← Carolina Clear Tech

Cyber Threat Brief

2026-04-17

Listen to this brief (28:37)

Download MP3
Show Notes

Show Notes - 2026-04-17

Stories Covered

CVEs Referenced

CVE-2009-0238, CVE-2023-33538, CVE-2024-32114, CVE-2025-14821, CVE-2025-64669, CVE-2026-20147, CVE-2026-20180, CVE-2026-20184, CVE-2026-20186, CVE-2026-32316, CVE-2026-33825, CVE-2026-33947, CVE-2026-33948, CVE-2026-34197, CVE-2026-35199, CVE-2026-35469, CVE-2026-39956, CVE-2026-39979, CVE-2026-40164, CVE-2026-40179, CVE-2026-5387, CVE-2026-5726, CVE-2026-6284

Read the full brief

Get tomorrow's brief in your inbox

Protect Your Business

Need a security assessment? See our cybersecurity packages.

View Services

Daily Cybersecurity Brief

April 17, 2026

Today: Apache ActiveMQ flaw now under active exploitation with CISA KEV deadline April 30. Microsoft Defender zero-day RedSun grants SYSTEM privileges on fully patched Windows 11 and Server with no fix available. Three Windows domain controllers entering reboot loops after April patches due to LSASS crashes in PAM environments.

Critical Alerts

Apache ActiveMQ CVE-2026-34197 Added to CISA KEV Amid Active Exploitation

A 13-year-old authentication bypass vulnerability in Apache ActiveMQ Classic is now being actively exploited in the wild. CVE-2026-34197 (CVSS 8.8, EPSS 6.2%/91st percentile) allows authenticated attackers to execute arbitrary code via command injection through the Jolokia API. The flaw was discovered by a Horizon3 researcher using Claude AI. Threat actors can invoke management operations to force the broker to fetch remote configuration files and run OS commands. Default credentials (admin:admin) are common in many environments. On ActiveMQ versions 6.0.0-6.1.1, another vulnerability (CVE-2024-32114) exposes the Jolokia API without authentication, making CVE-2026-34197 effectively an unauthenticated RCE in those versions. Over 7,500 ActiveMQ servers are exposed online. Signs of exploitation include suspicious broker connections using the brokerConfig=xbean:http:// query parameter and the internal transport protocol VM.

Microsoft Defender "RedSun" Zero-Day Grants SYSTEM Privileges (Unpatched)

Security researcher "Chaotic Eclipse" has published proof-of-concept exploit code for a second Microsoft Defender zero-day in two weeks. The RedSun exploit achieves local privilege escalation to SYSTEM on Windows 10, Windows 11, and Windows Server (2019 and later) running the latest April 2026 security patches when Windows Defender is enabled. The vulnerability exploits a flaw in how Defender handles cloud-tagged malicious files. When Defender detects a cloud-tagged file, it rewrites the file to its original location. The exploit abuses this behavior through the Cloud Files API, writes EICAR to a file, wins a volume shadow copy race using an oplock, and uses a directory junction to redirect the file rewrite to C:\Windows\system32\TieringEngineService.exe. The Cloud Files Infrastructure then runs the attacker-planted executable as SYSTEM. Huntress Labs reports the exploit is now being used in the wild, with RedSun and UnDefend observed on a Windows device breached via compromised SSLVPN user access.

17-Year-Old Excel RCE CVE-2009-0238 Added to CISA KEV

CISA has added CVE-2009-0238 to its Known Exploited Vulnerabilities catalog, a 17-year-old remote code execution vulnerability in Microsoft Office that is now being actively exploited. The vulnerability has an EPSS score of 81.1% (99th percentile), indicating extremely high likelihood of exploitation. Federal agencies must remediate by April 28, 2026. The vulnerability impacts legacy Microsoft Office versions and allows attackers to execute arbitrary code when victims open specially crafted Excel files.

Ransomware Claims (Last 48h)

2 claims tracked across 2 groups in the last 48 hours. These are unverified claims from ransomware leak sites, not confirmed breaches.

Group Victim Sector Country
Prinz Eugen Standard Bank Group Financial Services South Africa
RansomExx GoTip Technology Unknown

The Prinz Eugen group claims a three-week attack on Standard Bank and Liberty beginning February 27, 2026, resulting in 1.2TB of exfiltrated data from internal servers.

