← Carolina Clear Tech

Cyber Threat Brief

2026-04-15

Listen to this brief (24:07)

Download MP3
Show Notes

Show Notes - 2026-04-15

Stories Covered

CVEs Referenced

CVE-2009-0238, CVE-2023-20585, CVE-2024-27227, CVE-2026-20945, CVE-2026-21637, CVE-2026-23666, CVE-2026-25250, CVE-2026-26154, CVE-2026-32157, CVE-2026-32190, CVE-2026-32201, CVE-2026-32631, CVE-2026-33114, CVE-2026-33115, CVE-2026-33824, CVE-2026-33825, CVE-2026-33826, CVE-2026-33827, CVE-2026-34621, CVE-2026-35616, CVE-2026-5281

Read the full brief

Get tomorrow's brief in your inbox

Protect Your Business

Need a security assessment? See our cybersecurity packages.

View Services

Daily Cybersecurity Brief

April 15, 2026

Today: Microsoft patched 167 vulnerabilities including an actively exploited SharePoint spoofing flaw (CVE-2026-32201, CISA KEV deadline April 28) and a publicly disclosed Defender privilege escalation bug (CVE-2026-33825, BlueHammer exploit). Eight critical flaws include a 9.8 CVSS remote code execution in Windows IKE (CVE-2026-33824) and multiple Office RCE vulnerabilities exploitable via preview pane. Ransomware gangs 0APT and Krybit are fighting each other, and a watering hole attack compromised cpuid.com to deliver signed malware for 19 hours.

Critical Alerts

Microsoft SharePoint Server Spoofing Vulnerability (CVE-2026-32201)

Microsoft patched an actively exploited SharePoint Server spoofing vulnerability with a CVSS score of 6.5. The flaw stems from improper input validation allowing unauthenticated attackers to view sensitive information and modify disclosed data over a network. Attack complexity is low and requires no user interaction. CISA added this to the Known Exploited Vulnerabilities catalog with a federal remediation deadline of April 28, 2026.

Microsoft Defender Elevation of Privilege (CVE-2026-33825, BlueHammer)

A publicly disclosed privilege escalation flaw in Microsoft Defender allows local attackers with low privileges to gain SYSTEM access. The vulnerability has a CVSS score of 7.8 and exploits insufficient granularity of access control. Proof-of-concept exploit code was published on GitHub on April 2 by a researcher frustrated with Microsoft's disclosure process. Attack complexity is low and requires no user interaction. Microsoft classifies exploitation as more likely.

Windows Internet Key Exchange RCE (CVE-2026-33824)

Microsoft patched a critical remote code execution vulnerability in Windows IKE Service Extensions with a CVSS score of 9.8. The double free vulnerability allows unauthenticated remote attackers to execute arbitrary code by sending specially crafted packets to Windows machines with IKE version 2 enabled. No user interaction is required and attack complexity is low.

Windows TCP/IP Remote Code Execution (CVE-2026-33827)

A critical race condition vulnerability in Windows TCP/IP allows unauthenticated remote attackers to execute arbitrary code with a CVSS score of 8.1. An attacker can send specially crafted IPv6 packets to Windows nodes with IPSec enabled. Attack complexity is high and requires the attacker to win a race condition and take additional preparatory actions to configure the target environment before exploitation.

Windows Active Directory Remote Code Execution (CVE-2026-33826)

A critical improper input validation flaw in Windows Active Directory can result in remote code execution over an adjacent network with a CVSS score of 8.0. Successful exploitation requires an authenticated attacker to send specially crafted RPC calls to an RPC host. The attacker must be in the same restricted Active Directory domain as the target system.

CISA Adds Legacy Microsoft Office RCE to KEV Catalog (CVE-2009-0238)

CISA added CVE-2009-0238, a 15-year-old Microsoft Office remote code execution vulnerability, to the Known Exploited Vulnerabilities catalog based on evidence of active exploitation. The vulnerability has a CVSS EPSS score of 0.572 (98th percentile), indicating high probability of exploitation. Federal agencies must remediate by April 28, 2026.

Business & Infrastructure Threats

CPU-Z Watering Hole Attack Delivered Signed Malware for 19 Hours

On April 9, 2026, the official cpuid.com website was compromised at the API level and actively served malware through its official download button for approximately 19 hours. Attackers redirected legitimate download requests to attacker-controlled infrastructure that served properly signed CPU-Z binaries with malicious payloads bundled inside. The attack targeted CPU-Z, HWMonitor, HWMonitor Pro, and PerfMonitor. Users who downloaded directly from the official site received genuine digitally signed binaries with malicious DLLs. The malware used DLL sideloading (malicious CRYPTBASE.dll loaded before legitimate system DLL), reflective PE loading with XXTEA encryption and DEFLATE decompression, and three redundant persistence mechanisms including registry Run keys, 68-minute scheduled tasks with 20-year duration, and MSBuild project files in AppData\Local.

