← Carolina Clear Tech

Cyber Threat Brief

2026-04-24

Listen to this brief (31:24)

Download MP3
Show Notes

Show Notes - 2026-04-24

Stories Covered

CVEs Referenced

CVE-2025-20333, CVE-2025-20362, CVE-2025-60710, CVE-2025-65856, CVE-2025-70994, CVE-2026-0740, CVE-2026-27174, CVE-2026-27175, CVE-2026-28950, CVE-2026-33102, CVE-2026-33626, CVE-2026-33819, CVE-2026-33825, CVE-2026-35431, CVE-2026-3844, CVE-2026-3893, CVE-2026-39987, CVE-2026-6074, CVE-2026-6375, CVE-2026-6376

Indicators of Compromise

IP Addresses: 169.254.169.254, 51.7.0.77, 63.8.0.4, 48.8.0.4, 62.8.0.4

Read the full brief

Get tomorrow's brief in your inbox

Protect Your Business

Need a security assessment? See our cybersecurity packages.

View Services

Daily IT Security Brief - 2026-04-24

Today: CISA orders federal agencies to patch Microsoft Defender BlueHammer zero-day within two weeks. A state-sponsored backdoor survives Cisco firewall patches through six months of persistence. Bitwarden CLI package compromised in supply chain attack targeting developer credentials.

Critical Alerts

BlueHammer Microsoft Defender Zero-Day Exploited (CVE-2026-33825)

CISA added the BlueHammer vulnerability to its Known Exploited Vulnerabilities catalog on Monday, giving federal agencies until May 7 to patch. CVE-2026-33825 is a high-severity privilege escalation flaw in Microsoft Defender that allows low-privileged local attackers to gain SYSTEM permissions. Microsoft patched it April 14, but proof-of-concept exploit code was published April 7 after a researcher using the handle "Chaotic Eclipse" leaked the vulnerability in protest over Microsoft's disclosure handling. Huntress Labs confirmed active exploitation showing hands-on-keyboard threat actor activity with evidence of broader intrusion. The activity included suspicious FortiGate SSL VPN access from a Russian IP. CISA also added CVE-2025-60710, a Windows Task Host privilege escalation flaw affecting Windows 11 and Windows Server 2025, to the KEV catalog last week. Both vulnerabilities grant SYSTEM-level access on unpatched devices.

Marimo Remote Code Execution (CVE-2026-39987)

CISA added CVE-2026-39987 to the KEV catalog based on evidence of active exploitation. The Marimo remote code execution vulnerability has a May 7 remediation deadline for federal agencies. EPSS score is 7.0% (91st percentile), indicating moderate likelihood of exploitation.

Business & Infrastructure Threats

FIRESTARTER Backdoor Persists on Cisco Firewalls After Patching

A state-sponsored threat actor tracked as UAT-4356 deployed the FIRESTARTER backdoor on Cisco ASA and Firepower devices, maintaining persistence even after organizations applied September 2025 security patches. CISA discovered the malware on a federal agency's Cisco Firepower device through continuous network monitoring. The backdoor survives firmware updates and standard reboots by manipulating the Cisco Service Platform mount list to restore itself during the boot sequence. Only a hard reboot (physical power disconnection) removes the implant. UAT-4356 initially exploited CVE-2025-20333 (RCE in VPN web server, EPSS 22.2%, 96th percentile) and CVE-2025-20362 (unauthorized access, EPSS 43.6%, 98th percentile) before patches were applied in September 2025. The attackers first deployed LINE VIPER to extract configurations, credentials, and encryption keys, then installed FIRESTARTER for persistence. In the federal agency incident, the attackers used FIRESTARTER to redeploy LINE VIPER in March 2026, nearly six months after initial breach. CISA issued an updated Emergency Directive (ED 25-03 V1) requiring all federal civilian agencies to audit Cisco firewall infrastructure and submit device memory snapshots by Friday. Cisco Talos noted FIRESTARTER shares technical similarities with RayInitiator, suggesting shared development within UAT-4356's toolkit. Censys researchers previously found evidence indicating a China-based threat group behind the related ArcaneDoor campaign.

