoft resolved a known issue preventing some Classic Outlook users from sending emails via Outlook.com. Affected users received non-delivery reports (NDRs) with 0x80070005-0x0004dc-0x000524 errors warning "This message could not be sent. Try sending the message again later or contact your network administrator." The issue occurred more frequently when the Outlook.com account was an Outlook profile linked to another Exchange account, or when the sender's account had an Exchange Online mail contact with the same SMTP address. Microsoft implemented a server-side fix on April 3, 2026.

Trends & Context

Three major themes dominate this cycle: zero-day exploitation velocity is accelerating, AI is enabling both attacks and defense at new scale, and healthcare remains the highest-value ransomware target. Storm-1175's one-day weaponization of CVE-2025-31324 and their exploitation of CVE-2025-10035 and CVE-2026-23760 as zero-days before disclosure demonstrate threat actors are outpacing patch cycles. The AI-enabled device code phishing campaign shows how generative AI and automation platforms are lowering the barrier for sophisticated social engineering at scale. Every major ransomware story today involves healthcare: Storm-1175 heavily impacting healthcare organizations, Pay2Key targeting a US healthcare provider, and Maine advancing legislation specifically to protect hospitals. The pattern is clear - patch faster, assume breach, and prioritize healthcare infrastructure defense.