← Carolina Clear Tech

Cyber Threat Brief

2026-04-11

Listen to this brief (16:02)

Download MP3
Show Notes

Show Notes - 2026-04-11

Stories Covered

CVEs Referenced

CVE-2026-24302, CVE-2026-27140, CVE-2026-27143, CVE-2026-27144, CVE-2026-28389, CVE-2026-28810, CVE-2026-29181, CVE-2026-32280, CVE-2026-32281, CVE-2026-32282, CVE-2026-32283, CVE-2026-32288, CVE-2026-32289, CVE-2026-33119, CVE-2026-33810, CVE-2026-35611, CVE-2026-39882, CVE-2026-39987, CVE-2026-4878, CVE-2026-5869, CVE-2026-5871, CVE-2026-5876, CVE-2026-5883, CVE-2026-5884, CVE-2026-5886, CVE-2026-5888, CVE-2026-5889, CVE-2026-5891, CVE-2026-5893, CVE-2026-5894, CVE-2026-5896, CVE-2026-5899

Read the full brief

Get tomorrow's brief in your inbox

Protect Your Business

Need a security assessment? See our cybersecurity packages.

View Services

Daily Security Brief - 2026-04-11

Today: Marimo Python notebook flaw CVE-2026-39987 exploited within 10 hours of disclosure, CPUID hacked to deliver malware through CPU-Z and HWMonitor downloads, and Silent Ransom Group leaked data from second major law firm after Orrick refused $1M offer. Time-to-exploit now averaging negative seven days according to new Qualys research.

Critical Alerts

Marimo RCE Flaw CVE-2026-39987 Exploited Within 10 Hours of Disclosure

A critical pre-authenticated remote code execution vulnerability in Marimo, an open-source Python notebook for data science, was exploited within 10 hours of public disclosure. CVE-2026-39987 (CVSS 9.3, EPSS 0.027/86th percentile) affects all versions prior to 0.20.4. The terminal WebSocket endpoint /terminal/ws lacks authentication validation, allowing attackers to obtain a full PTY shell without credentials. Sysdig observed the first exploitation attempt on a honeypot system 9 hours and 41 minutes after disclosure, with the attacker manually exploring the filesystem and harvesting credentials from .env files and SSH keys. The attacker returned an hour later to confirm access, consistent with a human operator working through a target list. No proof-of-concept code was available at the time of the first attack.

CPUID Hacked to Deliver Malware via CPU-Z, HWMonitor Downloads

Hackers compromised a secondary API for the CPUID project and modified download links on the official website to serve malicious executables for CPU-Z and HWMonitor, two widely-used system monitoring utilities with millions of users. The compromise lasted approximately six hours between April 9 and April 10. Users who downloaded either tool received trojanized versions that fetched a Russian installer with an Inno Setup wrapper, masquerading as HWiNFO (a different developer's tool). The malware uses advanced techniques including file masquerading, multi-stage execution, in-memory operation, and NTDLL proxying from .NET assemblies to evade detection. Researchers at vxunderground identified the same threat group behind last month's FileZilla supply chain attack, suggesting a campaign targeting widely-used utilities. CPUID has since fixed the issue and original signed files were not compromised.

Ransomware & Extortion

Silent Ransom Group Leaked Orrick Law Firm After $1M Offer Rejected

Silent Ransom Group (also known as Luna Moth, Chatty Spider, or UNC3753) leaked data from international law firm Orrick, Herrington & Sutcliffe LLP after the firm's $1 million settlement offer fell short of the ransom demand. The group gained access on January 20, 2026, and remained in Orrick's network for approximately one week without deploying malware. This is the second major law firm hit by SRG in recent months, following the Jones Day breach. Orrick, which has over 25 offices across the US, Europe, and Asia with $1.5 billion in gross revenue, had previously settled an $8 million class-action lawsuit in 2024 related to a 2023 data breach affecting 461,000 people. During negotiations, Orrick's representative made reasonable points about the limits of paying for "the word of a stranger," but the firm never approached SRG's demanded amount. SRG stated this was the first top-100 law firm to offer such a low sum, noting that top firms typically recognize the seriousness and pay. The group uses phishing and social engineering for initial access and contacted Orrick employees and clients during the intrusion.

