← Carolina Clear Tech

Cyber Threat Brief

2026-04-13

Listen to this brief (11:15)

Download MP3
Show Notes

Show Notes - 2026-04-13

Stories Covered

CVEs Referenced

CVE-2026-39987

Indicators of Compromise

IP Addresses: 0.0.0.0

Read the full brief

Get tomorrow's brief in your inbox

Protect Your Business

Need a security assessment? See our cybersecurity packages.

View Services

Daily IT Security Brief - 2026-04-13

Today: Critical Marimo RCE exploited within 10 hours of disclosure. OpenAI revokes macOS certificates after North Korean supply chain attack. Microsoft 365 mailbox rules remain a persistent threat with 10% of compromised accounts targeted for credential exfiltration and thread hijacking.

Critical Alerts

Marimo pre-auth RCE (CVE-2026-39987)

A critical unauthenticated RCE vulnerability in Marimo reactive Python notebook platform saw active exploitation begin just 10 hours after public disclosure on April 8. CVE-2026-39987 (CVSS 9.3, EPSS 2.7% / 86th percentile) affects versions 0.20.4 and earlier. The flaw exposes the '/terminal/ws' WebSocket endpoint without authentication, giving attackers direct shell access with Marimo process privileges. First exploitation occurred in credential theft operations targeting .env files and SSH keys, completed in under three minutes. Attackers demonstrated methodical reconnaissance (pwd, whoami, ls) followed by environment variable extraction and credential harvesting. No persistence mechanisms deployed, suggesting stealthy credential theft operations. 125 IP addresses began reconnaissance within the first 12 hours.

Business & Infrastructure Threats

OpenAI macOS Certificate Revocation After Axios Supply Chain Attack

OpenAI revoked its macOS app signing certificate after a GitHub Actions workflow downloaded the malicious Axios npm package (versions 1.14.1, 0.30.4) on March 31. Google attributes the supply chain compromise to North Korean threat group UNC1069, which hijacked the package maintainer's npm account and embedded the "plain-crypto-js" dependency deploying cross-platform backdoor WAVESHAPER.V2. The compromised workflow had access to certificate and notarization materials for ChatGPT Desktop, Codex, Codex CLI, and Atlas. OpenAI found no evidence the signing certificate was successfully exfiltrated due to payload execution timing and job sequencing, but is treating the certificate as compromised out of caution. No user data, internal systems, or intellectual property were compromised.

Mailbox Rules as Post-Exploitation Persistence in Microsoft 365

Malicious mailbox rules are deployed in approximately 10% of compromised Microsoft 365 accounts in Q4 2025. Attackers abuse native mailbox rules for covert data exfiltration, persistence, and email suppression to hide security alerts. Auto-forwarding rules persist after password resets, maintaining visibility into victim mailboxes as long as the rule exists. Attackers favor minimal, nonsensical rule names (single characters like ".", "...", ";") and actions including deletion, moving messages to Archive or RSS Subscriptions folders, or forwarding to external accounts. Rules target keywords ("invoice", "wire", "contract") or specific senders to collect high-value data. Suppression rules hide password reset emails, MFA notifications, and security alerts to prevent detection.

PlugX RAT Distributed via Fake Claude Website

Fake Claude AI website distributes PlugX remote access trojan targeting users searching for Anthropic's Claude. The malware mimics legitimate Anthropic installation process and relies on DLL sideloading for execution. The campaign cleans up after itself to avoid detection. PlugX is a long-standing Chinese APT malware family used for espionage and persistence.

Ransomware & Extortion

JanelaRAT Targets Latin American Financial Institutions

JanelaRAT is a modified variant of BX RAT targeting financial and cryptocurrency data from banks in Latin America since June 2023. The malware monitors browser activity using custom title bar detection to identify target websites and intercept banking interactions. Recent campaigns evolved to use MSI files delivering legitimate PE32 executables and sideloaded DLLs (nevasca.exe + PixelPaint.dll). JanelaRAT version 33 was masqueraded as legitimate pixel art app, protected with Eazfuscator obfuscator (previous versions used ConfuserEx). Infection begins with phishing emails mimicking pending invoice delivery, redirecting victims to malicious websites downloading compressed archives. MSI dropper creates startup persistence via LNK shortcut and redirects users to external website as decoy.

Patch Priority

General Security News

France Migrates from Windows to Linux for Digital Sovereignty

France's Interministerial Directorate for Digital Affairs (DINUM) will migrate from Windows desktops to Linux as part of broader digital sovereignty initiative. The agency employs 201-500 people (0.008% of France's 5.8 million civil servants) and serves as test case for wider government migration. All French ministries are now required to create plans adopting non-European alternatives for PC operating systems, collaboration tools, antivirus, AI, databases, virtualization, and network equipment. DINUM already sponsors LaSuite collection of open-source tools: Visio (replaces Teams/Meet), FranceTransfert/Fichiers (replaces Drive/OneDrive), Messagerie (email), Docs/Grist (office suites), and Tchap secure messaging (based on Matrix protocol). State Procurement Department will devise timeline for reducing American tech dependence. Industrial digital meetings scheduled for June 2026 to engage private sector.

Gmail End-to-End Encryption for Mobile Enterprise Users

Gmail now supports end-to-end encryption for Android and iOS enterprise users. The feature allows composing and reading encrypted messages natively on mobile devices without requiring desktop clients. Available exclusively for Google Workspace enterprise accounts.

Linux 7.0 Released with Official Rust Support

Linux kernel 7.0 released with official Rust language support, concluding experimental phase. Linus Torvalds noted AI tools are "finding corner cases for us for a while" and this "may be the new normal" for bug discovery. Kernel 2IC Greg Kroah-Hartman confirmed AI has become useful bug-spotter, prompting documentation updates to security-bugs.rst file to guide AI tools and users on better security bug reports. Release includes enhanced ARM/RISC-V/Loongson support, sophisticated KVM support for AMD EPYC 5 CPUs, self-healing XFS filesystem, and new code for legacy SPARC and DEC Alpha CPUs.

Anthropic Mythos AI Model for Zero-Day Discovery

Anthropic launched Mythos, an AI model claimed capable of finding and exploiting zero-day vulnerabilities with high success rates. The company describes the model as too dangerous to release publicly. Security community debate centers on whether the claims represent genuine capability or pre-IPO marketing hype.

Trends & Context

Active exploitation timelines continue compressing. Marimo CVE-2026-39987 exploitation began 10 hours post-disclosure, demonstrating automated exploit development from public advisories. Malicious mailbox rules in Microsoft 365 show attackers rely on low-effort persistence (single-character rule names, minimal operational security) confident in detection gaps. France's Linux migration follows similar moves by Germany (Schleswig-Holstein, 60,000 users), Netherlands (four cities piloting), and Denmark (multiple cities) citing American surveillance concerns and digital sovereignty. The common thread: adversaries bet on defenders not checking native platform features, while geopolitical tensions accelerate decoupling from US technology vendors.