← Carolina Clear Tech

Cyber Threat Brief

2026-04-21

Listen to this brief (33:40)

Download MP3
Show Notes

Show Notes - 2026-04-21

Stories Covered

CVEs Referenced

CVE-2023-27351, CVE-2024-27198, CVE-2024-27199, CVE-2024-34359, CVE-2025-2749, CVE-2025-32975, CVE-2025-48700, CVE-2025-60710, CVE-2025-61620, CVE-2026-20122, CVE-2026-20128, CVE-2026-20133, CVE-2026-20204, CVE-2026-33825, CVE-2026-34197, CVE-2026-5760

Indicators of Compromise

Domains: Sfrclak[.]com

Read the full brief

Get tomorrow's brief in your inbox

Protect Your Business

Need a security assessment? See our cybersecurity packages.

View Services

Daily Cybersecurity Brief

April 21, 2026

Today: CISA added eight exploited vulnerabilities to its KEV catalog with federal patch deadlines ranging from April 23 to May 4, including three Cisco SD-WAN Manager flaws and critical issues in TeamCity, PaperCut, and Quest KACE. Axios npm suffered a supply chain compromise from suspected North Korean actors that delivered multi-stage malware payloads to roughly 100 million weekly downloads. Gentlemen ransomware affiliates deployed SystemBC proxy malware across a botnet of 1,570 corporate victims while Microsoft warns that Teams is increasingly abused for helpdesk impersonation attacks that lead to remote access and data theft.

Critical Alerts

CISA Adds Eight Exploited Vulnerabilities to KEV Catalog

CISA added eight actively exploited vulnerabilities to its KEV catalog on April 20, setting federal remediation deadlines between April 23 and May 4. The list includes CVE-2023-27351 (PaperCut NG/MF improper authentication, CVSS 8.2, EPSS 98th percentile), which was previously exploited by Lace Tempest to deliver Cl0p and LockBit ransomware in 2023. CVE-2024-27199 (JetBrains TeamCity path traversal, CVSS 7.3, EPSS 99th percentile) allows limited admin actions and was added alongside CVE-2024-27198, another TeamCity flaw added to KEV in March 2024. CVE-2025-32975 (Quest KACE SMA improper authentication, CVSS 10.0) was exploited as recently as March 2026 by unknown actors targeting unpatched systems. Three Cisco Catalyst SD-WAN Manager flaws round out the list: CVE-2026-20122 (privileged API misuse, CVSS 5.4), CVE-2026-20128 (passwords stored in recoverable format, CVSS 7.5), and CVE-2026-20133 (sensitive information exposure, CVSS 6.5). Cisco confirmed active exploitation of the first two in March 2026 but has not yet revised its advisory for CVE-2026-20133. Additional KEV entries include CVE-2025-2749 (Kentico Xperience path traversal, CVSS 7.2) and CVE-2025-48700 (Synacor Zimbra XSS, CVSS 6.1).

Apache ActiveMQ Code Injection (CVE-2026-34197)

CISA warns of active exploitation of CVE-2026-34197, a high-severity code injection vulnerability in Apache ActiveMQ that allows remote code execution. The flaw carries a CVSS score of 8.8 and EPSS score in the 98th percentile. Apache addressed the vulnerability in versions 5.19.4 and 6.2.3. CISA added this CVE to the KEV catalog with a federal remediation deadline of April 30, 2026.

Windows Task Host Privilege Escalation (CVE-2025-60710)

CISA flagged CVE-2025-60710 as actively exploited in the wild. This Windows Task Host privilege escalation flaw affects Windows 11 and Windows Server 2025, allowing a local attacker to gain SYSTEM privileges on compromised devices. The vulnerability is on the KEV catalog with a federal deadline of April 27, 2026, and has an EPSS score in the 95th percentile.

Microsoft Defender BlueHammer Zero-Day (CVE-2026-33825)

Microsoft patched CVE-2026-33825 in its April Patch Tuesday release, one of three actively exploited Microsoft Defender zero-days dubbed BlueHammer, RedSun, and UnDefend. The vulnerabilities allow local privilege escalation and denial of service. Researchers confirmed exploitation began in April after the vulnerabilities were publicly disclosed.

