CVE-2017-17215, CVE-2023-33538, CVE-2024-32114, CVE-2024-3721, CVE-2025-26399, CVE-2025-5777, CVE-2026-33032, CVE-2026-33825, CVE-2026-34197, CVE-2026-6296, CVE-2026-6311, CVE-2026-6313, CVE-2026-6359, CVE-2026-6363, CVE-2026-6364
Get tomorrow's brief in your inbox
Today: Microsoft Defender zero-days are being actively exploited with two still unpatched. Apache ActiveMQ gets a 13-year-old RCE added to CISA KEV with a two-week patch deadline. Payouts King ransomware uses QEMU virtual machines to hide from endpoint security while stealing domain credentials.
Three Microsoft Defender Zero-Days Under Active Exploitation (CVE-2026-33825)
Microsoft Defender is under attack through three zero-day vulnerabilities collectively known as BlueHammer, RedSun, and UnDefend. All three are being actively exploited in the wild. BlueHammer (CVE-2026-33825, EPSS 0.000/12th percentile) was patched in this week's Patch Tuesday, but RedSun and UnDefend remain unpatched. BlueHammer and RedSun enable local privilege escalation while UnDefend triggers denial-of-service and blocks definition updates. Huntress observed exploitation starting April 10 for BlueHammer, with RedSun and UnDefend exploitation beginning April 16. These exploits followed typical enumeration commands indicating hands-on-keyboard activity. All three flaws were disclosed by researcher Chaotic Eclipse in response to Microsoft's handling of the vulnerability disclosure process.
Apache ActiveMQ 13-Year-Old RCE Added to CISA KEV (CVE-2026-34197)
CISA added CVE-2026-34197 to the Known Exploited Vulnerabilities catalog with a patch deadline of April 30. This remote code execution flaw in Apache ActiveMQ has been hiding in the codebase for 13 years. The vulnerability allows authenticated users to execute arbitrary code via the Jolokia management API. The flaw was discovered using Anthropic's Claude AI by Horizon3 researcher Naveen Sunkavally. Many deployments use default credentials (admin:admin), making authentication trivial. On ActiveMQ versions 6.0.0 through 6.1.1, CVE-2024-32114 (EPSS 0.020/84th percentile) exposes the Jolokia API without authentication, creating an unauthenticated RCE chain. Over 8,000 ActiveMQ instances are publicly exposed according to ShadowServer monitoring.
SolarWinds Web Help Desk Exploitation in Payouts King Campaigns (CVE-2025-26399)
CVE-2025-26399 is a SolarWinds Web Help Desk vulnerability being exploited by the GOLD ENCOUNTER threat group in Payouts King ransomware campaigns. This vulnerability is on CISA KEV with a March 12 due date (EPSS 0.322/97th percentile). Recent attacks also leveraged exposed Cisco SSL VPN and Microsoft Teams social engineering where attackers posed as IT staff to trick employees into installing QuickAssist.
Payouts King Ransomware Uses QEMU VMs to Bypass Endpoint Security
Payouts King ransomware deploys QEMU virtual machines running Alpine Linux to evade endpoint detection. Security solutions on the host cannot scan inside VMs, allowing attackers to execute payloads, store malicious tools, and create covert SSH tunnels. Sophos documented two campaigns: STAC4713 (linked to Payouts King, active since November 2025) and STAC3725 (exploiting CitrixBleed 2/CVE-2025-5777 in NetScaler). The STAC4713 campaign creates a scheduled task named TPMProfiler to launch hidden QEMU VMs as SYSTEM. The VM includes AdaptixC2, Chisel, BusyBox, and Rclone. Initial access vectors include exposed SonicWall VPNs, SolarWinds Web Help Desk exploitation (CVE-2025-26399), exposed Cisco SSL VPN, and Microsoft Teams phishing with QuickAssist abuse. Post-infection, attackers use VSS to create shadow copies, then extract NTDS.dit, SAM, and SYSTEM hives. In both campaigns, attackers sideload Havoc C2 via ADNotificationManager.exe and exfiltrate data using Rclone to remote SFTP. Zscaler links Payouts King to former BlackBasta affiliates based on similar tactics. The ransomware uses AES-256 CTR with RSA-4096, terminates security tools via low-level system calls, and employs intermittent encryption for larger files.