Ransomware & Extortion

Ransomware Gang 0APT Threatens Rival Group Krybit

Ransomware group 0APT published a leak blog post threatening to expose identities, photos, names, and locations of people affiliated with rival ransomware gang Krybit unless payment is made. 0APT leaked a sample of allegedly stolen Krybit data including plaintext credentials belonging to Krybit operators and affiliates, five cryptocurrency wallet addresses, and no evidence of a single paid ransom. Krybit's website is currently down, replaced by an apology message. 0APT launched in January 2026 and posted hundreds of victim claims in its first 48 hours, likely including inflated claims. Krybit has only been active for a few weeks with no major threat intelligence coverage.

Patch Priority

Vulnerability Disclosures

Microsoft April 2026 Patch Tuesday - 167 Vulnerabilities

Microsoft released patches for 167 security vulnerabilities, the second-largest Patch Tuesday on record. The release includes 8 critical vulnerabilities, 157 important, 3 moderate, and 1 low severity. Vulnerability breakdown includes 93 elevation of privilege (57% of total, a new record), 21 information disclosure, 20 remote code execution, 14 security feature bypass, 10 denial of service, and 9 spoofing vulnerabilities. The release also addresses 78 Chromium/Edge vulnerabilities patched earlier this month and 4 non-Microsoft CVEs affecting AMD (CVE-2023-20585), Node.js (CVE-2026-21637, EPSS 0.000 at 13th percentile), Windows Secure Boot (CVE-2026-25250), and Git for Windows (CVE-2026-32631). 2026 is on track to exceed 1,000 Patch Tuesday CVEs annually. Multiple security researchers noted a significant increase in AI-discovered vulnerabilities, with submission rates tripling at some vulnerability programs. Microsoft credited one vulnerability to an Anthropic researcher using Claude.

Microsoft Office Remote Code Execution Vulnerabilities

Microsoft patched three critical remote code execution vulnerabilities in Microsoft Office with CVSS scores of 7.8 to 8.8. CVE-2026-32190 affects Microsoft Office, CVE-2026-33114 affects Word, and CVE-2026-33115 affects Word. All three are use-after-free or untrusted pointer dereference vulnerabilities exploitable via malicious documents. Remote attackers can execute code locally by tricking users into opening crafted files. These vulnerabilities can be triggered via the preview pane in some configurations.

Remote Desktop Client RCE (CVE-2026-32157)

A critical use-after-free vulnerability in Remote Desktop Client allows unauthenticated remote attackers to execute arbitrary code with a CVSS score of 8.8. Attack requires an authorized user on the client to connect to a malicious RDP server. Connections may be initiated by clicking on rdp: links in web pages or documents.

.NET Framework Denial of Service (CVE-2026-23666)

Microsoft patched a critical denial of service vulnerability in .NET Framework. Successful exploitation allows attackers to deny service over the network. Microsoft rated this critical despite it being only a denial of service vulnerability.

Git for Windows NTLM Hash Leak (CVE-2026-32631)

A vulnerability in Git for Windows allows attackers to obtain a user's NTLM hash by tricking them into cloning a malicious repository or checking out a malicious branch that accesses an attacker-controlled server. By default, NTLM authentication does not require user interaction. Visual Studio updates incorporate Git updates addressing this vulnerability.

Windows / AD Security

Windows Server Update Service Tampering Vulnerability (CVE-2026-26154)

Microsoft patched an improper input validation vulnerability in Windows Server Update Service (WSUS) that allows unauthorized attackers to perform tampering over a network.

SharePoint Server Spoofing Vulnerability (CVE-2026-20945)

Microsoft patched a second SharePoint Server spoofing vulnerability (in addition to actively exploited CVE-2026-32201). CVE-2026-20945 is a cross-site scripting flaw in SharePoint that allows authorized attackers to perform spoofing over a network. This is distinct from the actively exploited CVE-2026-32201.

Node.js TLS Denial of Service (CVE-2026-21637)

A vulnerability in Node.js TLS error handling allows remote attackers to crash or exhaust resources of a TLS server when pskCallback or ALPNCallback are in use. Synchronous exceptions thrown during these callbacks bypass standard TLS error handling paths (tlsClientError and error), causing either immediate process termination or silent file descriptor leaks leading to denial of service. EPSS score is 0.000 at the 13th percentile.

