← Carolina Clear Tech

Cyber Threat Brief

2026-04-09

Listen to this brief (19:04)

Download MP3
Show Notes

Show Notes - 2026-04-09

Stories Covered

CVEs Referenced

CVE-2016-3088, CVE-2023-46604, CVE-2023-50224, CVE-2024-32114, CVE-2026-1340, CVE-2026-21509, CVE-2026-21513, CVE-2026-28387, CVE-2026-28388, CVE-2026-31789, CVE-2026-31790, CVE-2026-33634, CVE-2026-34197, CVE-2026-34445, CVE-2026-34446, CVE-2026-34933, CVE-2026-35093, CVE-2026-39314

Read the full brief

Get tomorrow's brief in your inbox

Protect Your Business

Need a security assessment? See our cybersecurity packages.

View Services

Daily Cybersecurity Brief

April 9, 2026

Today: CISA adds actively exploited Ivanti EPMM flaw to KEV catalog with today's deadline. A 13-year-old Apache ActiveMQ bug enables unauthenticated RCE, discovered by Claude AI. Adobe Reader zero-day targets Russian oil and gas sectors with no user interaction required.

Critical Alerts

Ivanti EPMM Code Injection (CVE-2026-1340)

CISA added CVE-2026-1340 to the Known Exploited Vulnerabilities catalog based on evidence of active exploitation. This code injection vulnerability affects Ivanti Endpoint Manager Mobile (EPMM) and carries an EPSS score of 67.7% (99th percentile), indicating high probability of exploitation. Federal agencies face a remediation deadline of April 9, 2026.

Adobe Reader Zero-Day Exploited Since December

Attackers have exploited an unpatched Adobe Reader vulnerability using malicious PDF documents since at least December 2025. Security researcher Haifei Li discovered the attacks using a fingerprinting-style PDF exploit that works on the latest Adobe Reader version without user interaction beyond opening the file. The exploit leverages privileged Acrobat APIs (util.readFileIntoStream and RSS.addFeed) to steal local data and deploy additional RCE/sandbox escape attacks. PDF lures contain Russian-language content targeting the oil and gas industry.

TeamPCP Supply Chain: Cisco Breach via Trivy, KEV Deadline Arrives (CVE-2026-33634)

The TeamPCP supply chain campaign (now tracked by Google GTIG as UNC6780) breached Cisco's development environment via Trivy-compromised credentials. Attackers stole 300+ private GitHub repositories containing AI product source code, customer code for banks and US government agencies, and AWS keys used for unauthorized cloud activities. Multiple threat actors participated in the breach. ShinyHunters claimed access to 3+ million Salesforce records and alleged victim data includes FBI, DHS, DISA, IRS, NASA, Australian Ministry of Defense, and Indian government agencies. CISA KEV deadline for CVE-2026-33634 is today (April 9, 2026) with EPSS 21.2% (96th percentile), yet no standalone CISA advisory has been published.

Ransomware Claims (Last 48h)

3 claims tracked from 1 group (Timc) on April 8, 2026. These are unverified claims from ransomware leak sites, not confirmed breaches.

Group Victim Sector Country
Timc oncologica.com Healthcare Unknown
Timc seidor.com IT Services Unknown
Timc debene.com Unknown Unknown

Source: RansomLook

Ransomware & Extortion

Dutch Healthcare Vendor ChipSoft Hit by Ransomware

ChipSoft, a Dutch healthcare software vendor serving 80% of hospitals in the Netherlands, went offline April 7 following a ransomware attack confirmed by Z-CERT. The company's website remains unreachable while email functions continue. Eleven hospitals pulled ChipSoft systems offline as a precaution, nine of which rely heavily on the software for patient records. The majority of ChipSoft customers retain access to patient portals. The threat group has not been identified. Z-CERT recommends auditing ChipSoft systems for unusual traffic and reporting suspicious activity.

Iran-Linked Pay2Key Targets US Healthcare with Destructive Intent

Former FBI cyber chief Cynthia Kaiser (now at Halcyon Ransomware Research Center) investigated a late February Pay2Key attack against a US healthcare organization coinciding with US-Israel military strikes on Iran. The Iran-government-linked group had compromised admin account access for several days before deploying ransomware that encrypted the environment in three hours. The variant showed significant anti-detection upgrades from July 2025 versions. Unusually, no data was stolen, suggesting destruction rather than financial motive. Kaiser draws parallels to Albania 2022 attacks where Iran maintained 14-month access for espionage before weaponizing it.

Business & Infrastructure Threats

13-Year-Old Apache ActiveMQ RCE Discovered by AI (CVE-2026-34197)

Horizon3 researcher Naveen Sunkavally discovered CVE-2026-34197, a remote code execution vulnerability in Apache ActiveMQ Classic that existed undetected for 13 years, using Claude AI analysis. The flaw (CVSS 8.8) affects ActiveMQ/Broker versions before 5.19.4 and all 6.x versions up to 6.2.3. The vulnerability stems from ActiveMQ's Jolokia management API exposing the addNetworkConnector function, allowing attackers to load external Spring XML configurations and execute arbitrary system commands. The issue requires Jolokia authentication, but becomes unauthenticated on versions 6.0.0-6.1.1 due to CVE-2024-32114 (EPSS 2.0%, 84th percentile), which exposes the API without access control. CVE-2026-34197 has EPSS 0.1% (28th percentile) but Horizon3 warns that prior ActiveMQ CVEs (CVE-2016-3088 and CVE-2023-46604) are on CISA KEV and linked to ransomware.