UNC6692 Social Engineering via Microsoft Teams Deploys SNOW Malware Suite

UNC6692 threat cluster leverages email bombing followed by Microsoft Teams impersonation to deploy a custom malware toolkit called SNOW. The attack begins with a flood of spam emails to overwhelm the target's inbox, creating urgency. The threat actor then contacts the victim via Microsoft Teams, claiming to be IT support offering help with the email problem. The victim is directed to click a phishing link for a "Mailbox Repair and Sync Utility v2.1.5" that downloads an AutoHotkey script from an AWS S3 bucket. The script performs reconnaissance and installs SNOWBELT, a malicious Chromium-based browser extension for Edge, using headless mode with the "--load-extension" switch. The SNOW ecosystem includes SNOWBELT (JavaScript backdoor), SNOWGLAZE (Python-based WebSocket tunneler), and SNOWBASIN (persistent command executor). The phishing page also harvests mailbox credentials through a fake "Health Check" authentication prompt, exfiltrating data to an Amazon S3 bucket. This tactic resembles methods used by former Black Basta affiliates. ReliaQuest reported 77% of observed incidents from March to April 2026 targeted senior-level employees, up from 59% in January-February. In some cases, Teams chats were initiated just 29 seconds apart across different targets.

Scattered Spider Defeats Password Reset Controls to Breach UK Retailer

The April 2025 Marks & Spencer attack disrupted operations for five days, causing an estimated $25.5 million in losses ($5.1 million daily). Attackers linked to Scattered Spider gained initial access by impersonating an M&S employee and convincing a third-party service desk to reset a password. With legitimate credentials, they exploited Active Directory to extract the NTDS.dit file containing all domain password hashes. The attackers cracked these hashes offline to recover additional credentials, then moved laterally using standard tools and normal login activity over several weeks. Once they had sufficient privileges, they deployed ransomware, encrypting systems supporting payments, e-commerce, and logistics. The breach highlights how social engineering can bypass technical controls when service desk verification processes rely on guessable or publicly available information rather than cryptographic identity verification.

LMDeploy SSRF Exploited 13 Hours After Disclosure

A Server-Side Request Forgery vulnerability in LMDeploy (CVE-2026-33626, CVSS 7.5) was exploited within 12 hours and 31 minutes of public disclosure. The flaw in the vision-language module's load_image() function allows attackers to access cloud metadata services, internal networks, and sensitive resources without validating internal or private IP addresses. Sysdig detected the first exploitation attempt against honeypot systems on April 22, 2026 at 03:35 AM UTC. Over an eight-minute session, the attacker used the vision-language image loader as an HTTP SSRF primitive to port-scan internal infrastructure including AWS Instance Metadata Service, Redis, MySQL, a secondary HTTP administrative interface, and an out-of-band DNS exfiltration endpoint. The attacker switched between different vision language models (internlm-xcomposer2, OpenGVLab/InternVL2-8B) likely to avoid detection. The vulnerability affects all LMDeploy versions 0.12.0 and prior with vision language support.

Ransomware & Extortion

Trigona Ransomware Deploys Custom Exfiltration Tool

Trigona ransomware attacks observed in March 2026 used a custom command-line exfiltration tool named "uploader_client.exe" instead of publicly available utilities like Rclone or MegaSync. The shift to proprietary malware indicates the affiliate is investing in tools with lower detection profiles. The tool connects to a hardcoded server and supports five simultaneous connections per file for faster parallel uploads, rotates TCP connections after 2GB of traffic to evade monitoring, allows selective file type exfiltration to exclude large media files, and requires an authentication key to restrict access to stolen data. In one incident, the tool exfiltrated high-value documents including invoices and PDFs from network drives. The attack chain installs Huorong Network Security Suite's HRSword as a kernel driver service, then deploys tools to disable security products (PCHunter, Gmer, YDark, WKTools, DumpGuard, StpProcessMonitorByovd) by leveraging vulnerable kernel drivers to terminate endpoint protection. PowerRun is used to execute utilities with elevated privileges, bypassing user-mode protections. AnyDesk provides remote access, while Mimikatz and Nirsoft utilities perform credential theft and password recovery. Trigona was launched in October 2022 as a double-extortion operation demanding payment in Monero. Ukrainian cyber activists disrupted operations in October 2023, but Symantec's report confirms the group has resumed activity.