Ransomware & Extortion

McGraw Hill Appears on ShinyHunters Leak Site After 13.5M Record Exposure

Textbook publisher McGraw Hill has been added to the ShinyHunters ransomware leak site following an alleged Salesforce-linked misconfiguration that exposed 13.5 million records. Have I Been Pwned confirms the breach exposed names, phone numbers, email addresses, and some physical addresses. McGraw Hill described the source as a limited Salesforce-hosted webpage, though the data now circulating publicly exceeds 100GB. ShinyHunters claims to have over 40 million Salesforce records containing PII and accused the company of failing to pay ransom before an April 14 deadline. Most Salesforce compromises stem from stolen credentials, abused OAuth apps, or over-permissioned integrations rather than Salesforce vulnerabilities themselves. McGraw Hill stated the activity did not involve unauthorized access to McGraw Hill's Salesforce accounts, customer databases, courseware, or internal systems. McGraw Hill has not acknowledged the incident on its own website.

Tennessee Hospital Breach Affects 337,000 After Rhysida Ransomware Attack

Cookeville Regional Medical Center in Tennessee was targeted by the Rhysida ransomware group in 2025, with the breach now confirmed to affect 337,000 individuals. The group stole 500GB of data during the attack. Healthcare remains a high-value target for ransomware operators, with patient data particularly valuable on underground markets.

P3 Campus Tip System Breached: 8.3 Million Anonymous Tips Exposed

Hacktivist group Internet Yiff Machine (IYM) compromised P3 Global Intel's tip management platform used by 35,000 U.S. schools, exposing 8.3 million tips that were supposed to be anonymous. The 91.53GB dataset contains student reports on bullying, suicide threats, drugs, and other sensitive issues. IYM provided the data to DDoSecrets.org and journalist Mikael Thalen but did not make it public. However, the data is now being offered for sale for $10,000. Navigate360, the parent company of P3, has not yet acknowledged the breach or that sensitive information has been compromised. DataBreaches.net confirmed that very sensitive information has been exposed, including tip content with identifiable details that compromise the anonymity P3 promised to students.

Business & Infrastructure Threats

Cisco Patches Critical Webex and Identity Services Engine Vulnerabilities

Cisco released security updates for four critical vulnerabilities, including CVE-2026-20184 (CVSS 9.8) in Webex Services and three flaws in Identity Services Engine (ISE). CVE-2026-20184 is an improper certificate validation flaw in the SSO integration with Control Hub that allows remote attackers with no privileges to impersonate any Webex user and gain unauthorized access. Cisco has already fixed the vulnerability in Webex Services, but customers using SSO integration must upload a new SAML certificate for their identity provider to Control Hub to avoid service interruption. The three ISE vulnerabilities (CVE-2026-20147, CVE-2026-20180, CVE-2026-20186, all CVSS 9.9) allow authenticated attackers with administrative or read-only admin credentials to execute arbitrary commands on the underlying OS. In single-node ISE deployments, exploitation could cause denial-of-service, preventing endpoints from accessing the network until the node is restored. Cisco has no evidence of exploitation in the wild.

Claude Opus Developed Chrome Exploit for $2,283 in API Costs

Anthropic's publicly available Claude Opus 4.6 model was used to develop a full exploit chain targeting Chrome 138's V8 JavaScript engine, which is bundled into current versions of Discord. Hacktron CTO Mohan Pedhapati spent one week, 2.3 billion tokens, $2,283 in API costs, and approximately 20 hours of human intervention to produce working exploit code. The exploit successfully achieved code execution ("popped calc"). Discord is running Chrome 138, nine major versions behind current releases. While $2,283 is significant for an individual, it's far less than the weeks of manual work required without AI assistance and well below the theoretical reward from Google's and Discord's bug bounty programs (~$15,000). Opus 4.7 has similar cyber capabilities with added safeguards to detect and block high-risk requests, but Pedhapati argues the specific model doesn't matter. As AI code generation improves, patch windows shrink and every patch becomes an exploit hint. This is particularly problematic for open source projects where fixes become visible before releases.

Git Identity Spoofing Fools Claude into Approving Malicious Code

Manifold Security demonstrated that AI code reviewers built on Claude can be tricked into approving malicious code by spoofing a trusted developer's Git identity. Two simple Git commands can set a fake author name and email, making a commit appear to originate from a legitimate maintainer. In automated review workflows where the AI model gives weight to author identity, this allows hostile changes to pass review. Manifold's test targeted workflows configured to auto-approve pull requests from recognized industry legends, but real-world implementations often check org membership, past contributions, or maintainer lists with the same underlying assumption that authorship can be trusted. This is not a Git vulnerability, commit metadata has always been easy to fake unless signing is enforced. The problem is treating that metadata as a signal of trust. A human reviewer might question why a particular maintainer is making an unexpected change, but automated reviewers follow internal signals consistently. If those signals include author identity, spoofing becomes a way in.