Former Black Basta Affiliates Automating Executive Targeting
Reliaquest reports that former Black Basta affiliates are evolving the gang's social engineering playbook into faster, more automated attacks targeting senior leadership. Black Basta was active from early 2022 until its internal chat logs leaked in February 2025. The new campaign uses a two-pronged approach: mass email bombing to overwhelm the target's inbox followed by Microsoft Teams help desk impersonation to gain remote access. In some cases, attackers moved from initial chat engagement to executing malicious scripts in as little as 12 minutes. This represents a significant acceleration of the social engineering timeline.
Scattered Spider Member Tyler Buchanan Pleads Guilty
Tyler Robert Buchanan of Scotland pleaded guilty to conspiracy to commit wire fraud and aggravated identity theft. Between September 2021 and April 2023, Buchanan and co-conspirators conducted cyber intrusions and virtual currency thefts targeting entertainment companies, telecom firms, technology companies, BPO/IT suppliers, cloud communications providers, and individuals. They defrauded at least a dozen companies and employees throughout the U.S. Buchanan faces sentencing on August 21 with a statutory maximum of 22 years. His co-defendant Noah Michael Urban ("King Bob") was sentenced to ten years and $13 million in restitution in August 2025. Three other defendants (Ahmed Hossam Eldin Elbadawy, Evans Onyeaka Osiebo, and Joel Martin Evans) still face charges.
Mirai Variant Nexcorium Exploits TBK DVRs (CVE-2024-3721)
Nexcorium, a Mirai variant, exploits CVE-2024-3721 (CVSS 6.3, EPSS 0.839/99th percentile) in TBK DVR-4104 and DVR-4216 devices to deploy botnet malware. The attack chain downloads a script that launches architecture-specific payloads with the message "nexuscorp has taken control." The malware includes an exploit for CVE-2017-17215 targeting Huawei HG532 devices and hard-coded credentials for Telnet brute-force attacks. If successful, it establishes persistence via crontab and systemd, connects to C2 for DDoS commands (UDP, TCP, SMTP), then deletes the original binary to evade analysis. The malware supports multiple architectures and downloads pre-built command handlers as source code from the server, compiling them on the infected machine to reduce its static footprint.
Unit 42 also observed automated scans attempting to exploit CVE-2023-33538 (CVSS 8.8, EPSS 0.911/100th percentile, CISA KEV due July 7, 2025) in end-of-life TP-Link routers (TL-WR940N, TL-WR740N, TL-WR841N). The observed attacks were flawed and failed, but the underlying vulnerability is real and requires authentication to the router's web interface. The attacks attempt to deploy Mirai-like malware with source code referencing the string "Condi."
AgingFly Malware Targets Ukrainian Government and Hospitals
Ukraine's CERT-UA uncovered campaign UAC-0247 using AgingFly malware to target local governments, hospitals, and possibly defense personnel. The attack starts with phishing emails disguised as humanitarian aid offers containing malicious shortcut files. These trigger scripts and loaders that deploy AgingFly, a C# malware providing remote control. Capabilities include command execution, file theft, screenshots, keylogging, and payload deployment. The malware uses PowerShell to update configurations and retrieves C2 details through Telegram. It downloads command handlers as source code from the server and compiles them locally to reduce static footprint and evade signature-based detection. Attackers use ChromElevator for browser credential theft, ZAPiDESK for WhatsApp decryption, and RustScan, Ligolo-ng, and Chisel for reconnaissance and lateral movement. CERT-UA documented at least a dozen impacted organizations.
Windows Server 2025 Rogue Upgrade Issue Marked Resolved After Boot Loop Fix
Microsoft declared resolved the 2024 issue where security updates unexpectedly upgraded Windows Servers to Server 2025. The incident has been closed as of KB5082063, though this cumulative update introduces its own issue: non-Global Catalog domain controllers in environments using Privileged Access Management experience LSASS crashes during startup, causing repeated reboots and potentially rendering the domain unavailable. Microsoft blamed the original 2025 upgrade issue on third-party patch management tools not properly interpreting the Optional update classification, though several administrators reported servers without third-party tools also received the unwanted upgrade. Microsoft promises a fix for the boot loop problem in the coming days.