Lotte Card Faces $3M Penalty, 4-Month Business Suspension Over Data Breach

South Korea's Financial Supervisory Service notified Lotte Card of approximately 5 billion won ($3.38 million) in penalties and a business suspension exceeding four months over a massive data leak affecting almost 3 million customers. This is the second monetary penalty action involving Lotte Card this year, both stemming from the same incident. The suspension prevents new customer sign-ups, creating significant business impact beyond the financial penalty. South Korea regulators continue to demonstrate stricter consequences for data breaches compared to most jurisdictions, including business suspensions and executive fines. This is not the first time Lotte Card has faced business suspension consequences from a breach.

General Security News

Analysis of One Billion CISA KEV Remediation Records Exposes Limits of Human-Scale Security

New research from the Qualys Threat Research Unit analyzing over one billion CISA KEV remediation records from 10,000 organizations over four years quantifies the structural failure of enterprise vulnerability management. Despite organizations closing 400 million more vulnerability events annually than baseline, the percentage of critical vulnerabilities still open at seven days worsened from 56% to 63%. Time-to-exploit has collapsed to negative seven days according to Google M-Trends 2026, meaning adversaries weaponize the most serious vulnerabilities before patches exist. Of 52 high-profile weaponized vulnerabilities tracked with complete timelines, 88% were remediated slower than they were exploited. Spring4Shell was exploited two days before disclosure but took an average of 266 days to remediate. Cisco IOS XE was weaponized a month early with average remediation at 263 days. The research identifies a "Manual Tax" where long-tail assets that human processes cannot reach drag exposure from weeks into months. For infrastructure systems like Cisco IOS XE, even the median remediation was 232 days. The research introduces "Risk Mass" (vulnerable assets multiplied by days exposed) and "Average Window of Exposure" (AWE) as more meaningful metrics than CVE counts. The study concludes that staffing cannot solve this problem and autonomous, closed-loop risk operations are required to match the speed of AI-powered attackers.

Anthropic's Mythos AI Can Find Zero-Days 72% of the Time

Anthropic launched Project Glasswing, a coalition committing $100 million in AI resources to hunt vulnerabilities in open source software using its new Mythos AI program. Mythos Preview can generate working exploits 72.4% of the time, compared to Claude Opus 4.6 which barely finds zero-days. Anthropic claims Mythos "surpasses all but the most skilled humans at finding and exploiting software vulnerabilities." The program offers free access with $100 million in usage credits for Mythos Preview and $4 million in direct donations to open source security organizations. Anthropic reports finding a 27-year-old bug in OpenBSD, a 16-year-old vulnerability in FFmpeg, and new chained exploits in the Linux kernel enabling privilege escalation to root. However, open source maintainers express concern about the burden this creates. Curl founder Daniel Stenberg noted that while AI bug reports have improved in recent months, they typically do not come with fixes, adding significant load to already under-resourced maintainer teams. Several companies and "armies of users" will fill maintainer inboxes while far fewer maintainers exist to process and fix the findings. AIs are not yet as good at fixing problems as finding them, creating an imbalance.

FCC Foreign-Made Router Policy Faces Industry Pushback

The Global Electronics Association warns that the FCC's ban on foreign-made network routers is impractical because few are made domestically, leaving consumers with limited choices and delayed access to next-generation products like Wi-Fi 7. The FCC policy prohibits approval of new foreign-made consumer router models unless vendors commit to US manufacturing and submit detailed, time-bound onshoring plans. The policy requires Department of Defense or Department of Homeland Security clearance, but neither agency has previously staffed or resourced a process designed around consumer electronics product cycles. The GEA points out that vulnerabilities are not limited to any geography and the most damaging known intrusions, including Salt Typhoon's penetration of American carriers, exploited US-made equipment running unpatched software. The policy affects over 100 million consumer routers currently in active use across the US. The GEA estimates that if the approval process cannot achieve sufficient throughput within 6 to 12 months, consumers and ISPs will face constrained selection, leaving many unable to replace aging routers and more vulnerable to attacks exploiting security flaws in outdated devices.

