← Carolina Clear Tech

Cyber Threat Brief

2026-04-10

Listen to this brief (18:24)

Download MP3
Show Notes

Show Notes - 2026-04-10

Stories Covered

CVEs Referenced

CVE-2022-41678, CVE-2024-32114, CVE-2025-13926, CVE-2025-27152, CVE-2026-23403, CVE-2026-23411, CVE-2026-34197, CVE-2026-39881, CVE-2026-40024, CVE-2026-40026, CVE-2026-4436

Indicators of Compromise

Domains: bluegraintours[.]com

IP Addresses: 169.40.2.68

Read the full brief

Get tomorrow's brief in your inbox

Protect Your Business

Need a security assessment? See our cybersecurity packages.

View Services

Daily Cybersecurity Brief - April 10, 2026

Today: Adobe Reader zero-day active since December delivers targeted payloads through malicious PDFs. Apache ActiveMQ RCE chain bypasses authentication in 13-year-old vulnerability. Healthcare provider ChipSoft taken offline by ransomware affecting Dutch hospital systems.

Critical Alerts

Adobe Reader Zero-Day Exploited Since December 2025

A zero-day vulnerability in Adobe Acrobat Reader has been actively exploited since at least December 2025 using malicious PDF documents. The exploit executes obfuscated JavaScript automatically when PDFs are opened, harvesting system data and file paths without user interaction. Once initial reconnaissance completes, attackers deliver second-stage payloads for remote code execution or sandbox escape. The malware targets Russian oil and gas sector organizations based on lure document content. Adobe has not issued a patch or assigned a CVE. Detection rates remain low with only 15 antivirus engines flagging the initial samples as malicious.

Apache ActiveMQ 13-Year RCE Chain Bypasses Authentication (CVE-2026-34197)

CVE-2026-34197 (CVSS 8.8, EPSS 90th percentile) chains with CVE-2024-32114 to enable unauthenticated remote code execution in Apache ActiveMQ Classic. Attackers invoke management operations through the Jolokia API and trick the message broker into retrieving remote configuration files containing OS commands. ActiveMQ versions 6.0.0 through 6.1.1 expose Jolokia without authentication, turning the vulnerability into a pre-auth RCE. Older versions using default credentials (admin:admin) face the same risk. The flaw bypasses CVE-2022-41678 (EPSS 100th percentile) protections and allows web shell writes to disk.

Ransomware & Extortion

ChipSoft Healthcare IT Provider Offline After Ransomware Attack

Dutch electronic health record provider ChipSoft shut down its website and patient-facing services following a ransomware incident. The company's HiX platform is used by 70% of Dutch hospitals. ChipSoft warned healthcare institutions of possible unauthorized access and advised them to disconnect from its systems pending cleanup. Multiple hospitals confirmed outages including Sint Jans Gasthuis, Laurentius, VieCuri, and Flevo Hospital. Z-CERT, the Netherlands healthcare cybersecurity response team, is coordinating recovery efforts. No ransomware group has claimed responsibility.

FBI Reports $17.7 Billion in Cyber Fraud Losses for 2025

Cyber-enabled fraud cost victims $17.7 billion in 2025, a 26% increase over 2024. Cryptocurrency investment scams led losses at $7.2 billion. Business email compromise accounted for $3 billion and tech support scams reached $2.1 billion. Ransomware losses totaled $32 million across 63 variants. Top ransomware families targeting critical manufacturing, healthcare, and government included Akira, Qilin, INC/Lynx, BianLian, Play, RansomHub, LockBit, DragonForce, Safepay, and Medusa.

Business & Infrastructure Threats

Storm-2755 Payroll Diversion Campaign Targets Canadian Employees (CVE-2025-27152)

Microsoft DART observed financially-motivated threat actor Storm-2755 using malvertising and SEO poisoning to hijack Canadian employee payroll. The actor registered bluegraintours[.]com and positioned it at the top of search results for "Office 365" and misspellings like "Office 265." Victims clicking the link reach a fake Microsoft 365 login page that performs adversary-in-the-middle attacks to steal session tokens and bypass MFA. Storm-2755 maintains persistence through the hijacked session, changes payroll direct deposit accounts, and diverts salary payments to attacker-controlled banks. Sign-in logs show user-agent shifts to Axios 1.7.9 when sessions transfer to attacker control. Microsoft has taken down the malicious tenant.