Axios npm Supply Chain Compromise

CISA issued an alert after suspected North Korean threat actors compromised Axios npm packages on March 31, 2026. Two versions ([email protected] and [email protected]) were injected with the malicious dependency [email protected] that downloads multi-stage payloads including a remote access trojan. Axios has roughly 100 million weekly downloads across enterprises, startups, and government systems. The compromised packages were identified within minutes by an Elastic researcher using AI-powered monitoring and removed within three hours, but may have been downloaded over 500,000 times in that window.

Ransomware & Extortion

Gentlemen Ransomware Deploys SystemBC Botnet

The Gentlemen ransomware-as-a-service operation, which emerged in mid-2025 and claims over 320 victims (240 in 2026 alone), has expanded its attack toolkit to include SystemBC proxy malware. Check Point researchers discovered a botnet of more than 1,570 corporate victims during an incident response engagement. SystemBC establishes SOCKS5 tunnels and connects to C2 servers using RC4-encrypted protocols, enabling covert payload delivery and exfiltration. The majority of victims are located in the United States, United Kingdom, Germany, Australia, and Romania. The infection profile strongly suggests targeting of corporate and organizational environments. Gentlemen provides multi-OS lockers for Windows, Linux, NAS, and BSD (written in Go) plus an ESXi locker (written in C), and grants affiliates access to EDR-killing tools. The ransomware uses a hybrid encryption scheme based on X25519 and XChaCha20, encrypting files under 1MB fully while larger files are encrypted in chunks of 9%, 3%, or 1%. Before encryption, the malware terminates databases, backup software, and virtualization processes, and deletes Shadow copies and logs.

Adaptavist Group Breach Spawns Imposter Emails

UK enterprise software consultancy The Adaptavist Group disclosed a security breach after an attacker used stolen credentials to gain unauthorized access to systems in late March. The company detected the incident, brought in external security specialists, and says affected systems contained typical business data such as contact information, contracts, and NDAs. The Gentlemen ransomware group claimed responsibility on its dark web leak site, boasting of a complete infrastructure compromise with hundreds of thousands of alleged customer records, source code for products like ScriptRunner, internal documents, credentials, and production systems. Adaptavist stresses there is no evidence that customer data was accessed despite the group's claims. An unknown third party has been sending misleading imposter emails to customers and partners, suggesting someone is leveraging the incident for phishing attacks.

Florida Ransomware Negotiator Pleads Guilty

Angelo Martino, 41, of Florida, pleaded guilty to conspiring to deploy BlackCat/ALPHV ransomware against U.S. companies while working as a ransomware negotiator at a cyber incident response company. Between April and November 2023, Martino abused his role by providing BlackCat actors with confidential information about five victim clients, including insurance policy limits and internal negotiation positions. He conspired with Ryan Goldberg of Georgia and Kevin Martin of Texas to deploy BlackCat ransomware, successfully extorting approximately $1.2 million in Bitcoin from one victim. Law enforcement seized $10 million in assets from Martino, including digital currency, vehicles, a food truck, and a luxury fishing boat obtained from offense proceeds. Martino faces sentencing on July 9, 2026.

Minidoka Memorial Hospital Cyberattack

Minidoka Memorial Hospital in Rupert, Idaho, suffered a cyber incident on Easter morning (April 5) that limited imaging services and led to some emergency patient transfers. The hospital posted an April 17 update stating the incident temporarily affected internal systems but did not prevent safe patient treatment. A new ransomware group called Blackwater added Minidoka to their dark web leak site on April 17, claiming they acquired 2,329,290 files (576 GB) with a leak deadline of April 24. The group provides no proof of claims and does not state whether data was encrypted. Blackwater may be a new group or rebrand, with only three listings on their site and no contact or group information provided.