RAMP Ransomware Marketplace Database Leaked

A leaked database from RAMP (Russia's ransomware marketplace) covering November 2021 to January 2024 reveals the commercial infrastructure behind ransomware operations. The MySQL dump contains 7,707 registered users, 1,732 forum threads, 340,333 IP log records, 1,899 private conversations, and 3,875 private messages. The leak exposes both public forum activity and private conversations that facilitated real attacks. RAMP functioned as a business platform where criminals sold access, recruited affiliates, advertised ransomware, and negotiated deals. Comparitech's analysis shows this was not a small corner of the internet but a large marketplace with significant activity and participant count.

Kyber Ransomware Uses Post-Quantum Cryptography

Kyber ransomware, active since September 2025, is the first confirmed ransomware family using post-quantum cryptography. Rapid7 reverse-engineered the Windows variant and confirmed it uses ML-KEM1024 (Module Lattice-based Key Encapsulation Mechanism), the highest strength version of NIST's PQC standard. Kyber uses ML-KEM to conceal the key used to encrypt victims' data with AES-256. The implementation is designed to resist attacks by quantum computers, which have no advantage in solving lattice-based mathematical problems. The ransomware name comes from the alternate name for ML-KEM. This represents a marketing approach emphasizing encryption strength, though AES-256 is already quantum-resistant and AES-128 would suffice against quantum attacks.

Windows / AD Security

PhantomRPC: New Windows RPC Privilege Escalation Technique

Kaspersky researchers disclosed PhantomRPC, a new privilege escalation technique in Windows RPC architecture that allows processes with impersonation privileges to escalate to SYSTEM level. The vulnerability affects all Windows versions and differs fundamentally from the "Potato" exploit family. Microsoft has not issued a patch despite proper disclosure. The research demonstrates five different exploitation paths showing how privileges can be escalated from various local or network service contexts to SYSTEM or high-privileged users. Some techniques rely on coercion, some require user interaction, and some exploit background services. The issue stems from an architectural weakness in RPC, meaning any new process or service depending on RPC could introduce another exploitation path. The research focuses on Advanced Local Procedure Call (ALPC) as the RPC transport mechanism.

Microsoft Entra ID SSRF Vulnerabilities

CVE-2026-35431 is a Server-Side Request Forgery in Microsoft Entra ID Entitlement Management that allows unauthorized attackers to perform spoofing over a network. CVE-2026-33102 is an Open Redirect in M365 Copilot allowing privilege escalation. CVE-2026-33819 is a deserialization flaw in Microsoft Bing allowing remote code execution.

Microsoft Teams Meeting Join Failures After Edge Update

A recent Microsoft Edge browser update introduced a regression preventing Windows users from joining Teams meetings via scheduled meetings or links. Restarting the Teams client temporarily resolves the issue. Microsoft is analyzing diagnostic data and monitoring recent service changes. A separate Edge update broke right-click paste functionality in Teams desktop client chats, with a fix rolling out through the next scheduled platform update. Another recent service update blocked some customers from launching Teams desktop client, leaving them stuck on the loading screen.

General Security News

Bitwarden CLI Compromised in Supply Chain Attack

Version 2026.4.0 of the Bitwarden CLI NPM package was compromised with malicious code designed to steal credentials and secrets. The malicious package, with over 250,000 monthly downloads, contained an altered execution path running a malicious loader that downloads a Bun archive from GitHub, extracts it, and executes a JavaScript payload. The malware targets secrets and tokens across Azure, AWS, GitHub, GCP, NPM, SSH material, shell history, AI tooling configuration, and MCP-related files. It weaponizes GitHub tokens by abusing GitHub Actions to create repositories in victim accounts, create branches, commit workflow files, and download resulting artifacts to extract more secrets. Data is exfiltrated via HTTPS or switches to GitHub paths if that fails. The attack is linked to the recent Checkmarx supply chain campaign and appears to leverage a compromised GitHub Action in Bitwarden's CI/CD pipeline. The payload contains the string "Shai-Hulud: The Third Coming," suggesting this is the latest phase of the Shai-Hulud worm campaign from 2025. The malware includes a Russian locale kill switch, quitting execution on systems with Russian locale. Shared tooling suggests connection to TeamPCP (also known as DeadCatx3, PCPcat, ShellForce), which claimed responsibility for the Checkmarx incident. Bitwarden confirmed the compromise but found no evidence that end user vault data was accessed or that production systems were compromised. The malicious version is no longer available on npm.