VENOM PhaaS Targets C-Suite Executives with QR Code Phishing

A closed-access phishing-as-a-service platform called VENOM targets credentials of CEOs, CFOs, and VPs across multiple industries. Attack emails impersonate SharePoint notifications with personalized content and fake email threads. QR codes rendered in Unicode bypass scanning tools and shift attacks to mobile devices. Target email addresses are double Base64-encoded in URL fragments, making them invisible to server logs and reputation feeds. Landing pages filter security researchers before redirecting victims to credential harvesting sites. VENOM proxies Microsoft login flows in real time to capture MFA codes and session tokens. The platform also offers device code phishing to establish persistent access resistant to password resets.

Microsoft Locks Out VeraCrypt and WireGuard Developers Without Warning

Microsoft deactivated developer accounts for VeraCrypt creator Mounir Idrassi and WireGuard developer Jason Donenfeld without prior notification or explanation. Both developers lost access to code signing systems required to publish driver updates. Idrassi cannot sign VeraCrypt drivers or bootloaders through the hardware dashboard. Donenfeld completed weeks of WHLK testing and purchased an EV code signing certificate before discovering his account was suspended. The appeals process requires an active account to file, creating a catch-22. Microsoft confirmed appeals take 60 days. The lockouts prevent security updates if vulnerabilities are discovered in either project during the suspension period.

Phorpiex Botnet Resurges with Hybrid P2P Communication

A new variant of the Phorpiex (Trik) botnet uses hybrid C2 combining HTTP polling with peer-to-peer TCP and UDP protocols to survive server takedowns. The Twizt variant drops cryptocurrency clippers that redirect transactions, distributes sextortion spam, and deploys LockBit Black and Global ransomware. The malware propagates through removable drives, exfiltrates mnemonic phrases, and scans for local file inclusion vulnerabilities. Phorpiex encrypts payloads to prevent external command injection. The botnet averages 125,000 daily infections concentrated in Iran, Uzbekistan, China, Kazakhstan, and Pakistan.

LA City Attorney's Office Hacked, 7.7TB of Sensitive Data Leaked

The Los Angeles city attorney's office was breached and 7.7TB of sensitive data published online. Leaked files include case details, personal information of LA police officers, witness names, medical records, and internal affairs investigations. No ransomware group has claimed responsibility.

FleetWave Car Fleet Management Platform Disrupted by Cyberattack

A cyberattack took down FleetWave, a fleet management platform used by local governments to assign vehicles, schedule maintenance, and manage fuel allocations. Several US local governments lost access to vehicle management systems.

Windows / AD Security

When MFA Fails: Credential Exposure Enables Session Hijacking

Financial services company Figure exposed 967,200 email records without exploitation. The breach demonstrates how credential exposure defeats MFA when attackers use real-time phishing relays. Adversary-in-the-middle frameworks proxy authentication flows, capturing session cookies and OAuth tokens as they are issued. When victims enter credentials and respond to MFA challenges on spoofed pages, proxies forward them to legitimate services in real time. Credential stuffing campaigns against fresh email lists achieve 2-3% success rates. On 967,000 records, this yields 19,000 to 29,000 valid credential pairs. AI-assisted tooling generates personalized phishing at scale. Help desk social engineering bypasses authentication entirely by targeting password and MFA reset processes.

BlueHammer Windows Zero-Day Released After Microsoft Disclosure Dispute

A researcher operating as Chaotic Eclipse released a proof-of-concept exploit for a Windows zero-day allowing local privilege escalation to SYSTEM. The researcher cited a dispute with Microsoft's vulnerability disclosure process as the reason for public release. No CVE has been assigned. Microsoft has not commented on the vulnerability or patch timeline.

General Security News

UAT-10362 Targets Taiwan NGOs with LucidRook Malware

Threat actor UAT-10362 deployed Lua-based LucidRook malware against Taiwanese NGOs and universities through spear-phishing campaigns. Attacks use RAR or 7-Zip archives containing LNK files with PDF icons or fake Trend Micro antivirus executables. LucidPawn dropper uses DLL side-loading to deploy LucidRook. The malware embeds a Lua 5.4.8 interpreter to execute remotely-delivered bytecode payloads, allowing operators to update functionality without modifying the core binary. LucidRook collects system information, installed applications, and running processes, encrypts data with RSA, and exfiltrates via FTP to compromised servers and OAST services. A companion tool, LucidKnight, exfiltrates data via Gmail SMTP. Both droppers geofence execution to Traditional Chinese (zh-TW) environments matching Taiwan to avoid sandbox detection.