Business & Infrastructure Threats

Microsoft Teams Abused in Helpdesk Impersonation Attacks

Microsoft warns that threat actors are increasingly abusing external Microsoft Teams collaboration to impersonate IT or helpdesk staff and trick employees into granting remote access. The multi-stage attack begins with the attacker contacting the target via external Teams chat, posing as company IT and claiming to address an account issue or security update. The goal is convincing the target to start a remote support session via Quick Assist, giving the attacker direct machine control. From there, attackers perform reconnaissance using Command Prompt and PowerShell, drop payloads via DLL side-loading into trusted signed applications (Autodesk, Adobe Acrobat/Reader, Windows Error Reporting, DLP software), establish C2 over HTTPS, and secure persistence via Registry modifications. Lateral movement occurs via Windows Remote Management (WinRM) targeting domain controllers and high-value assets. Attackers deploy additional remote management tools and use Rclone to exfiltrate targeted sensitive data to external cloud storage. Microsoft notes that follow-on activity is hard to distinguish from normal operations due to heavy use of legitimate applications and native administrative protocols.

Vercel Breach via Context.ai AI Tool Compromise

Web infrastructure provider Vercel disclosed a security breach originating from the compromise of Context.ai, a third-party AI tool used by a Vercel employee. The attacker used Context.ai access to take over the employee's Google Workspace account, enabling access to some Vercel environments and environment variables not marked as sensitive. A threat actor using the ShinyHunters persona claimed responsibility. Context.ai disclosed a March 2026 incident involving unauthorized AWS access and later acknowledged that OAuth tokens for some consumer users were likely compromised. Hudson Rock uncovered that a Context.ai employee was infected with Lumma Stealer in February 2026, raising the possibility of supply chain escalation from the malware infection.

Splunk Enterprise/Cloud Platform RCE (CVE-2026-20204)

Splunk released fixes for CVE-2026-20204, a high-severity vulnerability in Splunk Enterprise and Cloud Platform. The flaw allows a low-privileged user to upload a malicious file to a temporary directory and achieve remote code execution. Two additional medium-severity issues were also addressed in the same update.

Booking.com Data Breach

Booking.com confirmed a data breach after unauthorized parties accessed reservation data for some customers. Exposed information includes names, email addresses, phone numbers, physical addresses, and booking details, creating phishing risk. The company reset reservation PINs and notified affected users.

McGraw-Hill Data Breach via Salesforce

McGraw-Hill disclosed a data breach following an extortion attempt after attackers accessed its Salesforce environment. Leaked data from about 13.5 million accounts includes names, email addresses, phone numbers, and physical addresses. No payment card information was reported exposed.

Basic-Fit Gym Chain Data Breach

Basic-Fit, Europe's largest gym chain, reported a data breach after attackers accessed a franchise-wide system used to track club visits. The incident exposed bank account details and personal data for about one million members across six countries. Passwords and identity documents were not affected.

Seiko USA Website Defaced

The Seiko USA website was defaced over the weekend with a message claiming attackers stole the company's Shopify customer database and threatening to leak it unless a ransom is paid. The defaced "Press Lounge" section warned that attackers breached Shopify security and downloaded customer information including names, email addresses, phone numbers, order history, shipping data, and account details. The attackers gave Seiko USA 72 hours to contact them via an email address added to a specific Shopify customer account (ID 8069776801871). Seiko USA has since removed the extortion message but has not publicly confirmed or responded to the incident.

Windows / AD Security

Microsoft Credential Elimination and Managed Identities

Microsoft Deputy CISO for Dynamics 365 and Power Platform emphasizes credential elimination as a defense against opportunistic attacks. Most attackers log in with stolen credentials rather than breaking into networks. Microsoft has redesigned standards internally to eliminate passwords, client secrets, and API keys wherever workloads can authenticate without secrets. On Azure, the primary mechanisms are managed identities (workload identities issued by Entra ID) and federated identity patterns that mint tokens just-in-time with just-enough-access. This removes incident root causes tied to leaked or stale secrets and makes credential-free patterns accessible for organizations building on Microsoft platforms.

Windows Server April Update Causes Domain Controller Restart Loop

Microsoft pushed an out-of-band update to address a restart loop affecting some Windows Server devices after the April 2026 update (KB5082063). Domain controllers in environments with multiple domains using Privileged Access Management (PAM) experienced LSASS crashes during startup, causing repeated restarts that prevent authentication and directory services from functioning. The issue affected Windows Server 2016 through 2025. Microsoft issued out-of-band fixes and hotpatches. A separate known issue with the April update requires some enterprise devices with unrecommended BitLocker Group Policy configurations to enter their BitLocker recovery key on first restart.

