← Carolina Clear Tech

Cyber Threat Brief

2026-04-16

Listen to this brief (29:19)

Download MP3
Show Notes

Show Notes - 2026-04-16

Stories Covered

CVEs Referenced

CVE-2009-0238, CVE-2025-60710, CVE-2026-27282, CVE-2026-27304, CVE-2026-27305, CVE-2026-27306, CVE-2026-27681, CVE-2026-32201, CVE-2026-33032, CVE-2026-34619, CVE-2026-34621, CVE-2026-35616, CVE-2026-39808, CVE-2026-39813

Indicators of Compromise

IP Addresses: 0.0.0.0, 46.6.14.135

Read the full brief

Get tomorrow's brief in your inbox

Protect Your Business

Need a security assessment? See our cybersecurity packages.

View Services

Daily Cybersecurity Brief

April 16, 2026

Today: Two zero-day vulnerabilities from Microsoft and Adobe are under active exploitation. CISA added a 17-year-old Excel flaw to the Known Exploited Vulnerabilities catalog after detecting in-the-wild abuse. Fortinet, SAP, and nginx-ui all released critical patches, with nginx-ui already being exploited following public disclosure.

Critical Alerts

17-Year-Old Excel Vulnerability (CVE-2009-0238) Exploited in Active Attacks

A critical Excel remote code execution vulnerability from 2009 has returned to active exploitation. CVE-2009-0238 (CVSS 9.3, EPSS 81%, 99th percentile) was first patched in February 2009 but CISA confirmed exploitation shortly after Microsoft's April Patch Tuesday. The vulnerability allows attackers to execute code by convincing victims to open a specially crafted Excel document with a malformed object. It affects Microsoft Office Excel 2000-2007, Excel Viewer, and Office for Mac 2004/2008. CISA added the vulnerability to its KEV catalog with a two-week remediation deadline, one week shorter than usual, indicating urgency.

Adobe Acrobat Reader Zero-Day (CVE-2026-34621) Under Active Exploitation

Adobe addressed a critical remote code execution vulnerability in Acrobat Reader that has been exploited in the wild. CVE-2026-34621 (CVSS 8.6, CISA KEV due April 27, EPSS 6.1%, 91st percentile) allows code execution without user interaction beyond opening a malicious PDF. Adobe has not disclosed exploitation details, including threat actor identity, targeting patterns, or infection scale.

Microsoft SharePoint Server Spoofing Flaw (CVE-2026-32201) Exploited as Zero-Day

Microsoft confirmed active exploitation of a SharePoint Server spoofing vulnerability prior to April Patch Tuesday. CVE-2026-32201 (CVSS 6.5, CISA KEV due April 28, EPSS 1.2%, 79th percentile) stems from improper input validation, allowing attackers to spoof data over a network and access sensitive information. SharePoint environments used as document stores are high-value targets for ransomware operators seeking data for double extortion. The vulnerability could be weaponized to deploy malicious documents or replace legitimate files with infected versions for lateral movement.

Windows Task Host Privilege Escalation (CVE-2025-60710) Exploited

CISA flagged a Windows privilege escalation vulnerability as exploited in attacks. CVE-2025-60710 (CVSS score not disclosed, CISA KEV due April 27, EPSS 18.2%, 95th percentile) affects Windows 11 and Windows Server 2025. The flaw stems from improper link resolution before file access, allowing local attackers with basic user permissions to gain SYSTEM privileges via low-complexity attacks. Microsoft patched the vulnerability in November 2025, but CISA confirmed active exploitation and gave federal agencies two weeks to remediate.

nginx-ui Authentication Bypass (CVE-2026-33032) Actively Exploited

A critical authentication bypass vulnerability in nginx-ui is under active exploitation following public disclosure. CVE-2026-33032 (CVSS 9.8, EPSS 0.1%, 19th percentile) allows unauthenticated attackers to invoke all Model Context Protocol (MCP) tools, including restarting nginx, creating/modifying/deleting configuration files, and triggering automatic reloads. The vulnerability exists because the /mcp_message endpoint only applies IP whitelisting, and the default IP whitelist is empty, which the middleware treats as "allow all." Approximately 2,600 publicly exposed instances exist, concentrated in China, the United States, Indonesia, Germany, and Hong Kong. Attackers can achieve full nginx service takeover in seconds via two HTTP requests.

Ransomware Claims (Last 48h)

No structured ransomware victim claims data was available in today's collection.

Ransomware & Extortion

Autovista Group Confirms Ransomware Attack

Automotive data and analytics provider Autovista confirmed a ransomware attack affecting operations in Europe and Australia. The London-headquartered company, which provides residual value monitoring, TCO tools, and data services to manufacturers, dealers, insurers, and body shops, is working with external incident response teams to contain the attack. Customer-facing applications are experiencing disruptions. No ransomware group has claimed responsibility. Some customer organizations have advised staff to block inbound email from all Autovista Group entities and sanitize any files to remove links and executables.