EngageLab SDK Intent Redirection Exposed 30M Crypto Wallet Users

Microsoft disclosed an intent redirection vulnerability in EngageLab SDK affecting over 30 million cryptocurrency wallet installations and 50 million total Android app installs. The flaw in version 4.5.4 allows malicious apps on the same device to bypass Android sandbox protections and access private data in apps using the SDK. Attackers could steal credentials, financial data, and personally identifiable information. EngageLab patched the issue in version 5.2.1 released November 2025. Google removed all apps using vulnerable SDK versions from Play Store. Android deployed automatic user protections against the specific exploitation vector.

Obfuscated JavaScript Drops Formbook via Multi-Stage Loader

A 10MB obfuscated JavaScript file (cbmjlzan.JS) distributed via phishing emails in RAR archives deploys Formbook malware. The script uses ActiveXObject and ADODB.Stream to copy itself to C:\Users\Public\Libraries\ and establishes persistence through a scheduled task running every 15 minutes. Three PNG files (Brio.png, Orio.png, Xrio.png) dropped to C:\Users\Public contain encrypted payloads. PowerShell decrypts Xrio.png with AES to extract evasion code patching EtwEventWrite() and AmsiScanBuffer(). Orio.png decrypts to a .NET DLL injected into MSBuild.exe. The DLL loads Brio.png containing the final Formbook payload. Detection remains low with only 15 antivirus engines flagging the initial JavaScript.

Shadow AI Creates Uncontrolled Data Exposure and Attack Surface

Employees adopt AI tools without IT approval, creating shadow AI that processes sensitive data outside security controls. A 2024 Salesforce survey found 55% of employees use unapproved AI tools. Generative AI platforms can exfiltrate customer data, financial information, and hardcoded credentials when developers paste code for troubleshooting. Traditional network monitoring cannot detect AI usage through personal accounts or devices. AI agents operating autonomously create complex exploitation pathways. GDPR and HIPAA violations occur when data transfers lack audit trails.

China National Supercomputing Center Hacked, Petabytes of Military Data Leaked

Threat actor FlamingChina breached China's National Supercomputing Center (NSCC) and leaked petabytes of data including files marked "secret" containing military and government information. The breach was published in March but took weeks to verify due to data volume. FlamingChina first appeared in February 2026.

Patch Priority

Vulnerability Disclosures

GPL Odorizers GPL750 Modbus Manipulation (CVE-2026-4436)

CVE-2026-4436 allows low-privileged remote attackers to send Modbus packets manipulating register values controlling odorant injection into gas lines. Successful exploitation results in too much or too little odorant being injected. Affected versions include GPL750 XL4 (v1.0 to v6.0), XL4 Prime (v4.0 to v6.0), XL7 (v13.0 to v20.0), and XL7 Prime (v18.4 to v20.0). GPL Odorizers recommends updating to version 20.0 and applying latest Horner Automation firmware (15.76 for XL Series, 17.30 for XL Prime Series).

Contemporary Controls BASC 20T Network Sniffing (CVE-2025-13926)

CVE-2025-13926 allows attackers sniffing network traffic to forge packets making arbitrary requests to Contemporary Controls BASC 20T PLCs. Successful exploitation enables enumeration of component functionality, reconfiguration, renaming, deletion, file transfers, and remote procedure calls. The BASC-20T is obsolete. Contemporary Controls recommends contacting support for migration options.

Microsoft AppArmor and Sleuth Kit CVEs

Microsoft published CVE details for multiple Linux subsystem vulnerabilities. CVE-2026-23403 through CVE-2026-23411 address AppArmor memory leaks, double frees, bounds check failures, and race conditions. CVE-2026-40024 through CVE-2026-40026 fix Sleuth Kit path traversal and out-of-bounds reads. All have EPSS scores below 1st percentile. CVE-2026-39881 patches Vim NetBeans integration command injection with EPSS 33rd percentile.

Trends & Context

Zero-day exploitation targeting widely-deployed software continues with Adobe Reader and Apache ActiveMQ vulnerabilities demonstrating long dwell times before detection. Healthcare IT supply chain attacks show cascading impact when shared platforms serving multiple organizations are compromised. Session hijacking and MFA bypass through real-time phishing relays render legacy multi-factor authentication insufficient against sophisticated credential theft campaigns. Organizations must deploy phishing-resistant authentication and conditional access policies monitoring for mid-session anomalies.