Russian GRU APT28 Exploits Routers for DNS Hijacking (CVE-2023-50224)

Russian GRU 85th GTsSS (APT28/Fancy Bear/Forest Blizzard) has been exploiting vulnerable SOHO routers worldwide since at least 2024 to conduct DNS hijacking operations targeting military, government, and critical infrastructure. FBI disrupted a GRU network of compromised routers including TP-Link devices exploited via CVE-2023-50224 (CISA KEV due September 24, 2025, EPSS 1.5%/81st percentile). Attackers modify DHCP/DNS settings to introduce actor-controlled DNS resolvers, which connected devices inherit. GRU provides fraudulent DNS answers for specific domains including Microsoft Outlook Web Access, enabling adversary-in-the-middle attacks against TLS-encrypted traffic if users bypass certificate warnings. GRU harvests passwords, authentication tokens, emails, and web browsing data.

Windows / AD Security

APT28 Deploys PRISMEX Malware Targeting Ukraine and NATO Allies

Russian APT28 (Forest Blizzard/Pawn Storm) launched spear-phishing campaign active since September 2025 targeting Ukraine and NATO allies with PRISMEX malware suite. Targets include Ukrainian central executive bodies, defense, emergency services, and NATO logistics partners in Poland, Romania, Slovenia, Turkey, Slovakia, and Czech Republic. APT28 rapidly weaponized CVE-2026-21509 (CISA KEV due February 16, 2026, EPSS 7.5%/92nd percentile) and CVE-2026-21513 (CISA KEV due March 3, 2026, EPSS 28.0%/96th percentile), with infrastructure preparation observed January 12, 2026, two weeks before CVE-2026-21509 disclosure. Akamai reported APT28 exploited CVE-2026-21513 as zero-day based on VirusTotal upload January 30, before Microsoft's February 10 Patch Tuesday fix. Attacks chain the vulnerabilities: CVE-2026-21509 forces retrieval of malicious LNK file, which exploits CVE-2026-21513 to bypass security and execute payloads. PRISMEX uses steganography to hide payloads in images, COM hijacking for persistence, and abuses Filen.io for C2. The COVENANT Grunt payload includes wiper functionality that erases all files under %USERPROFILE%.

General Security News

Cisco Talos: Using Year in Review for Incident Response Tabletops

Cisco Talos published guidance for incident responders on operationalizing the 2025 Year in Review findings for tabletop exercises. Key findings: identity-based attacks accounted for 60% of Talos IR cases, with Active Directory focal point in 44%. MFA spray attacks doubled down on privileged accounts, and device compromise attacks rose significantly. Manufacturing was most impacted sector for ransomware in 2025. Talos recommends tabletop scenarios based on real IR casework: adversary authenticates via VPN, user approves MFA push, attacker gains legitimate perimeter access.

AWS Bedrock AgentCore "God Mode" IAM Privilege Escalation

Palo Alto Unit 42 disclosed privilege escalation vulnerability in AWS Bedrock AgentCore starter toolkit's default IAM configuration. The toolkit's auto-create logic generates IAM roles with overly broad permissions across the entire AWS account rather than scoped to individual resources. An attacker compromising a single agent can exfiltrate proprietary ECR images, access other agents' memories, invoke every code interpreter, and extract sensitive data. AWS updated documentation following disclosure to warn default roles are "designed for development and testing purposes" and not recommended for production.

Patch Priority

Vulnerability Disclosures

CUPS and Avahi Denial of Service Vulnerabilities

Microsoft published CVE-2026-39314 affecting CUPS (integer underflow in _ppdCreateFromIPP causes root cupsd crash via negative job-password-supported, EPSS 0.0%/2nd percentile) and CVE-2026-34933 affecting Avahi (reachable assertion in transport_flags_from_domain() crashes avahi-daemon via conflicting publish flags, EPSS 0.0%/2nd percentile).

OpenSSL and ONNX Vulnerabilities

Microsoft disclosed multiple low-severity CVEs: CVE-2026-31789 (heap buffer overflow in hexadecimal conversion, EPSS 0.0%/1st percentile), CVE-2026-28387 (use-after-free in DANE client code, EPSS 0.0%/5th percentile), CVE-2026-31790 (incorrect failure handling in RSA KEM, EPSS 0.0%/1st percentile), CVE-2026-28388 (NULL pointer dereference processing delta CRL, EPSS 0.0%/1st percentile), CVE-2026-34446 (ONNX arbitrary file read via ExternalData hardlink bypass, EPSS 0.0%/1st percentile), and CVE-2026-34445 (ONNX malicious models crash servers, EPSS 0.1%/18th percentile).

Libinput Plugin Vulnerability

CVE-2026-35093 affects Libinput with unauthorized code execution and information disclosure through Lua bytecode plugins (EPSS 0.0%/4th percentile).

Trends & Context

Today's threat landscape emphasizes the convergence of nation-state tradecraft with criminal infrastructure. APT28's rapid weaponization of Windows zero-days and Iran's weaponization of dormant healthcare access demonstrate adversaries shifting from espionage to destructive operations with minimal warning. The TeamPCP supply chain campaign shows how shared credentials between threat actors create compound breach scenarios where single compromises cascade across multiple victim environments. The 13-year-old ActiveMQ vulnerability discovered by AI analysis suggests technical debt in widely deployed enterprise software poses persistent risk, especially when prior CVEs in the same product already appear on CISA KEV linked to ransomware campaigns.