Patch Priority

Vulnerability Disclosures

Go Language Multiple CVEs

Microsoft Security Response Center published multiple Go language vulnerabilities including CVE-2026-32288 (unbounded allocation in archive/tar, EPSS 0.000/1st percentile), CVE-2026-32283 (unauthenticated TLS 1.3 KeyUpdate DoS in crypto/tls, EPSS 0.000/0th percentile), CVE-2026-28810 (predictable DNS transaction IDs enabling cache poisoning, EPSS 0.001/16th percentile), CVE-2026-32282 (TOCTOU root escape on Linux, EPSS 0.000/1st percentile), CVE-2026-33810 (case-sensitive name constraints auth bypass in crypto/x509, EPSS 0.000/0th percentile), CVE-2026-32281 (inefficient policy validation in crypto/x509, EPSS 0.000/0th percentile), CVE-2026-32289 (XSS in html/template, EPSS 0.000/1st percentile), CVE-2026-32280 (unexpected work during chain building in crypto/x509, EPSS 0.000/4th percentile), CVE-2026-27143 (memory corruption in cmd/compile, EPSS 0.000/1st percentile), CVE-2026-27144 (miscompilation allows memory corruption in cmd/compile, EPSS 0.000/1st percentile), and CVE-2026-27140 (code execution in SWIG code generation in cmd/go, EPSS 0.000/1st percentile).

Microsoft Edge Chromium CVEs

Multiple Chromium-based vulnerabilities affecting Microsoft Edge including CVE-2026-5869 (heap buffer overflow in WebML, EPSS 0.000/8th percentile), CVE-2026-5871 (type confusion in V8, EPSS 0.000/11th percentile), CVE-2026-5876 (side-channel information leakage in Navigation, EPSS 0.000/10th percentile), CVE-2026-5883 (use after free in Media, EPSS 0.000/11th percentile), CVE-2026-5884 (insufficient validation in Media, EPSS 0.001/16th percentile), CVE-2026-5886 (out of bounds read in WebAudio, EPSS 0.000/9th percentile), CVE-2026-5888 (uninitialized use in WebCodecs, EPSS 0.000/9th percentile), CVE-2026-5889 (cryptographic flaw in PDFium, EPSS 0.000/1st percentile), CVE-2026-5891 (insufficient policy enforcement in browser UI, EPSS 0.000/9th percentile), CVE-2026-5893 (race in V8, EPSS 0.000/9th percentile), CVE-2026-5894 (inappropriate implementation in PDF, EPSS 0.000/3rd percentile), CVE-2026-5896 (policy bypass in Audio, EPSS 0.000/3rd percentile), and CVE-2026-5899 (incorrect security UI in History Navigation, EPSS 0.001/17th percentile). Microsoft Edge ingests Chromium updates to address these vulnerabilities.

CVE-2026-33119 Microsoft Edge for Android Spoofing Vulnerability

User interface misrepresentation of critical information in Microsoft Edge (Chromium-based) for Android allows an unauthorized attacker to perform spoofing over a network. EPSS data not yet available.

CVE-2026-4878 Libcap Privilege Escalation

Libcap privilege escalation vulnerability via TOCTOU race condition in cap_set_file(). EPSS 0.000 (1st percentile).

OpenTelemetry-Go CVEs

CVE-2026-29181 (multi-value baggage header extraction causes excessive allocations for remote DoS amplification, EPSS 0.000/12th percentile) and CVE-2026-39882 (OTLP HTTP exporters read unbounded HTTP response bodies, EPSS 0.000/3rd percentile).

CVE-2026-28389 OpenSSL NULL Dereference

Possible NULL dereference when processing CMS KeyAgreeRecipientInfo. EPSS 0.000 (7th percentile).

CVE-2026-35611 Addressable Regular Expression DoS

Addressable has a regular expression denial of service vulnerability in Addressable templates. EPSS 0.000 (12th percentile).

CVE-2026-24302 Azure Arc Elevation of Privilege

Azure Arc elevation of privilege vulnerability. EPSS 0.001 (29th percentile). Informational change, acknowledgement added.

Trends & Context

The collapse of time-to-exploit to negative seven days fundamentally changes vulnerability management. When 88% of weaponized vulnerabilities are exploited faster than they are remediated, the operational model breaks down. Supply chain attacks targeting widely-used utilities (CPUID, FileZilla) demonstrate attackers are systematically targeting trust relationships rather than just finding zero-days. The rapid exploitation of Marimo within 10 hours, with attackers building exploits directly from advisories without proof-of-concept code, confirms defenders face an impossibly narrow window between disclosure and weaponization.