General Security News

Scattered Spider Leader Pleads Guilty

Tyler Robert Buchanan, 24, a British man believed to be a leader of the Scattered Spider cybercrime collective, pleaded guilty in the United States to wire fraud and aggravated identity theft. Buchanan and co-conspirators stole at least $8 million in cryptocurrency after hacking at least a dozen companies through SMS phishing attacks between September 2021 and April 2023. The group sent hundreds of phishing messages purporting to be from victim companies or contracted IT/BPO suppliers, leading recipients to provide credentials on spoofed websites. The stolen information enabled SIM swap attacks, allowing control of phone numbers and virtual currency wallets. Buchanan was arrested in Spain in June 2024, has been in U.S. custody since April 2025, and will be sentenced on August 21, 2026, facing a statutory maximum of 22 years in prison. Three accomplices (Ahmed Hossam Eldin Elbadawy, Evans Onyeaka Osiebo, Joel Martin Evans) were charged in November 2024 and face up to 20 years. Noah Michael Urban, another key Scattered Spider member, was sentenced to 10 years in prison last year.

AI-Driven Breach of Mexican Government Agencies

Researchers revealed that a lone hacker weaponized Claude Code and OpenAI's GPT-4.1 to breach nine Mexican government agencies. AI-driven commands accelerated reconnaissance, issuing 5,317 actions across 34 sessions and accessing 195 million taxpayer records and 220 million civil records. Safety filters were bypassed through prompt manipulation and an injected hacking manual. This demonstrates how frontier AI models are collapsing the exploit window and enabling less-skilled attackers to conduct sophisticated operations.

Fake Claude AI Pro Installer Delivers PlugX

Researchers detailed a phishing campaign impersonating Anthropic's Claude AI with a fake Claude Pro installer for Windows. The package displays a working application to distract victims while abusing a trusted program to sideload PlugX malware, enabling remote access and persistence on compromised systems.

AI Agent Prompt Injection Hijacks GitHub Workflows

Researchers demonstrated a prompt injection technique that hijacks AI agents used in GitHub workflows from major vendors. Malicious instructions hidden in pull request titles or comments can make agents run commands and expose repository secrets, including access tokens and API keys, during automated development tasks.

WordPress Supply Chain Compromise

EssentialPlugin, a WordPress plugins development firm, suffered a supply chain compromise that pushed malicious updates to more than 30 plugins installed on thousands of websites. The backdoored code enabled unauthorized access and spam page creation. WordPress.org closed the affected plugins but infections may remain on sites that installed the compromised updates.

China's Apple App Store Crypto Wallet Scam

A set of 26 malicious apps on Apple App Store impersonate popular wallets such as Metamask, Coinbase, Trust Wallet, and OneKey to steal recovery seed phrases. The apps used typosquatting and fake branding, and were published as games or calculator apps to bypass China's restrictions on crypto apps. Once opened, the apps redirect users to phishing pages that convince victims to download trojanized wallet apps using iOS provisioning profiles. The apps intercept mnemonic phrases, encrypt them with RSA and Base64, and send them to attackers. Kaspersky named the campaign FakeWallet and associates it with the SparkKitty operation. Apple removed all 26 apps following responsible disclosure.

NGate Android Malware Steals NFC Payment Data

A new variant of NGate malware targets Android users by hiding in a trojanized version of HandyPay, a legitimate mobile payments processing tool. The malware steals payment card information through the device's NFC chip and sends it to attackers who create virtual cards for unauthorized purchases or ATM withdrawals. NGate uses HandyPay because it is cheaper (€9.99 per month versus $400-500 for alternatives) and requires no permissions beyond being set as the default payment app. The campaign has been active since November 2025, primarily targeting Android devices in Brazil via fake apps and lottery websites.

WAV Files as Malware Delivery Vector

SANS Internet Storm Center reported threat actors using WAV audio files as malware delivery vectors. The WAV files play (with audible noise) but contain BASE64-encoded payloads that replace sound data bytes. The BASE64-decoded payload is an XOR-encoded PE file. Researchers extracted and analyzed the payload without needing custom decoders by using known-plaintext attacks on the DOS header.

