CVE-2012-1854, CVE-2017-7921, CVE-2020-9715, CVE-2023-21529, CVE-2023-36424, CVE-2025-0520, CVE-2025-60710, CVE-2026-20131, CVE-2026-21643, CVE-2026-27483, CVE-2026-27944, CVE-2026-34621, CVE-2026-5194
Domains:
sites[.]google
IP Addresses:
2.26.97.61, 160.119.76.250, 45.95.147.178
Get tomorrow's brief in your inbox
Today: CISA added 7 actively exploited vulnerabilities to the KEV catalog, including a 14-year-old Microsoft VBA flaw and an Adobe zero-day exploited since December. Interlock ransomware used a Cisco FMC zero-day to breach enterprise networks. Anthropic's Claude Mythos AI model can autonomously discover and exploit vulnerabilities, forcing a rethink of defensive timelines.
Adobe Acrobat/Reader Zero-Day (CVE-2026-34621)
Adobe released emergency patches for a prototype pollution vulnerability exploited in the wild since December 2025. The flaw bypasses sandbox restrictions to execute arbitrary code through specially crafted PDFs. Attacks use malicious JavaScript to read local files via util.readFileIntoStream() and exfiltrate data through RSS.addFeed(). Security researcher Haifei Li discovered the exploit after someone submitted a sample named "yummy_adobe_exploit_uwu.pdf" to EXPMON on March 26. Researchers spotted Russian-language documents targeting oil and gas sectors. Adobe initially rated the flaw critical (9.6) but later lowered it to 8.6.
Cisco FMC Zero-Day Exploited by Interlock Ransomware (CVE-2026-20131)
Interlock ransomware group actively exploited a zero-day in Cisco Secure Firewall Management Center software to execute arbitrary Java code as root without authentication. Amazon Threat Intelligence published analysis on March 18, 2026 detailing the campaign. The vulnerability allowed attackers to compromise enterprise networks, deploy custom remote access trojans, and facilitate ransomware operations. CISA added this to KEV catalog with April 22 remediation deadline. EPSS score 0.008 (74th percentile).
CISA KEV Additions (7 vulnerabilities, April 27 deadline)
CISA added 7 actively exploited vulnerabilities requiring federal agency remediation by April 27. The list includes CVE-2012-1854 (Microsoft VBA insecure library loading), patched 14 years ago but still under active exploitation. CVE-2023-21529 (Microsoft Exchange Server deserialization) linked to Storm-1175 deploying Medusa ransomware. CVE-2026-21643 (Fortinet FortiClient EMS SQL injection, CVSS 9.1) exploited since March 24, 2026. CVE-2020-9715 (Adobe Acrobat use-after-free, EPSS 0.504, 98th percentile). CVE-2023-36424 (Windows CLFS out-of-bounds read). CVE-2025-60710 (Windows link following privilege escalation).
No structured ransomware victim claims data available in today's collection.
Silent Ransom Group Targeting Law Firms
Silent Ransom Group (SRG) has compromised 38 U.S. law firms according to leak site listings, representing only firms that refused to pay. SRG claims most targeted law firms do pay, suggesting 76+ total attacks. Recent victims include Wood Smith Henning & Berman LLP (WSHB), a California firm with $81 million revenue. SRG gained access February 20, 2026, acquired 3.6 GB of data, and demanded $1.8 million. Negotiations failed when the firm questioned the valuation relative to data volume. SRG follows consistent negotiation strategy: calling firms despite requests not to, waiting for firms to make first reasonable offer before lowering demands. FBI issued Private Industry Notice in May 2025 warning about SRG's law firm targeting campaign.
Medusa Ransomware via Exchange Vulnerabilities
Storm-1175 threat group exploits CVE-2023-21529 (Exchange Server deserialization) plus 15 other vulnerabilities to gain initial access, steal data, and deploy Medusa ransomware in extortion attacks. Microsoft threat hunters warned of this activity last week. The group is financially motivated and targets organizations for data theft before ransomware deployment.
No structured IOC data available in today's collection.