Nginx UI Authentication Bypass Under Active Exploitation (CVE-2026-33032)
CVE-2026-33032 (EPSS 0.050/90th percentile), a critical authentication bypass in Nginx UI, is being actively exploited to hijack servers. This vulnerability allows attackers to bypass authentication and gain control of Nginx UI instances. Exploitation has been observed in the wild.
W3LL Phishing Platform Dismantled, Developer Arrested
The FBI, working with Indonesian authorities, dismantled the W3LL phishing platform, seized its infrastructure, and arrested its alleged developer. W3LL kits sold for $500 and enabled criminals to clone login portals, steal credentials, bypass MFA using adversary-in-the-middle techniques, and launch business email compromise attacks. More than 25,000 compromised accounts were sold through the W3LL Store marketplace, fueling over $20 million in attempted fraud. After the storefront shut down in 2023, operations continued through encrypted channels under new branding. The platform was used against over 17,000 victims worldwide and helped more than 500 threat actors commit financial fraud.
North Korean IT Worker Scheme Sentencers Imposed
Two U.S. nationals received sentences for helping North Korean IT workers pose as American residents and secure remote jobs at over 100 U.S. companies, including Fortune 500 firms. Between 2021 and 2024, the scheme generated over $5 million for the DPRK and caused about $3 million in losses to victim companies. The defendants used stolen identities from over 80 U.S. citizens, created fake companies and financial accounts, and hosted company-issued laptops in U.S. homes so North Korean workers could secretly access corporate networks. Kejia Wang received nine years, while Zhenxing Wang received over seven years. The broader network remains active with additional suspects at large.
Grinex Exchange Blames Western Intelligence for $13.7M Hack
Kyrgyzstan-based cryptocurrency exchange Grinex suspended operations after a $13.7 million hack it attributes to Western intelligence agencies. Grinex is believed to be a rebrand of Garantex, a Russian exchange whose admin was arrested and domains seized for processing over $100 million in illicit transactions. The U.S. Treasury sanctioned Grinex in August 2025 for continuing Garantex operations. The theft occurred April 15 at 12:00 UTC. Stolen USDT was sent to TRON and Ethereum addresses, converted to TRX and ETH via SunSwap to avoid Tether freezing the stablecoins. TRM Labs identified 70 attacker addresses and discovered a simultaneous hack at TokenSpot, another Kyrgyzstan exchange with Grinex ties. TRM links TokenSpot to Houthi-linked laundering, weapons procurement, and Moldova influence operations. No technical evidence supports the Western intelligence attribution claim.
Microsoft Defender Predictive Shielding Disrupts Domain Compromise
Microsoft published a case study on how predictive shielding in automatic attack disruption contained an Active Directory domain compromise. Predictive shielding focuses on moments when credentials are likely exposed: when Defender detects high-confidence credential theft activity on a device, it proactively restricts the accounts that might have been exposed there, limiting lateral movement and high-impact identity operations. This approach addresses the speed gap where attackers can reuse newly exposed credentials faster than responders can scope, reset, and clean up. The case study demonstrates how exposure-based containment stopped an attacker who had achieved domain-level control. Once an attacker obtains domain-administration rights, they can change group memberships and ACLs, mint Kerberos tickets, replicate directory secrets, and push policy through Group Policy Objects. The capability is available for Microsoft Defender for Endpoint P2 customers who meet prerequisites.
AI Ghost Narratives Create Crisis Response Challenges
CyberScoop reports on three types of AI-generated fake narratives causing crisis response issues. First, language models generate entirely fictional breach stories with specific, technical details that appear convincing. Before companies realize the breach didn't happen, reporters request comment and companies mobilize communications teams. Second, website redesigns assign new URLs and timestamps to old breach articles, causing AI-powered news aggregators to flag resolved incidents as fresh stories. Third, AI generates fake quotes attributed to real security researchers and publications run them as fact. Sullivan and Callow recommend that entities develop Non-Incident Response Plans including quick response to journalists' inquiries and proactive website/social media notices when fake claims emerge. For journalists, the article raises unresolved questions about verifying AI-generated quotes when it's unrealistic to contact everyone quoted in news stories.
