← Carolina Clear Tech

Cyber Threat Brief

2026-04-12

Listen to this brief (10:05)

Download MP3
Show Notes

Show Notes - 2026-04-12

Stories Covered

CVEs Referenced

CVE-2026-34621, CVE-2026-34757, CVE-2026-35206, CVE-2026-39853, CVE-2026-39855, CVE-2026-39856, CVE-2026-40226

Read the full brief

Get tomorrow's brief in your inbox

Protect Your Business

Need a security assessment? See our cybersecurity packages.

View Services

Daily Security Brief - 2026-04-12

Today: Adobe patches actively exploited Acrobat Reader zero-day CVE-2026-34621 with evidence of exploitation since December. Two major supply chain attacks hit Trivy and Axios. Brockton Hospital in week two of Anubis ransomware recovery with prescription systems still offline.

Critical Alerts

Adobe Acrobat Reader Zero-Day CVE-2026-34621

Adobe released emergency patches for a critical prototype pollution vulnerability (CVE-2026-34621, CVSS 8.6) in Acrobat Reader that has been actively exploited in the wild since December 2025. The flaw allows arbitrary code execution when opening specially crafted PDF documents. Security researcher Haifei Li disclosed the zero-day exploitation after observing malicious JavaScript execution through weaponized PDFs. Adobe initially scored this vulnerability at 9.6 but revised it down to 8.6 after changing the attack vector from Network to Local. EPSS scoring shows this at 0.002 (46th percentile), but active exploitation confirms real-world targeting.

Ransomware Claims (Last 48h)

2 claims tracked across 2 groups in the last 48 hours. These are unverified claims from ransomware leak sites, not confirmed breaches.

Group Victim Sector Country
Lamashtu Gauthier Tissus Manufacturing France
Blackwater Medical Park Healthcare Turkey

Ransomware & Extortion

Brockton Hospital Anubis Ransomware Attack

Brockton Hospital (Signature Healthcare) remains in downtime procedures two weeks after an Anubis ransomware attack on March 29. Many services have resumed but new prescription orders still cannot be filled. The hospital diverted ambulances, canceled chemotherapy appointments, and implemented paper-based workflows during the initial response. Anubis operators reached out to media attempting to portray themselves as careful actors who avoided encrypting critical systems, but the hospital's prolonged operational impact contradicts those claims. Anubis operates as ransomware-as-a-service and the spokesperson admitted to SuspectFile they had encrypted systems. The hospital expects to continue downtime procedures for another two weeks.

Business & Infrastructure Threats

Supply Chain Attacks Target Trivy Scanner and Axios Library

Two separate supply chain attacks in March infected widely-used open source tools with credential-stealing malware. TeamPCP compromised Trivy (100,000+ users) on March 16, injecting malware into the vulnerability scanner's binary, GitHub Actions, and container images. The malware harvested CI/CD secrets, cloud credentials, SSH keys, and Kubernetes configs while planting persistent backdoors. TeamPCP then used stolen Trivy credentials to compromise the KICS static analysis tool on March 23 and published malicious versions of LiteLLM and Telnyx to PyPI. A separate North Korean-linked campaign hit Axios (100 million weekly downloads, used in 80% of cloud environments) with similar goals. Mandiant CTO Charles Carmakal expects stolen credentials to be leveraged for months, with expanding blast radius as attackers pivot using compromised secrets. Both campaigns demonstrate advanced social engineering skills and deep understanding of developer environments.

CPUID Website Breach Distributes STX RAT via Trojanized CPU-Z Downloads

Unknown attackers compromised the CPUID website (cpuid.com) on April 9-10 for less than 24 hours, replacing download links for CPU-Z and HWMonitor with trojanized installers hosting STX RAT. The breach affected a secondary API that caused the main site to randomly display malicious download URLs pointing to cahayailmukreatif.web.id, pub-45c2577dbd174292a02137c18e7b1b5a.r2.dev, transitopalermo.com, and vatrobran.hr. Malicious installers contained legitimate signed executables paired with a malicious CRYPTBASE.dll that leveraged DLL side-loading. The DLL performs anti-sandbox checks before deploying STX RAT, a remote access trojan with HVNC and broad infostealer capabilities. Kaspersky identified 150+ victims across retail, manufacturing, consulting, telecom, and agriculture sectors, mostly in Brazil, Russia, and China. Attackers reused the same infection chain and C2 infrastructure from a prior campaign using fake FileZilla installers.

General Security News

Operation Atlantic Identifies 20,000 Cryptocurrency Fraud Victims

International law enforcement operation led by the UK's National Crime Agency identified over 20,000 cryptocurrency fraud victims across Canada, UK, and US. The week-long operation in March involved the NCA, US Secret Service, Ontario Provincial Police, and Ontario Securities Commission working from the NCA's London headquarters. Investigators froze $12 million in suspected criminal proceeds from approval phishing attacks where scammers trick victims into granting wallet access through investment scams. An additional $45 million in stolen cryptocurrency was identified worldwide. The NCA reports 77% of victims were unaware they were being scammed. The FBI's parallel Operation Level Up has identified 8,000 cryptocurrency investment fraud victims since January 2024, with estimated savings of $511 million. The FBI's 2025 Internet Crime Report shows 61,559 complaints of cryptocurrency investment fraud totaling $7.228 billion in losses, a 48% increase in complaints and 25% increase in losses from 2024.

Patch Priority

Vulnerability Disclosures

Microsoft Security Update Guide CVEs

Microsoft published security advisories for multiple CVEs affecting open source components and libraries. CVE-2026-35206 affects Helm Chart extraction with directory collapse via Chart.yaml name dot-segment (EPSS 0.000, 2nd percentile). CVE-2026-34757 is a use-after-free in libpng affecting png_set_PLTE, png_set_tRNS, and png_set_hIST leading to corrupted chunk data and potential heap information disclosure (EPSS 0.000, 2nd percentile). Three CVEs affect osslsigncode: CVE-2026-39853 stack buffer overflow via unbounded digest copy during signature verification (EPSS 0.000, 3rd percentile), CVE-2026-39855 integer underflow in PE page hash calculation causing out-of-bounds read (EPSS 0.000, 4th percentile), and CVE-2026-39856 out-of-bounds read via unvalidated section bounds in PE page hash calculation (EPSS 0.000, 4th percentile). CVE-2026-40226 was also published without description (EPSS 0.000, 0 percentile).

Trends & Context

Supply chain attacks are evolving with attackers demonstrating deep understanding of developer workflows and CI/CD pipelines. The Trivy and Axios campaigns show credential harvesting as a primary goal with long-tail exploitation expected over months. Active exploitation of Adobe Reader zero-day since December highlights the gap between vulnerability introduction and public disclosure. Healthcare ransomware continues despite operator claims of avoiding patient harm, with Brockton Hospital entering week three of degraded operations.