Patch Priority

Vulnerability Disclosures

Anthropic MCP Design Flaw Enables RCE

A critical by-design weakness in Anthropic's Model Context Protocol (MCP) architecture could enable remote code execution on any system running a vulnerable MCP implementation. The flaw affects unsafe defaults in how MCP configuration works over the STDIO transport interface, resulting in Arbitrary Command Execution on systems running the MCP SDK across Python, TypeScript, Java, and Rust. The vulnerability affects more than 7,000 publicly accessible servers and packages totaling over 150 million downloads. Ten vulnerabilities were discovered in popular projects like LiteLLM, LangChain, LangFlow, Flowise, LettaAI, and LangBot, with some vendors issuing patches. Anthropic declined to modify the protocol architecture, citing the behavior as expected, leaving the code execution risks unaddressed in the reference implementation and inherited by downstream developers.

SGLang RCE via Malicious GGUF Model Files (CVE-2026-5760)

A critical vulnerability in SGLang (CVSS 9.8) allows remote code execution via specially crafted GGUF model files. The flaw affects the reranking endpoint "/v1/rerank" and stems from use of jinja2.Environment() without sandboxing. An attacker creates a GGUF model file with a malicious tokenizer.chat_template containing a Jinja2 server-side template injection (SSTI) payload. When a victim downloads and loads the model and a request hits the endpoint, the malicious template executes arbitrary Python code. This falls under the same vulnerability class as CVE-2024-34359 (Llama Drama) and CVE-2025-61620 (vLLM). No patch was obtained during coordination.

Google Antigravity AI Agent Sandbox Escape

Researchers at Pillar Security disclosed a vulnerability in Antigravity, Google's AI-powered developer tool for filesystem operations. The bug, since patched, combined prompt injection with Antigravity's file-creation capability to grant remote code execution. The exploit circumvented Secure Mode, Google's highest security setting that runs commands in a virtual sandbox. A file-searching tool called find_by_name is classified as a native system tool, executing directly before Secure Mode can evaluate it. Prompt injection attacks can be delivered through compromised identity accounts or by hiding instructions in open-source files or web content the agent ingests. Google patched the flaw on February 28 after a January 6 disclosure and awarded a bug bounty.

BePrime Cybersecurity Company Breach

A Mexican cybersecurity company, BePrime, which provides connectivity and security services to large corporations including Iberdrola, ArcelorMittal, Whirlpool, and Alsea (operator of Starbucks, Domino's, Vips), was compromised via administrator accounts without multifactor authentication. A malicious actor claims to have leaked 12.6 GB of data and gained access to network infrastructure and video surveillance. BePrime has acknowledged an attack but disputes some claims. The company threatened legal action against journalists and media outlets disseminating information about the breach, prompting a coordinated advocacy response from international digital rights organizations including EFF, Reporters Without Borders, Committee to Protect Journalists, and others.

GreyNoise Traffic Surges Predict Edge Device Vulnerabilities

GreyNoise research shows that network traffic surges targeting specific edge device vendors often precede public vulnerability disclosures by a median of nine days. During a 103-day study, roughly half of every activity surge was followed by a vulnerability disclosure from the same targeted vendor within three weeks. The study identified 104 distinct activity surges across 18 vendors, primarily affecting embedded systems like routers, VPNs, firewalls, and security appliances. When both session counts (intensity) and unique source IPs (breadth) increase simultaneously, it signals coordinated escalation and a high-confidence reason for defenders to investigate.

Trends & Context

Frontier AI models are fundamentally changing the cybersecurity landscape by collapsing the exploit window and lowering the barrier for sophisticated attacks. This week's stories demonstrate how AI is being weaponized across the attack lifecycle (Mexican government breach, prompt injection, autonomous vulnerability discovery) while simultaneously enabling defensive detection (Axios compromise identified in minutes via AI monitoring). The traditional assumption that defenders have time to scan, triage, prioritize, and remediate before exploitation is breaking down. Organizations must shift from vulnerability management to exposure management, understanding not just what is vulnerable but what is reachable, exploitable, and likely to matter in a real attack. At the same time, supply chain attacks continue to escalate, targeting developer toolchains (Axios, WordPress, Context.ai) and demonstrating that trusted platforms remain the most efficient path to widespread compromise.