CVE-2026-22005, CVE-2026-27820, CVE-2026-31432, CVE-2026-31439, CVE-2026-31441, CVE-2026-31444, CVE-2026-31448, CVE-2026-31450, CVE-2026-31452, CVE-2026-31454, CVE-2026-31455, CVE-2026-31461, CVE-2026-31464, CVE-2026-31474, CVE-2026-31476, CVE-2026-31477, CVE-2026-31478, CVE-2026-31480, CVE-2026-31495, CVE-2026-31502, CVE-2026-31512, CVE-2026-31530, CVE-2026-3219, CVE-2026-33825, CVE-2026-35239, CVE-2026-40372, CVE-2026-5928, CVE-2026-6507
Domains:
checkmarx[.]cx, api-monitor[.]com, icp0[.]io
Get tomorrow's brief in your inbox
Today: Microsoft Defender zero-day (CVE-2026-33825) added to CISA KEV allows NTLM hash extraction and System privileges. Supply chain attacks escalate with Checkmarx compromise affecting Docker images and VS Code extensions, credential-stealing malware deployed to developer environments. ASP.NET Core critical bug (CVE-2026-40372) bypasses authentication on Linux/macOS systems.
Microsoft Defender Insufficient Granularity of Access Control (CVE-2026-33825)
CISA added CVE-2026-33825 to the Known Exploited Vulnerabilities Catalog based on evidence of active exploitation. The vulnerability in Microsoft Defender allows attackers to access the SAM database, extract NTLM password hashes, and gain System-level privileges on Windows systems. EPSS score is 0.001 (19th percentile), but active exploitation confirms real-world targeting.
Checkmarx Supply Chain Compromise: Docker Images and VS Code Extensions Poisoned
Unknown threat actors compromised the official Checkmarx KICS Docker Hub repository and multiple Visual Studio Code extensions with credential-stealing malware. Affected Docker tags include v2.1.20, v2.1.21, and alpine. The malicious KICS binary exfiltrates infrastructure-as-code scan results (which often contain credentials) to attacker-controlled servers. Four VS Code extensions (cx-dev-assist 1.17.0/1.19.0, ast-results 2.63.0/2.66.0) download and execute a backdated malicious commit (68ed490b) containing a 10MB mcpAddon.js payload that harvests GitHub tokens, AWS credentials, Azure tokens, Google Cloud credentials, npm tokens, SSH keys, environment variables, and Claude MCP configuration files. Exfiltration occurs via HTTPS endpoint audit.checkmarx[.]cx/v1/telemetry and public GitHub repositories created in victim accounts. 51 repositories identified so far with naming pattern matching "Checkmarx Configuration Storage."
<word>-<word>-<3 digits> (examples: gesserit-melange-813, atreides-heighliner-520). Rotate all developer credentials including GitHub PATs, AWS keys, Azure tokens, npm tokens, and SSH keys. Audit any GitHub Actions workflows created on or after April 22, 2026 1:48 PM UTC. Check for unexpected commits to ast-vscode-extension repository. This is a tier-1 supply chain attack against developer tooling with credential theft and propagation capabilities.ASP.NET Core DataProtection Cryptographic Signature Bypass (CVE-2026-40372)
Microsoft released an out-of-band patch for CVE-2026-40372, a critical (CVSS 9.1) privilege escalation vulnerability in ASP.NET Core 10.0.0-10.0.6. A regression in Microsoft.AspNetCore.DataProtection causes the authenticated encryptor to compute HMAC validation tags over incorrect payload bytes and discard the hash, allowing attackers to forge payloads that bypass authenticity checks and decrypt protected data in authentication cookies and antiforgery tokens. Exploitation grants SYSTEM privileges and file disclosure/modification capabilities. Affects only Linux, macOS, and non-Windows systems running the NuGet package version.
Kyber Ransomware Implements Post-Quantum Encryption on Windows
A new ransomware operation named Kyber is targeting Windows and VMware ESXi environments with two distinct variants deployed simultaneously. The Windows variant (written in Rust) uses Kyber1024 post-quantum key encapsulation with X25519 for key protection and AES-CTR for bulk encryption. The ESXi variant falsely advertises post-quantum encryption but actually uses ChaCha8 with RSA-4096. Both variants share the same campaign ID and Tor infrastructure, indicating coordinated deployment by a single affiliate. The Windows variant appends .#~~~ extensions, terminates services (SQL, Exchange, backup), deletes shadow copies, disables boot repair, clears event logs, and includes experimental Hyper-V VM shutdown. The ESXi variant encrypts datastore files with .xhsyw extensions and defaces management interfaces. Rapid7 identified one victim: a multi-billion-dollar American defense contractor and IT services provider. While post-quantum cryptography is technically notable, it does not change victim outcomes since files remain unrecoverable without the attacker's private key.