Google Expands Gemini AI Use to Fight Malicious Ads

Google blocked or removed 8.3 billion ads and suspended 24.9 million advertiser accounts in 2025, including 602 million ads tied to scams. The company is increasingly using Gemini AI models to detect malicious advertising campaigns at scale. Cybercriminals are now using generative AI to create deceptive ads rapidly, and Google says Gemini analyzes billions of signals including advertiser behavior, account history, campaign patterns, and intent to determine whether an ad is malicious. By the end of 2025, the majority of Responsive Search Ads created in Google Ads were reviewed instantly with harmful content blocked at submission. Google says Gemini's accuracy has reduced incorrect advertiser suspensions by 80% and processes user reports much faster than previous systems. In the U.S., Google removed 1.7 billion ads and suspended 3.3 million advertiser accounts in 2025.

Windows / AD Security

Some Windows Domain Controllers Entering Reboot Loops After April Patches

Microsoft confirmed that some Windows domain controllers are entering restart loops due to Local Security Authority Subsystem Service (LSASS) crashes after installing the April 2026 security updates (KB5082063). The issue affects non-Global Catalog domain controllers in environments using Privileged Access Management (PAM). Affected DCs may restart repeatedly, preventing authentication and directory services from functioning and potentially rendering the domain unavailable. The issue can also occur when setting up new domain controllers or on existing ones if the server processes authentication requests very early in the startup process. Affected platforms include Windows Server 2025, 2022, 23H2, 2019, and 2016. This is unlikely to affect personal devices not managed by an IT department. Microsoft is still working on a fix and advises administrators to contact Microsoft Support for Business for mitigation measures.

North Korean Sapphire Sleet Targets macOS with Social Engineering Campaign

Microsoft Threat Intelligence uncovered a macOS-focused campaign by North Korean threat actor Sapphire Sleet that relies on social engineering rather than software vulnerabilities. The group impersonates legitimate software updates to trick users into manually running malicious files, stealing passwords, cryptocurrency assets, and personal data while avoiding macOS security checks. Sapphire Sleet uses AppleScript as a dedicated late-stage credential-harvesting component integrated with decoy update workflows. By persuading users to manually execute AppleScript or Terminal-based commands, Sapphire Sleet operates outside macOS protections such as Transparency, Consent, and Control (TCC), Gatekeeper, quarantine enforcement, and notarization checks. The campaign targets cryptocurrency, venture capital, blockchain organizations, and similar high-value targets. Microsoft shared details with Apple, which has implemented updates to detect and block infrastructure and malware associated with this campaign. The attack chain uses malicious .scpt files, multi-stage payload delivery, fake system dialogs, manipulation of the TCC database, persistence via launch daemons, and large-scale data exfiltration.

Microsoft's Original Windows Secure Boot Certificate Expiring

Microsoft's original Windows Secure Boot certificate is expiring, requiring one of the largest coordinated security maintenance efforts across the Windows ecosystem. Organizations should update affected PCs soon to maintain Secure Boot functionality. This is a planned security maintenance event, not an active threat, but failure to update could result in boot failures on systems with Secure Boot enabled.

General Security News

Ghost Breaches: AI-Generated Narratives Become New Threat Vector

Security researchers have documented incidents where AI language models generate convincing but entirely fictional data breach reports complete with technical details, named sources, and enough credibility to trigger full-scale crisis responses. In one case, a company faced a news story about a major breach that never happened, generated entirely by an AI system. In another, AI-powered news aggregators re-indexed years-old breach articles with new timestamps after a website redesign, treating resolved incidents as fresh stories. A third incident involved a cybersecurity publication running AI-generated quotes attributed to a real security researcher who had never spoken to the publication. AI systems now generate, amplify, and validate claims before security teams can confirm anything. Once a narrative enters the ecosystem, it can be ingested into threat intelligence feeds, risk scoring platforms, and automated workflows where fiction becomes signal. Security teams now need visibility into how their organization is being represented externally, not just what is happening internally. This creates a new class of false positive where fabricated breach narratives appear credible enough to trigger internal investigations, executive escalation, and defensive actions. Threat actors can weaponize fabricated breach narratives as pretext for phishing emails or IT impersonation.