Rockstar Games Data Breach via Anodot/Snowflake
ShinyHunters extortion gang leaked 78.6 million records stolen from Rockstar Games via compromised Snowflake environments. Threat actors obtained authentication tokens during an Anodot security incident and used them to access customer data in connected Snowflake, S3, and Amazon Kinesis instances. The leaked data includes internal analytics for Grand Theft Auto Online and Red Dead Online: in-game revenue, purchase metrics, player behavior tracking, game economy data, and customer support analytics from Zendesk. File listings reference fraud detection systems and anti-cheat model testing. Snowflake confirmed unusual activity affecting a small number of customer accounts tied to a third-party integration and locked down affected accounts.
wolfSSL Certificate Verification Flaw (CVE-2026-5194)
Critical vulnerability in wolfSSL SSL/TLS library allows improper verification of hash algorithm size when checking ECDSA signatures. Attackers can force devices to accept forged certificates for malicious servers or connections. The flaw affects ECDSA/ECC, DSA, ML-DSA, Ed25519, and Ed448 signature algorithms. wolfSSL is embedded in over 5 billion applications and devices including IoT devices, industrial control systems, routers, appliances, automotive systems, and aerospace/military equipment. Discovered by Nicholas Carlini of Anthropic. Patched in wolfSSL version 5.9.1 released April 8.
OpenAI Certificate Rotation After Axios Supply Chain Attack
OpenAI is rotating macOS code-signing certificates after a GitHub Actions workflow executed malicious Axios package version 1.14.1 on March 31, 2026. The workflow had access to certificates used to sign ChatGPT Desktop, Codex, Codex CLI, and Atlas. While no evidence indicates certificate compromise, OpenAI is treating it as potentially compromised. North Korean threat actors (UNC1069) conducted social engineering via fake web conferences to compromise an Axios maintainer's account and publish malicious packages to npm. The malicious package installed a remote access trojan on macOS, Windows, and Linux. Older app versions will stop working May 8, 2026. OpenAI worked with Apple to prevent future software notarization using the old certificate.
Storm Infostealer: Server-Side Decryption Model
New infostealer "Storm" launched early 2026 for under $1,000/month represents a tactical shift in credential theft. Storm harvests browser credentials, session cookies, and crypto wallets, then ships encrypted files to attacker's server for decryption instead of decrypting locally. This bypasses endpoint security tools that detect local browser database access. Handles both Chromium and Gecko-based browsers (Firefox, Waterfox, Pale Moon) server-side. Automates session hijacking: feed in a Google Refresh Token and geographically matched SOCKS5 proxy, and the panel restores the victim's authenticated session. Cookie restore makes MFA irrelevant, granting persistent access to Microsoft 365 and SaaS platforms without passwords. One compromised employee browser hands operators authenticated access to SaaS platforms, internal tools, and cloud environments. Operators connect their own VPS to Storm's central servers, routing stolen data through infrastructure they control, insulating central servers from takedown attempts.
Linux Foundation Social Engineering via Fake Slack Account
Attackers impersonated a real Linux Foundation official via Slack, targeting developers in TODO (Talk Openly, Develop Openly) and CNCF (Cloud Native Computing Foundation) projects. Phishing link hosted on Google Sites (https://sites[.]google[.]com/view/workspace-business/join) imitates Google Workspace sign-in, prompting credential entry and installation of fake root certificate masquerading as a Google certificate. On macOS, the fake certificate downloads and executes a binary (gapi) from 2.26.97.61. On Windows, it prompts installation of malicious certificate via browser trust dialog. Installing the certificate enables interception of encrypted traffic and credential theft. The binary execution results in full system compromise. Google's security team took down the spoofed pages. Google confirmed legitimate Google Workspace authentication never requires manual root certificate installation or binary download.
Anthropic's Claude Mythos: AI-Powered Vulnerability Discovery
Anthropic restricted public release of Claude Mythos Preview AI model due to cyberattack capabilities, launching Project Glasswing to scan public domain and proprietary software. The model autonomously discovers vulnerabilities at scale and writes effective exploits without human involvement. In testing, Mythos solved 73% of expert-level Capture the Flag problems (previous LLMs: 0%). In cyber range tests against 32-step attack playbooks on corporate networks, Mythos completed an average of 24 of 32 steps in successful runs (older models: maximum 16). UK AISI testing found Mythos "at least capable" of autonomously taking down smaller, weakly defended enterprise networks. Security company Aisle replicated vulnerabilities using older, cheaper, public models, but exploiting vulnerabilities requires more sophistication than just finding them. Joint CSA/SANS/OWASP report warns organizations "likely to be overwhelmed" by threat actors using AI to find and exploit vulnerabilities faster than defenders can patch. The cost and capability floor for exploit discovery is dropping, time between disclosure and weaponization is compressing toward zero, and nation-state capabilities are becoming broadly accessible.