"The Gentlemen" Ransomware Group Rapidly Scales Operations
A new ransomware gang called "The Gentlemen" has impressed researchers with its speed in scaling operations and technical sophistication. Details on specific victims and tactics are limited in available reporting.
BlueLeaks 2.0: Navigate360 Breach Exposes 8.3M Anonymous Tips
Hacktivist group "Internet Yiff Machine" (IYM) obtained 93GB of data comprising 8.3 million anonymous tips from P3 Global Intel (acquired by Navigate360 in 2020). The dataset spans 1987 to November 2025 and includes first and last names of tipsters and subjects from school safety platforms, Crime Stoppers, and military reporting apps. Tips were stored in plain text without anonymization. IYM initially provided the data to DDoSecrets and subsequently put it up for sale. Navigate360 has not publicly confirmed the breach or notified affected individuals. Over 7,300 schools and referral systems are documented in the dataset. Student tips covered bullying, suicide ideation, and drug use. The breach represents a complete failure of anonymity promises made to vulnerable populations reporting sensitive information.
CanisterSprawl: Self-Propagating npm Supply Chain Worm
A self-propagating supply chain worm is spreading through npm packages by stealing developer credentials and using those tokens to inject malicious postinstall hooks into additional packages. Affected packages include @automagik/genie (4.260421.33-40), @fairwords/loopback-connector-es (1.4.3-4), @fairwords/websocket (1.0.38-39), @openwebconcept/design-tokens (1.0.1-3), @openwebconcept/theme-owc (1.0.1-3), and pgserve (1.1.11-14). The malware exfiltrates .npmrc files, SSH keys, git credentials, cloud credentials (AWS/GCP/Azure), Kubernetes/Docker configs, Terraform/Pulumi/Vault material, database passwords, .env files, shell history, browser credentials from Chromium-based browsers, and cryptocurrency wallet data. Stolen data is sent to telemetry.api-monitor[.]com and an ICP canister (cjn37-uyaaa-aaaac-qgnva-cai.raw.icp0[.]io). The worm includes PyPI propagation logic, using .pth-based payloads to execute when Python starts and uploads malicious Python packages with Twine if credentials are present. This is a multi-ecosystem, self-replicating supply chain attack that turns one compromised developer into additional package compromises.
LiteLLM, Axios, and CPU-Z Supply Chain Attacks Stopped by Behavioral Detection
SentinelOne blocked three tier-1 supply chain attacks in spring 2026 with no prior payload knowledge: LiteLLM (AI infrastructure package), Axios (JavaScript HTTP client), and CPU-Z (system diagnostic tool). The LiteLLM compromise (March 24, 2026) occurred when TeamPCP obtained PyPI credentials through a prior Trivy scanner compromise, publishing malicious versions 1.82.7 and 1.82.8 that executed credential theft payloads automatically. In one case, an AI coding agent running with unrestricted permissions (claude --dangerously-skip-permissions) auto-updated to the infected version and executed the payload without human review. SentinelOne detected and blocked malicious Python execution on the same day across multiple environments. The attacks exploited trusted delivery channels: AI agents with unrestricted permissions, phantom dependencies staged hours before detonation, and signed binaries from official vendor domains. No signature or IOA existed for any payload.
SBOM Data Struggles: Are SBOMs Failing?
Research indicates that while SBOM (Software Bill of Materials) adoption is increasing, security teams are struggling to turn SBOM and VEX data into actionable security decisions. Supply chain attacks continue to rise despite SBOM mandates. The missing piece is a governance-driven intelligence layer that translates SBOM data into explainable security decisions rather than raw dependency lists.
Mirai Botnet Targets Discontinued D-Link Routers
Mirai botnet operators are exploiting a command injection vulnerability in discontinued D-Link routers. The exploitation began one year after public disclosure and proof-of-concept code publication. D-Link has not released patches for the affected end-of-life hardware.
Malicious npm and PyPI Packages Deploy LLM Proxy Infrastructure
Two malicious packages (npm: kube-health-tools, PyPI: kube-node-health) masquerading as Kubernetes utilities install a Go-based binary that establishes a SOCKS5 proxy, reverse proxy, SFTP server, and LLM proxy on victim machines. The LLM proxy is an OpenAI-compatible API gateway that routes requests to Chinese LLM services like shubiaobiao. Every request passes through the router in plaintext, allowing the operator to inject malicious tool calls into coding agent responses (introducing pip install or curl | bash payloads mid-flight) and exfiltrate secrets from request/response bodies (API keys, AWS credentials, GitHub tokens, Ethereum keys, system prompts).
Xinference Python Package Compromised by Credential Stealer
The legitimate Python package "xinference" versions 2.6.0, 2.6.1, and 2.6.2 were compromised to include a Base64-encoded payload that fetches a second-stage credential harvester. JFrog analysis found the payload includes the comment "# hacked by teampcp." TeamPCP disputed responsibility on X, claiming it was a copycat.