CrowdStrike Selected for OpenAI's Trusted Access for Cyber Program

CrowdStrike has been selected for OpenAI's Trusted Access for Cyber (TAC) program. OpenAI released GPT-5.4-Cyber, a frontier model designed for defensive cybersecurity, with access through identity verification and tiered controls. OpenAI models are already in use across the CrowdStrike Falcon platform via AgentWorks, CrowdStrike's agentic AI framework. The CrowdStrike 2026 Global Threat Report documented the fastest eCrime breakout time at 27 seconds in 2025. As frontier models reach production, the volume of findings they generate will outpace what human teams can process manually. CrowdStrike tracks 280+ adversary groups, generating real-world attack data that determines which vulnerabilities matter most. The Falcon sensor observes AI agent actions at the endpoint level: commands executed, files accessed, network connections, processes spawned. CrowdStrike has visibility into more than 1,800 distinct AI applications and nearly 160 million unique application instances. The EU AI Act's next phase takes effect August 2, 2026.

Patch Priority

Vulnerability Disclosures

Multiple Industrial Control System Vulnerabilities Disclosed by CISA

CISA published advisories for vulnerabilities in Anviz access control products, Delta Electronics ASDA-Soft, AVEVA Pipeline Simulation, and Horner Automation Cscape PLCs. The Anviz advisory covers 12 CVEs affecting CX2 Lite, CX7 access control devices, and CrossChex Standard software. Vulnerabilities include unauthenticated photo capture via POST, unauthenticated debug configuration disclosure, unauthenticated modification of debug settings (enabling SSH), and authenticated command injection leading to root-level access. Anviz did not respond to CISA's coordination attempts. Delta Electronics ASDA-Soft CVE-2026-5726 is a stack-based buffer overflow triggered during parsing of malformed .par files, potentially allowing arbitrary code execution. Fixed in ASDA-Soft v7.2.6.0. AVEVA Pipeline Simulation CVE-2026-5387 allows unauthenticated attackers to modify simulation parameters, training configuration, and training records via privilege escalation. Fixed in 2025 SP1 P01. Horner Automation CVE-2026-6284 allows brute force password discovery due to limited password complexity and no input limiters. Fixed in Cscape v10.2 SP2 and latest XL4/XL7 firmware.

Multiple Third-Party Component Vulnerabilities in Microsoft Update Guide

Microsoft published multiple CVE disclosures for third-party components used in Microsoft products including jq (JSON processor), SpdyStream, SymCrypt, libssh, and Prometheus. The jq vulnerabilities (CVE-2026-33948, CVE-2026-40164, CVE-2026-39956, CVE-2026-32316, CVE-2026-33947, CVE-2026-39979) include embedded-NUL truncation, algorithmic complexity DoS, missing runtime type checks, integer overflow, unbounded recursion, and out-of-bounds read issues. CVE-2026-35469 affects SpdyStream with DoS on CRI. CVE-2026-35199 affects SymCrypt with heap overflow via 64-to-32-bit leaf-count truncation. CVE-2025-14821 affects libssh with insecure default configuration on Windows leading to local man-in-the-middle attacks. CVE-2026-40179 affects Prometheus with stored XSS via metric names and label values. CVE-2025-64669 is a Windows Admin Center elevation of privilege vulnerability.

Mirai-like Botnet Exploiting End-of-Life TP-Link Routers (CVE-2023-33538)

Palo Alto Networks Unit 42 analyzed active exploitation attempts targeting CVE-2023-33538, a command injection vulnerability in end-of-life TP-Link Wi-Fi routers including TL-WR940N, TL-WR740N, and TL-WR841N. The vulnerability was added to CISA KEV in June 2025. Observed payloads are malicious binaries characteristic of Mirai-like botnet malware. Exploits attempt to download ELF binaries using wget, grant execute permissions with chmod 777, and execute the malware. Unit 42's analysis confirmed the underlying vulnerability is real, though the specific in-the-wild attacks observed were flawed and would fail. Successful exploitation requires authentication to the router's web interface, but widespread use of default IoT credentials makes this a practical infection vector. TP-Link confirmed the affected devices are end-of-life with no vendor patches available and recommends replacing units with supported hardware.

Trends & Context

Today's brief highlights the shrinking window between vulnerability disclosure and exploitation. Apache ActiveMQ's 13-year-old vulnerability went from discovery to active exploitation within weeks. Microsoft Defender zero-days are being weaponized immediately upon public disclosure. AI-powered exploit development is collapsing the traditional patch cycle, with Claude Opus generating working Chrome exploits for $2,283 in API costs. Organizations can no longer rely on the assumption that they have weeks or months to patch after disclosure. Defense requires faster patching cycles, better segmentation to limit blast radius, and robust detection for post-compromise activity. The rise of AI-generated content also introduces a new threat vector: fabricated breach narratives that trigger real-world crisis responses before security teams can validate whether incidents actually occurred.