PowMix Botnet Targets Czech Organizations

Cisco Talos identified an ongoing malicious campaign affecting the Czech workforce with a previously undocumented botnet called "PowMix." The campaign, active since at least December 2025, targets organizations across HR, legal, and recruitment sectors using compliance-themed lures impersonating the EDEKA brand and Czech Data Protection Act. The attack deploys a PowerShell loader that extracts malware from a ZIP archive, bypasses AMSI, and executes in memory. PowMix employs randomized C2 beaconing intervals, embeds encrypted heartbeat data in URL paths mimicking REST APIs, and can remotely update C2 domains. The campaign shares tactical overlaps with the ZipLine campaign, including ZIP-based payload concealment, scheduled task persistence, CRC32-based bot ID generation, and abuse of Heroku for C2 infrastructure.

Germany Reclaims Top Spot for European Ransomware Targeting

Google Threat Intelligence reports that Germany saw a 92% increase in data leak site posts in 2025, tripling the European average growth rate. Germany moved to the forefront of European data leak targets following a 2024 period where the UK led in DLS victims. The shift reflects Germany's status as an advanced European economy with an increasingly digitized industrial base. The targeting is not proportional to the number of active enterprises, as Germany has fewer companies than France or Italy. Threat actors are increasingly targeting the German Mittelstand as larger North American and UK targets improve security posture. AI-powered localization is eroding historical language barrier protections.

Business & Infrastructure Threats

n8n Workflow Automation Platform Abused for Phishing and Malware Delivery

Threat actors have weaponized n8n, an AI workflow automation platform, to deliver malware and fingerprint devices via phishing emails. Cisco Talos observed attackers leveraging n8n webhooks hosted on *.app.n8n.cloud domains to bypass security filters. Email volume containing these URLs in March 2026 was 686% higher than January 2025. In one campaign, attackers embedded n8n webhook links in emails claiming to share documents. Clicking the link displays a CAPTCHA that triggers download of modified RMM tools (Datto, ITarian Endpoint Management) from external hosts, establishing C2 persistence. A second campaign uses invisible images hosted on n8n webhook URLs as tracking pixels, automatically sending HTTP GET requests with victim email addresses when opened.

Supply Chain Compromise: TeamPCP Injects Credential Harvesters into Trusted Repositories

Recorded Future detailed a March 2026 supply chain attack by TeamPCP, which compromised LiteLLM (97 million monthly downloads) and Checkmarx security platform using stolen credentials. TeamPCP gained write access to trusted software repositories and injected credential-harvesting payloads into software. The malware ran on installation, stealing access keys, cloud credentials, and AI API keys, then exfiltrated encrypted data to lookalike domains. One compromised credential enabled cascading attacks across five ecosystems in five days. Recorded Future's identity intelligence contains almost 1 million compromised GitHub developer credentials from infostealers sold on dark web marketplaces.

Signed Adware Deploys AV-Killing PowerShell Scripts with SYSTEM Privileges

Huntress researchers discovered a campaign using digitally signed adware from Dragon Boss Solutions LLC to deploy PowerShell scripts that disable antivirus products. The operation affected more than 23,500 infected hosts in 124 countries, including endpoints in education, utilities, government, and healthcare sectors. The signed executables (promoted as browsers like Chromstera, Chromnius, Web Genius) use Advanced Installer's update mechanism to silently deploy MSI and PowerShell payloads with SYSTEM privileges. The ClockRemoval.ps1 script checks for Malwarebytes, Kaspersky, McAfee, and ESET, then disables them by stopping services, killing processes, deleting directories and registry entries, running silent uninstallers, and blocking vendor domains via hosts file modification. The script executes at boot, logon, and every 30 minutes. Huntress sinkholed the main update domain (chromsterabrowser.com) to track infections.

WordPress EssentialPlugin Suite Compromised with Backdoor

More than 30 WordPress plugins in the EssentialPlugin package were compromised with backdoor code allowing unauthorized access. The backdoor was planted in August 2025 after a new owner acquired the project in a six-figure deal, but activation only occurred recently. The malware contacts analytics.essentialplugin.com to fetch a file (wp-comments-posts.php) that injects code into wp-config.php. The malware retrieves spam links, redirects, and fake pages from an Ethereum-based C2 address, displaying content only to Googlebot to avoid detection by site owners. WordPress.org closed the plugins and pushed a forced update to disable the backdoor, but did not clean wp-config.php. Affected plugins have hundreds of thousands of active installations.