UK NCSC Endorses Passkeys, Recommends Moving Away from Passwords
The UK National Cyber Security Centre officially endorsed passkeys as the default authentication standard, marking the first time the agency has told consumers to move away from passwords entirely. New guidance states passwords should not be used where passkeys are available. A technical report concludes passkeys are at least as secure as, and generally more secure than, password plus two-step verification. Google, eBay, and PayPal were named as major platforms that simplified passkey adoption, with around 50 percent of UK Google users registering at least one. Microsoft made passkeys the default nearly a year ago. Where passkeys are not available, NCSC advises using password managers with 2SV. NCSC CEO Richard Horne stated the number of nationally significant cyberattacks in the UK is similar to October levels (four per week). He urged organizations to prioritize security hygiene as the country enters "tumultuous uncertainty."
Microsoft Teams Introduces Efficiency Mode for Constrained Hardware
Microsoft is rolling out Efficiency Mode for Teams on systems with limited CPU and memory resources. The feature dynamically adjusts video resolution during meetings and launches Teams without a pre-selected chat to improve responsiveness. Rolling out to Windows and Mac in early to mid-May 2026. Enabled by default with an opt-out option in Settings > General. Microsoft is also introducing a tool to report suspicious external users, a Security Detection Report in Teams admin center for messaging security detections (impersonation, malicious URLs, weaponizable files), and automatic tagging of third-party bots in meeting lobbies.
Firefox and Thunderbird 150 Released
Mozilla released Firefox 150 and Thunderbird 150 with multiple refinements. Firefox improvements include enhanced split view (right-click to open links in new panes), improved PDF page manipulation (remove, reorder, copy/paste, export pages), network access restrictions now apply to local network devices, native Gtk emoji picker on Linux, and official RPM packages. Thunderbird 150 inherits Firefox's PDF handling improvements, supports the Unobtrusive Email Signatures standard for encrypted mail readability, can search encrypted message bodies, includes an enhanced Account Hub for simplified configuration, and allows copying address book entries to clipboard.
CVE-2026-6507: Dnsmasq DHCP Bootreply Out-of-Bounds Write
Microsoft published information on CVE-2026-6507, a denial-of-service vulnerability in dnsmasq due to an out-of-bounds write in DHCP bootreply processing. EPSS score is 0.000 (10th percentile). No additional technical details or patch information available.
CVE-2026-3219: pip Concatenated Archive Vulnerability
Microsoft published CVE-2026-3219 affecting pip. The vulnerability involves pip not rejecting concatenated ZIP and tar archives. EPSS score is 0.000 (2nd percentile). No severity or patch details provided.
Linux Kernel CVEs (ksmbd, ext4, xfs, CAN, SCSI, DRM, dmaengine, netfilter, Bluetooth)
Microsoft published 20 Linux kernel CVEs addressing various subsystems: ksmbd SMB server (CVE-2026-31476, CVE-2026-31432, CVE-2026-31477, CVE-2026-31444, CVE-2026-31478), ext4 filesystem (CVE-2026-31452, CVE-2026-31448, CVE-2026-31450), xfs filesystem (CVE-2026-31455, CVE-2026-31454), CAN protocol (CVE-2026-31474), SCSI (CVE-2026-31464), AMD display driver (CVE-2026-31461), dmaengine (CVE-2026-31441, CVE-2026-31439), network stack (CVE-2026-31502, CVE-2026-31495, CVE-2026-31512), CXL (CVE-2026-31530), and tracing (CVE-2026-31480). Most have no EPSS data available yet. These are maintenance fixes for memory leaks, use-after-free, out-of-bounds access, and NULL dereference issues.
CVE-2026-27820, CVE-2026-5928, CVE-2026-35239, CVE-2026-22005: Various Buffer Overflow and Memory Issues
Microsoft published four CVEs with minimal details: CVE-2026-27820 (zlib buffer overflow in GzipReader ungetc), CVE-2026-5928 (static buffer overflow in deprecated nis_local_principal), CVE-2026-35239 (no description), and CVE-2026-22005 (no description). EPSS scores range from 0.000 (2nd-12th percentile). No patch or severity information provided.
Today's coverage is dominated by supply chain attacks targeting developer tooling and infrastructure. The Checkmarx compromise, CanisterSprawl worm, and LiteLLM/Axios/CPU-Z attacks demonstrate a coordinated shift toward poisoning trusted software distribution channels. These attacks exploit the implicit trust developers place in package registries, official Docker repositories, and IDE extensions. The Microsoft Defender zero-day and ASP.NET Core critical bug highlight continued exploitation of privileged software components for credential access and privilege escalation. Organizations should prioritize supply chain security controls including dependency pinning, credential rotation, and behavioral monitoring that detects malicious activity even when payloads are unknown.