JanelaRAT Malware Targets Latin American Banks
Modified version of BX RAT called JanelaRAT recorded 14,739 attacks in Brazil and 11,695 in Mexico during 2025. Targets banks and financial institutions in Latin America using phishing emails disguised as invoices. Attack chain downloads ZIP archives containing Visual Basic scripts or MSI installers, deploying DLL side-loading to install the trojan. The malware uses custom title bar detection to identify desired banking websites in victims' browsers. Capabilities include financial and cryptocurrency data theft, mouse tracking, keystroke logging, screenshots, and system metadata collection. Since May 2024, campaigns shifted from VBS to MSI installers. JanelaRAT also installs malicious Chromium-based browser extensions to gather cookies, browsing history, and tab metadata. Upon execution, malware establishes TCP socket communications with C2 server and monitors victim activity to intercept banking interactions. When detecting targeted financial institution windows, it waits 12 seconds before executing commands including screenshot capture, fake overlay display impersonating bank dialogs, keystroke capture, cursor manipulation, forced shutdown, and PowerShell command execution.
ShowDoc RCE Flaw (CVE-2025-0520) Actively Exploited
Critical vulnerability (CVSS 9.4) in ShowDoc document management service exploited in the wild for the first time. Unrestricted file upload flaw from improper file extension validation allows unauthenticated attackers to upload PHP files and achieve remote code execution. Patched in ShowDoc version 2.8.7 (October 2020), current version is 3.8.1. VulnCheck observed exploit leveraging the flaw to drop web shell on U.S.-based honeypot. Over 2,000 instances of ShowDoc online, most located in China. Example of threat actors increasingly exploiting N-day vulnerabilities regardless of install base.
EncystPHP Webshell Scans Targeting FreePBX
SANS Internet Storm Center detected scans for EncystPHP webshell from IP 160.119.76.250 (Netherlands). Requests probe for ajax.php with MD5 parameter (cf710203400b8c466e6dfcafcf36a411). This webshell is a favorite among attackers compromising vulnerable FreePBX systems, first reported by Fortinet in January 2026. The same IP also probes for FreePBX vulnerabilities using Originate actions to download and execute remote scripts (wget http://45.95.147.178/k.php). Successful exploitation installs EncystPHP webshell and adds 10 backdoor accounts (root, hima, asterisk, sugarmaint, spamfilter, asteriskuser, supports, freepbxuser, supermaint, juba) all using the same password hash ($1$nRz1Cbtk$6DnGs37n.OpPcgejUfp9p.).
March 2026 CVE Landscape: 31 High-Impact Vulnerabilities
Recorded Future identified 31 high-impact vulnerabilities actively exploited in March 2026, 29 with Very Critical Risk Score. Affected vendors: Cisco, Microsoft, Google, ConnectWise, Langflow, Citrix, Aquasecurity, Nginx UI, Qualcomm, F5, Craft CMS, Laravel, Apple, Synacor, Wing FTP Server, n8n, Omnissa, SolarWinds, Ivanti, Hikvision, Rockwell, Broadcom. Microsoft and Apple accounted for 32% of vulnerabilities. CVE-2017-7921 (Hikvision, 9 years old, CISA KEV, EPSS 0.942, 100th percentile) demonstrates attackers continue exploiting long-known weaknesses. 9 of 31 vulnerabilities allowed RCE affecting Google, Langflow, Craft CMS, Laravel, Microsoft, n8n, SolarWinds, and Apple. Most common weaknesses: CWE-502 (Deserialization of Untrusted Data) and CWE-94 (Code Injection). DarkSword iOS full-chain exploit enabled Safari RCE, sandbox escape, and kernel access, deploying GHOSTKNIFE, GHOSTSABER, and GHOSTBLADE payloads. Coruna exploit kit compromised iOS devices to deliver PlasmaLoader (PLASMAGRID) malware.
Fortinet FortiClient EMS SQL Injection (CVE-2026-21643)
CVSS 9.1 SQL injection vulnerability in Fortinet FortiClient EMS allows unauthenticated attackers to execute unauthorized code or commands via crafted HTTP requests. Defused Cyber detected exploitation attempts since March 24, 2026. EPSS 0.137 (94th percentile). Added to CISA KEV catalog with April 27 remediation deadline.
This week's stories highlight three converging trends reshaping defensive timelines. First, the persistence of old vulnerabilities: CVE-2012-1854 (14 years old) and CVE-2017-7921 (9 years old) remain under active exploitation, proving patching debt compounds risk indefinitely. Second, the collapse of zero-day advantages: Adobe CVE-2026-34621 was exploited for four months before discovery, and Cisco CVE-2026-20131 enabled enterprise ransomware campaigns before public disclosure. Third, AI-powered vulnerability discovery (Claude Mythos) compresses the timeline between disclosure and weaponization toward zero, forcing defenders to prepare for commodity zero-days. Organizations can no longer rely on multi-week patching cycles or assume zero-days require nation-state resources.
Generated 2026-04-14 | Sources: 40 articles from 28+ security feeds and 3 API sources