Compromised DVRs Used in Telnet-Based Botnet Attacks

SANS Internet Storm Center documented a two-second Telnet attack demonstrating how quickly exposed camera systems are compromised. An attack from IP 46.6.14.135 authenticated to TCP port 23 using default credentials (root/root), then executed 10 commands in an automated sequence. The offending device is an Airspace (Dahua OEM) 8-channel DVR in Spain running firmware last updated in August 2014, exposing Telnet, HTTP, and RTSP services. A PowerShell script scanning Shodan identified 5,313 matching DVRs globally, with 3.8% (approximately 202 devices) actively reported for abuse in the last 90 days. The actual number of compromised devices is likely much higher, as the figure only includes recently reported infections.

Windows / AD Security

Microsoft Fixes Windows Server 2025 Automatic Upgrade Bug

Microsoft resolved a known issue causing Windows Server 2019 and 2022 systems to unexpectedly upgrade to Windows Server 2025 overnight without licenses. The issue was first acknowledged in September 2024 following widespread reports from administrators. Microsoft blamed third-party update management software misconfigurations, but software vendors said the problem was caused by a "procedural error on Microsoft's side, both with the speed of release and the classification." After more than a year, Microsoft re-enabled the upgrade offer via the Windows Update settings panel.

April Windows Server 2025 Updates Trigger BitLocker Recovery Prompts

Microsoft confirmed that some Windows Server 2025 devices boot into BitLocker recovery after installing April 2026 KB5082063 security update. The issue affects systems with unrecommended BitLocker Group Policy configurations where all of the following conditions are met: BitLocker enabled on OS drive, Group Policy "Configure TPM platform validation profile for native UEFI firmware configurations" includes PCR7, System Information reports "Secure Boot State PCR7 Binding is Not Possible," Windows UEFI CA 2023 certificate is present in Secure Boot DB, and the device is not running the 2023-signed Windows Boot Manager. The issue is unlikely to affect personal devices, as configurations are typically found only on enterprise-managed systems. Microsoft provided workarounds including removing PCR7 Group Policy before deployment or applying Known Issue Rollback (KIR).

Windows Server 2025 April Update Fails to Install on Some Systems

Microsoft is investigating April KB5082063 security update installation failures on some Windows Server 2025 systems. Affected systems report 0x800F0983 install errors. Microsoft is monitoring diagnostic data and observes recurring errors on a limited number of servers. The company is investigating the root cause and will share details as it learns more.

General Security News

NIST Narrows CVE Analysis Scope Amid 263% Surge in Vulnerability Submissions

The National Institute of Standards and Technology announced it will only prioritize CVE analysis for vulnerabilities in CISA's Known Exploited Vulnerabilities catalog, federal government software, and critical software defined under Executive Order 14028. NIST analyzed nearly 42,000 vulnerabilities in 2025, with CVE submissions surging 263% from 2020 to 2025. Submissions during the first three months of 2026 are nearly one-third higher than the same period in 2025. NIST still has not cleared the backlog of unenriched CVEs that built up during the early 2024 funding lapse. CVEs outside the narrow criteria will still be listed in the NVD but will not be automatically enriched with additional details. NIST will no longer provide separate CVSS scores for CVEs submitted with severity ratings, instead relying on CVE Numbering Authority assessments.

UAC-0247 Targets Ukrainian Government and Hospitals with AgingFly Malware

CERT-UA identified attacks by threat cluster UAC-0247 targeting Ukrainian local governments and hospitals with a new malware family called AgingFly. The campaign, observed between March and April 2026, begins with emails claiming to be humanitarian aid proposals. Links redirect to legitimate sites compromised via XSS or AI-generated fake sites that download LNK files. The LNK executes remote HTA files via mshta.exe, which display decoy forms while injecting shellcode into legitimate processes. AgingFly is a C# malware that provides remote control, command execution, file exfiltration, screenshot capture, keylogging, and arbitrary code execution via WebSockets with AES-CBC encryption. A distinguishing feature is that command handlers are retrieved from C2 as source code and dynamically compiled at runtime rather than pre-built. Attackers deploy ChromElevator to bypass Chromium app-bound encryption and harvest cookies/passwords, and ZAPiDESK to decrypt WhatsApp databases.

Microsoft Pays $2.3 Million for Cloud and AI Vulnerabilities at Zero Day Quest

Microsoft awarded $2.3 million to security researchers after receiving nearly 700 submissions during the 2026 Zero Day Quest hacking contest. Over 80 flaws found during the live event at Microsoft's Redmond campus were high-impact cloud and AI security vulnerabilities. Researchers identified critical paths involving credential exposure, SSRF chains, and cross-tenant access. The contest is part of Microsoft's Secure Future Initiative launched in November 2023 following a Department of Homeland Security Cyber Safety Review Board report that found the company's security culture "inadequate" and requiring "an overhaul."

