CVE-2024-57726, CVE-2024-57728, CVE-2024-7399, CVE-2025-13763, CVE-2025-20333, CVE-2025-20362, CVE-2025-29635, CVE-2025-48700, CVE-2025-66376, CVE-2026-23428, CVE-2026-23434, CVE-2026-23438, CVE-2026-23439, CVE-2026-23446, CVE-2026-23447, CVE-2026-41080, CVE-2026-41205, CVE-2026-41651
Get tomorrow's brief in your inbox
Today: CISA warns federal agencies that Cisco Firestarter backdoor survives patches and firmware updates, requiring hard resets by April 30. Four new actively exploited vulnerabilities hit the KEV catalog, including critical flaws in SimpleHelp and Zimbra. BlackFile extortion gang ramps up vishing attacks against retail and hospitality sectors with seven-figure ransom demands.
CISA Adds Four Known Exploited Vulnerabilities to Catalog
CISA added four actively exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog on April 24, requiring federal agencies to remediate by May 8, 2026. CVE-2024-7399 (CVSS 8.8, EPSS 71st percentile) is a path traversal flaw in Samsung MagicINFO 9 Server previously exploited to deploy Mirai botnets. CVE-2024-57726 (CVSS 9.9) and CVE-2024-57728 (CVSS 7.2) are authorization and path traversal bugs in SimpleHelp exploited by DragonForce ransomware as an initial access vector. CVE-2025-29635 (CVSS 7.5) is a command injection flaw in end-of-life D-Link DIR-823X routers used to deliver the "tuxnokill" Mirai variant.
Firestarter Malware Survives Cisco Firewall Updates and Security Patches
CISA and NCSC-UK issued an urgent warning that the Firestarter backdoor persists on Cisco Firepower and Secure Firewall devices even after patching CVE-2025-20333 (CVSS 9.9, EPSS 97th percentile) and CVE-2025-20362 (CVSS 6.5, EPSS 98th percentile). The malware, linked to China-nexus UAT-4356 (Storm-1849), was deployed on at least one federal agency's firewall in September 2025 and maintains access through firmware updates and reboots unless a hard power cycle occurs. Firestarter hooks into LINA (the core ASA process), modifies boot files, and reinstalls itself via signal handlers. The backdoor executes attacker-supplied shellcode delivered through specially crafted WebVPN requests.
show kernel process | include lina_cs. Any output indicates infection. CISA has published two YARA rules for detection. This is not resolved by patching alone.Over 10,000 Zimbra Servers Vulnerable to Ongoing XSS Attacks (CVE-2025-48700)
CISA flagged CVE-2025-48700 (EPSS 95th percentile) as actively exploited and added it to the KEV catalog with a three-day federal remediation deadline (April 23). The cross-site scripting vulnerability in Zimbra Collaboration Suite affects versions 8.8.15, 9.0, 10.0, and 10.1. Exploitation requires no user interaction and triggers when a user views a malicious email in Zimbra Classic UI. Shadowserver reports over 10,500 unpatched Zimbra servers remain exposed online, concentrated in Asia (3,794) and Europe (3,793). Russian APT28 (Fancy Bear) exploited a similar XSS flaw (CVE-2025-66376, EPSS 93rd percentile) in Operation GhostMail targeting Ukrainian government entities.
New BlackFile Extortion Group Linked to Surge of Vishing Attacks
BlackFile (also tracked as CL-CRI-1116, UNC6671, Cordial Spider) has targeted retail and hospitality organizations with vishing and data theft campaigns since February 2026, demanding seven-figure ransoms. Attackers impersonate IT helpdesk staff via spoofed VoIP numbers, trick employees into entering credentials and one-time passcodes on fake login pages, then register their own devices to bypass MFA. They escalate access to executive accounts by scraping internal directories, steal data from Salesforce and SharePoint using standard API functions, and publish stolen documents to their dark web leak site. Unit 42 links BlackFile with moderate confidence to "The Com," a cybercrime network targeting young people for extortion and CSAM production. RH-ISAC and CyberSteward report a significant increase in BlackFile incidents with TTPs similar to ShinyHunters and SLSH.