Anthropic CEO Meets White House on Mythos Security Implications
Anthropic CEO Dario Amodei met with White House Chief of Staff Susie Wiles on Friday to discuss national security implications of Mythos, the company's new AI model capable of finding and exploiting software vulnerabilities. The model is so powerful that Anthropic restricted access to roughly 50 organizations (Microsoft, Apple, AWS, CrowdStrike, and other critical infrastructure vendors) under Project Glasswing. The meeting reflects the paradox of the Trump administration attempting to blacklist Anthropic over Pentagon AI disputes while simultaneously engaging with the company over Mythos risks. Bruce Schneier notes in his analysis that we lack critical information to evaluate Anthropic's decision: the false positive rate, how well Mythos performs on software outside its training distribution (industrial control systems, medical devices, bespoke financial infrastructure, older embedded systems), and whether 50 companies can substitute for distributed expertise of the entire research community. Schneier argues that domain specialists in under-represented fields could use Mythos as a force multiplier to probe systems Anthropic's engineers lack expertise to audit.
EU Age Verification App Hacked Within 2 Minutes
The European Commission unveiled a mobile age-verification app in Brussels on Wednesday. European Commission President Ursula von der Leyen presented the open-source tool as technically ready for use as countries move to ban kids from social media. Cybersecurity and privacy experts immediately examined the source code on GitHub and reported glaring privacy and security problems with the app's design within minutes of release.
Atlassian Mandates AI Training Data Collection for Lower Tiers
Starting August 17, Atlassian will collect customer data to train its AI models. Metadata collection (readability scores, task classifications, semantic similarity scores, story points, sprint dates, SLA times) is mandatory for Free, Standard, and Premium customers with no opt-out. Lower tiers have in-app data collection (Confluence page content, Jira descriptions/comments, custom emoji names, workflow names) turned on by default but can opt out. Enterprise customers have in-app collection off by default. Metadata is de-identified and aggregated, stored up to seven years. Exceptions include customers using customer-managed keys, BYOK, Atlassian Government Cloud, Isolated Cloud, HIPAA compliance requirements, and some government/financial services customers. Once opted out or apps deleted, in-app data is removed within 30 days and models retrained within 90 days.
Chromium Vulnerabilities in Microsoft Edge
Microsoft released updates for Edge (Chromium-based) addressing multiple Chromium CVEs: CVE-2026-6296 (heap buffer overflow in ANGLE, EPSS 0.000/6th percentile), CVE-2026-6363 (type confusion in V8, EPSS 0.001/21st percentile), CVE-2026-6359 (use after free in Video, EPSS 0.001/21st percentile), CVE-2026-6364 (out of bounds read in Skia, EPSS 0.000/8th percentile), CVE-2026-6313 (insufficient policy enforcement in CORS, EPSS 0.000/1st percentile), CVE-2026-6311 (uninitialized use in Accessibility, EPSS 0.000/6th percentile). Updates are available through Chrome releases.
Oklahoma Tax Commission 18-Month Undetected Breach
The Oklahoma Tax Commission suffered a breach lasting 18 months (July 2024 to December 2025) before detecting unauthorized access to W-2 and 1099 files in their online taxpayer portal. The Maine filing indicates 14 Maine residents affected but does not reveal total victim count. Oklahoma's breach transparency page lists the incident but states "it is not clear" how many individuals were affected.
Northern Ireland C2K School System Restored After Cyberattack
The C2K network managed by the Education Authority, which provides all online and IT systems for Northern Ireland schools, was largely restored after a cyberattack last week. The attack left all schools and pupils unable to log into their accounts during exam season. The EA reports 414,000 user accounts (pupils, teachers, non-teaching staff) have been successfully reconnected. A 16-year-old boy was arrested in Portadown, County Armagh, on suspicion of Computer Misuse Act offenses and released pending investigation.
The most significant pattern today is attackers weaponizing legitimate tools and trusted infrastructure to evade detection. Payouts King uses QEMU virtual machines to hide from endpoint security. Former Black Basta affiliates exploit Microsoft Teams' trusted position for help desk impersonation. North Korean IT workers use legitimate remote work infrastructure to access corporate networks. This trend makes traditional security controls less effective and requires behavioral analysis rather than signature-based detection. The second pattern is the acceleration of attack timelines: Black Basta affiliates move from initial Teams contact to malicious script execution in 12 minutes, while the 13-year-old Apache ActiveMQ flaw demonstrates how long vulnerabilities can hide before weaponization. Finally, AI is introducing new challenges both as a force multiplier for attackers (Mythos finding vulnerabilities) and as a source of misinformation (ghost breach narratives requiring crisis response).