GopherWhisper APT Targets Government Entities

A China-linked threat actor named GopherWhisper has been active since 2023 targeting government entities using a Go-based custom toolkit. The group abuses legitimate services like Microsoft 365 Outlook, Slack, and Discord for command-and-control communication. ESET detected a campaign targeting a Mongolian government entity where the attackers deployed multiple backdoors. The malware set includes LaxGopher (Slack-based C2), RatGopher (Discord-based C2), BoxOfFriends (Microsoft Graph API/Outlook-based C2 using draft emails), SSLORDoor (C++ backdoor using OpenSSL over port 443), JabGopher (injector for LaxGopher), FriendDelivery (loader for BoxOfFriends), and CompactGopher (file collection and exfiltration to file.io). Researchers accessed attacker accounts using hardcoded credentials and recovered 6,044 Slack messages dating to August 2024 and 3,005 Discord messages from November 2023. Timestamp analysis showed commands issued between 12 AM and 12 PM UTC (8 AM to 8 PM in UTC+8 timezone matching China's work hours). ESET telemetry indicates 12 compromised systems in a Mongolian government institution, with dozens of other victims revealed through C2 traffic analysis.

China-Nexus Botnets Using Compromised SOHO Devices

International cybersecurity agencies from 15 countries issued a joint advisory describing a major shift in China-nexus threat actor tactics toward using large-scale networks of compromised devices. These covert networks are mainly composed of compromised Small Office Home Office routers, IoT devices, and smart devices. China-nexus actors are using these networks strategically and at scale for each phase of their cyber kill chains, from reconnaissance scans to malware delivery, C2 communication, and data exfiltration. Multiple covert networks have been created and are constantly updated, with a single network potentially used by multiple actors. Volt Typhoon used these networks to pre-position offensive capabilities on critical national infrastructure, while Flax Typhoon used a different covert network for cyber espionage. The advisory provides defensive guidance for organizations targeted by activity using covert networks as an access vector.

Apple Patches Exploited Notification Database Vulnerability

Apple released iOS/iPadOS 26.4.2 and iOS/iPadOS 18.7.8 fixing CVE-2026-28950, a Notification Services vulnerability. The issue allowed notifications marked for deletion to be unexpectedly retained on the device. Apple described it as a logging issue addressed with improved data redaction. While Apple did not mark the vulnerability as exploited, news reports revealed the FBI used this vulnerability to extract Signal messages from a device seized in a criminal case. Signal uses end-to-end encryption and attempts not to store retrievable data on the device, but may display notifications with sender username and message content. iOS did not delete notification contents even when marked for deletion, allowing forensic extraction tools to recover them. Signal has a setting to block message content from displaying in push notifications, which this case highlights as important for high-risk users.

NPM Supply Chain Malware Campaign

Multiple malicious packages were discovered in the npm registry: ixpresso-core, forge-jsx, @genoma-ui/components, @needl-ai/common, rrweb-v1, cjs-biginteger, sjs-biginteger, bjs-biginteger, @fairwords/websocket, @fairwords/loopback-connector-es, @fairwords/encryption, js-logger-pack, and @kindo/selfbot. These packages steal sensitive data, perform system reconnaissance, implant SSH backdoors by injecting attacker public keys into ~/.ssh/authorized_keys, deliver information stealers, and spread the XWorm remote access trojan. Packages under the "@fairwords" scope self-propagate to all npm packages using victim's tokens and attempt cross-ecosystem propagation to PyPI via .pth file injection.

DeFi Hack Steals $290 Million Through RPC Infrastructure Compromise

North Korean threat actors tracked as TraderTraitor compromised two RPC nodes hosted by LayerZero and DDoS'd a third node to poison downstream infrastructure. The attack against KelpDAO resulted in $290 million theft. This was not a smart contract hack but a sophisticated attack on off-chain infrastructure. The attackers compromised internal RPC nodes and DDoS'd external nodes to feed false data to a single-point-of-failure verification network (1-of-1 DVN setup), tricking the Ethereum contract into releasing funds based on a phantom token burn. TraderTraitor was previously attributed to the Bybit hack in early 2025 ($1.5 billion theft) and recently linked to the $285 million Drift Protocol theft. Arbitrum Security Council temporarily froze 30,766 ETH connected to the exploit.