Raspberry Pi OS Requires Password for sudo by Default

The latest version of Raspberry Pi OS now requires a password for sudo by default on new installations. Existing setups are untouched. Previously, any user could run sudo commands as administrator without authentication. Once entered correctly, the password is not required again for five minutes. Users who prefer the old behavior can revert via Control Centre or raspi-config. The change will break some scripts but improves the default security posture.

US Nationals Sentenced for Operating North Korean IT Worker Laptop Farm

Two U.S. nationals were sentenced to prison for helping North Korean remote IT workers pose as U.S. residents and get hired by over 100 companies, including Fortune 500 firms. Kejia Wang (42) received 108 months and Zhenxing Wang (39) received 92 months for generating more than $5 million in illicit revenue for the DPRK government between 2021 and October 2024. They created financial accounts, fake websites, and shell companies (Tony WKJ LLC, Hopana Tech LLC, Independent Lab LLC) to collect payments. Zhenxing Wang hosted company-issued laptops in U.S. homes to help remote workers access company networks without raising suspicion. Nine other defendants remain at large, with the State Department offering up to $5 million for information.

Patch Priority

Vulnerability Disclosures

Fortinet FortiSandbox Critical Authentication Bypass and RCE

Fortinet released patches for two critical FortiSandbox vulnerabilities allowing unauthenticated attackers to bypass authentication or execute code via HTTP requests. CVE-2026-39808 (CVSS 9.1, EPSS 0.3%, 53rd percentile) is an OS command injection flaw affecting FortiSandbox 4.4.0-4.4.8, fixed in 4.4.9. CVE-2026-39813 (CVSS 9.1, EPSS 0.1%, 18th percentile) is a path traversal bug in the FortiSandbox JRPC API affecting 4.4.0-4.4.8 and 5.0.0-5.0.5, fixed in 4.4.9 and 5.0.6. No active exploitation has been reported, but public scanners are available. These updates arrive one week after Fortinet patched CVE-2026-35616, a critical FortiClient EMS bug under attack since at least March 31 and added to CISA's KEV catalog.

SAP BW/BPC SQL Injection (CVE-2026-27681)

SAP patched a critical SQL injection vulnerability in Business Planning and Consolidation (BPC) and Business Warehouse (BW). CVE-2026-27681 (CVSS 9.9, EPSS 0.0%, 14th percentile) allows a low-privileged user to upload a file with arbitrary SQL statements that are then executed against BW/BPC data stores. Attackers could extract sensitive data, delete or corrupt database content, and undermine close processes, executive reporting, and operational planning. Manipulated planning figures, broken reports, or deleted consolidation data can disrupt business operations.

Adobe ColdFusion Critical Vulnerabilities

Adobe patched five critical ColdFusion flaws in versions 2025 and 2023 that could lead to arbitrary code execution, denial-of-service, arbitrary file system read, and security feature bypass. CVE-2026-34619 (CVSS 7.7, EPSS 0.1%, 17th percentile) is a path traversal leading to security feature bypass. CVE-2026-27304 (CVSS 9.3, EPSS 0.0%, 12th percentile) is improper input validation leading to RCE. CVE-2026-27305 (CVSS 8.6, EPSS 0.1%, 31st percentile) is path traversal leading to arbitrary file system read. CVE-2026-27282 (CVSS 7.5, EPSS 0.2%, 44th percentile) is improper input validation leading to security feature bypass. CVE-2026-27306 (CVSS 8.4, EPSS 0.0%, 13th percentile) is improper input validation leading to RCE.

Microsoft April Patch Tuesday: 169 Vulnerabilities

Microsoft addressed 169 security defects in April Patch Tuesday, including two actively exploited zero-days (CVE-2026-34621 in Adobe Acrobat Reader and CVE-2026-32201 in SharePoint Server, both detailed above under Critical Alerts). This is Microsoft's second-largest monthly batch of defects on record.

Trends & Context

This month's Patch Tuesday releases reveal a convergence of legacy and modern threats. A 17-year-old Excel vulnerability returning to active exploitation demonstrates that threat actors are mining historical CVE databases for unpatched systems, particularly legacy Office deployments that predate modern security baselines. The simultaneous exploitation of zero-days in Adobe Reader and SharePoint Server shows attackers targeting both client-side document handling and server-side collaboration platforms. Infrastructure management tools continue to be high-value targets, with critical vulnerabilities in Fortinet FortiSandbox, SAP BW/BPC, and nginx-ui all requiring immediate attention. The surge in supply chain compromises (TeamPCP, WordPress EssentialPlugin, n8n abuse) indicates attackers are shifting from direct exploitation to poisoning trusted software distribution channels and productivity platforms.