Windows 11 and Windows 10 Cumulative Updates Released

Microsoft released Windows 11 KB5083769 and KB5082052 for versions 25H2/24H2 and 23H2, and Windows 10 KB5082200 extended security update. Windows 11 updates include Smart App Control can now be modified without clean install, Narrator integration with Copilot for image descriptions on Copilot+ PCs, improved Account Settings and About page design, and File Explorer reliability improvements. Windows 10 KB5082200 includes Remote Desktop Protocol file phishing protections, new Windows Security indicators for Secure Boot certificate rollout status, and a fix for BitLocker recovery screen issues on Intel devices with Connected Standby. Windows 10 build 19045.7184, Windows 10 Enterprise LTSC 2021 build 19044.7184, Windows 11 25H2 build 26200.8246, Windows 11 24H2 build 26100.8246, Windows 11 23H2 build 22631.6936.

General Security News

OpenAI Launches GPT-5.4-Cyber for Security Teams

OpenAI unveiled GPT-5.4-Cyber, a variant of GPT-5.4 optimized for defensive cybersecurity use cases. The company is expanding its Trusted Access for Cyber (TAC) program to thousands of authenticated individual defenders and hundreds of teams. OpenAI's Codex Security application security agent has contributed to over 3,000 critical and high fixed vulnerabilities. The launch follows Anthropic's Mythos preview as part of Project Glasswing. OpenAI's limited release aims to democratize access while minimizing misuse and strengthening safeguards against jailbreaks and adversarial prompt injections.

Google Adds Rust-Based DNS Parser to Pixel 10 Modem

Google integrated a Rust-based DNS parser into Pixel 10 modem firmware to mitigate memory safety vulnerabilities. The Rust implementation uses the hickory-proto crate with modifications for bare metal and embedded environments. Google chose DNS protocol for Rust implementation because it underpins modern cellular communications and vulnerabilities can expose users to attacks, as in CVE-2024-27227 (EPSS 0.001 at 21st percentile). The Rust crate introduced over 30 dependencies managed using custom cargo-gnaw tool. Pixel 10 is the first Pixel device to integrate memory-safe language into its modem.

Adobe Reader Zero-Day Actively Exploited Since November 2025

An Adobe Reader zero-day vulnerability (CVE-2026-34621) patched in an emergency update on April 11 has been actively exploited since at least November 2025. The vulnerability is added to CISA KEV catalog with a federal remediation deadline of April 27, 2026, and has an EPSS score of 0.061 at the 91st percentile.

Google Chrome Zero-Day (CVE-2026-5281)

Google Chrome fixed its fourth zero-day of 2026, CVE-2026-5281, a high-severity flaw added to CISA KEV catalog with a federal remediation deadline of April 15, 2026. The vulnerability has an EPSS score of 0.033 at the 87th percentile.

Fortinet FortiClient EMS Critical Vulnerability (CVE-2026-35616)

Fortinet patched a critical FortiClient Enterprise Management Server (EMS) vulnerability (CVE-2026-35616) that is actively exploited. The vulnerability is added to CISA KEV catalog with a federal remediation deadline of April 9, 2026 (past due), and has an EPSS score of 0.253 at the 96th percentile.

ICS Patch Tuesday - 8 Industrial Vendors Release Updates

Siemens, Schneider Electric, Aveva, Rockwell Automation, ABB, Phoenix Contact, Mitsubishi Electric, and Moxa published new security advisories and patches for industrial control systems.

California Cybersecurity Audit Rule Now in Effect

California Privacy Protection Agency's cybersecurity audit rule went into effect January 1, 2026, requiring certain businesses to conduct annual cybersecurity audits covering 18 technical and organizational components. Covered entities must submit written certification annually that they completed an audit meeting the rule's standards. The audit report does not need to be filed but will likely become a focal point of plaintiffs' discovery requests in data breach class actions seeking to prove negligence or violations of state data privacy laws.

Trends & Context

This month's Patch Tuesday marks the second-largest release on record at 167 CVEs, driven by a surge in AI-discovered vulnerabilities with submission rates tripling at some vulnerability programs. Elevation of privilege bugs now account for 57% of patches, a new record, while remote code execution vulnerabilities dropped to just 12%. The pattern reflects attackers and AI tools focusing on post-compromise escalation rather than initial access. The CPU-Z supply chain attack demonstrates that signed binaries from official sources are no longer sufficient trust indicators, requiring behavioral detection to catch malicious activity regardless of code signing. The ransomware ecosystem continues to cannibalize itself with 0APT threatening rival gang Krybit, suggesting operational instability that may lead to data leaks exposing victim information.