WordPress Plugin Exploitation

Threat actors are exploiting vulnerabilities in Ninja Forms - File Upload (CVE-2026-0740, CVSS 9.8) and Breeze Cache (CVE-2026-3844, CVSS 9.8) to upload arbitrary files to susceptible WordPress sites, resulting in arbitrary code execution and complete takeover.

Rituals Cosmetics Data Breach

Dutch cosmetics company Rituals disclosed a data breach affecting an undisclosed number of "My Rituals" loyalty program members (over 41 million total members). Attackers stole personal information including full name, email address, phone number, date of birth, gender, and home address. No passwords or payment information were accessed. Rituals discovered the breach earlier in April after being alerted to unauthorized downloads, has since contained the breach by blocking attacker access, and found no evidence of data leakage online. The company notified relevant authorities and affected customers directly.

Mile Bluff Medical Center Ransomware Incident

Mile Bluff Medical Center in Mauston, Wisconsin reported a security event involving data encryption that disrupted phone and computer functions. Clinical teams shifted to downtime procedures while patient care continued. The hospital said some services experienced limited and temporary interruptions with narrow scope. No criminal group has publicly claimed responsibility as of April 23.

Patch Priority

Vulnerability Disclosures

MajorDoMo Smart Home Platform Exploited

CVE-2026-27175 (critical command injection) exploited since April 13 to drop PHP webshells for persistent backdoor access. CVE-2026-27174 (unauthenticated RCE via PHP console in admin panel) exploited since April 18, ending in Metasploit php/meterpreter/reverse_tcp payloads. EPSS scores are 84.9% (99th percentile) and 24.7% (96th percentile) respectively.

Milesight Camera Vulnerabilities

Six CVEs affecting multiple Milesight camera models (MS-Cxx63-PD, MS-Cxx64-xPD, MS-Cxx73-xPD, MS-Cxx75-xxPD, MS-Cxx83-xPD, and others). Successful exploitation could crash devices or allow remote code execution. All affected models run firmware versions <=51.7.0.77-r12, <=3x.8.0.3-r11, <=63.8.0.4-r3, <=48.8.0.4-r3, <=62.8.0.4-r5, or <=7x.9.0.19-r5.

SpiceJet Booking System Authorization Bypass

CVE-2026-6375 allows unauthenticated users to query passenger name records (PNRs) without access controls due to missing authorization checks. PNR identifiers follow predictable patterns enabling systematic enumeration. CVE-2026-6376 permits full passenger booking details to be accessed using only PNR and last name with no authentication, exposing extensive personal, travel, and booking metadata. SpiceJet did not respond to CISA coordination requests.

ICS Vulnerabilities

Carlson Software VASCO-B GNSS Receiver (CVE-2026-3893) - missing authentication allows remote attackers to modify configuration and operational functions. Update to version 1.4.0 or greater. Hangzhou Xiongmai Technology XM530 IP Camera (CVE-2025-65856) - authentication bypass in ONVIF implementation fails to enforce authentication on 31 critical endpoints, enabling unauthorized video stream access. Intrado 911 Emergency Gateway (CVE-2026-6074) - path traversal allowing unauthenticated access to management interface, enabling file read, modify, or delete. Patch released March 2, 2026. Yadea T5 Electric Bicycle (CVE-2025-70994) - weak authentication vulnerable to signal forgery after intercepting legitimate key fob transmissions, allowing vehicle theft.

Trends & Context

Supply chain attacks targeting developer tooling continue to escalate with rapid weaponization of newly disclosed vulnerabilities. The LMDeploy exploitation within 13 hours and the Bitwarden CLI compromise through GitHub Actions demonstrate how CI/CD infrastructure has become a critical attack surface. State-sponsored actors are investing in persistent backdoors that survive patching cycles, as evidenced by FIRESTARTER's six-month persistence on Cisco devices. Social engineering remains effective at bypassing technical controls when help desk verification relies on information that can be researched or guessed rather than cryptographic proof.