OCR Announces Settlements of Four Ransomware Investigations (427,000+ Affected)
HHS Office for Civil Rights (OCR) announced $1.165 million in settlements with four healthcare entities following ransomware investigations that collectively affected over 427,000 individuals. Regional Women's Health Group (Maze ransomware, 37,989 affected) paid $320,000 after failing to conduct risk analysis. Assured Imaging (Pysa ransomware, 244,813 affected) paid $375,000 for impermissible PHI disclosure and failure to notify affected individuals timely. Consociate Health (business associate, 136,539 affected) was compromised in July 2020 phishing attack leading to November 2021 ransomware. All entities agreed to two-year corrective action plans monitored by OCR. This marks 19 completed ransomware investigations and 13 Risk Analysis Initiative investigations by OCR.
ADT Confirms Data Breach After ShinyHunters Leak Threat
ADT confirmed a data breach on April 20 after detecting unauthorized access to customer and prospective customer data. The company terminated the intrusion and notified affected individuals. Stolen data includes names, phone numbers, addresses, and in a small percentage of cases, dates of birth and last four digits of Social Security numbers or Tax IDs. No payment information or security systems were compromised. ShinyHunters claims to have stolen 10 million records and threatens to leak data unless ransom is paid by April 27. The attackers told BleepingComputer they breached ADT through a vishing attack compromising an employee's Okta SSO account, then accessed Salesforce. ShinyHunters has conducted widespread vishing campaigns since last year targeting Microsoft Entra, Okta, and Google SSO accounts.
Crime Crew Impersonates Help Desk, Abuses Microsoft Teams to Steal Data (UNC6692)
Google Threat Intelligence Group identified a new threat group (UNC6692) using custom "Snow" malware in data-stealing attacks since late December 2025. Attackers spam organizations with overwhelming email volume, then contact targets via Microsoft Teams posing as helpdesk staff offering a "Mailbox Repair Utility." Victims are directed to a fake health check page that harvests credentials using a double-entry psychological trick that auto-rejects the first two password attempts. The phishing page performs a fake integrity check while exfiltrating credentials to an Amazon S3 bucket and installing malware. The Snow malware ecosystem includes SnowBelt (JavaScript browser extension backdoor), SnowGlaze (Python-based WebSocket tunneler), and SnowBasin (Python bindshell listening on port 8000). Malicious traffic is disguised as legitimate encrypted web traffic via Base64-encoded JSON over WebSockets to Heroku C2 infrastructure.
NASA Employees Duped in Chinese Phishing Scheme Targeting U.S. Defense Software
The NASA Office of Inspector General revealed that Chinese national Song Wu (Aviation Industry Corporation of China engineer) orchestrated a multi-year spear-phishing campaign from January 2017 to December 2021 targeting U.S. professors, researchers, and engineers. Song impersonated U.S. colleagues and friends to obtain aerospace modeling software used for weapons development. Victims at NASA, Air Force, Navy, Army, FAA, universities, and private firms shared sensitive defense technology without realizing they violated export control laws. Song faces wire fraud and 14 counts of aggravated identity theft (maximum 20 years per wire fraud count plus two-year consecutive sentence per identity theft count). The 40-year-old remains at large and has been added to the FBI Most Wanted List. The specialized software can be used for tactical missile development and weapons aerodynamic design.
China-Linked Threat Actors Expand Botnets to Disguise Cyberattacks
NCSC-UK and allied agencies warn that China-linked actors increasingly route attacks through vast proxy networks of compromised consumer devices including routers, cameras, DVRs, and NAS devices instead of rented infrastructure. Raptor Train botnet (linked to Flax Typhoon and Integrity Technology Group) infected over 260,000 devices in 2024. KV Botnet (Volt Typhoon) targets end-of-life routers and was revived in November 2024 after FBI disruption in January 2024. These constantly shifting proxy networks undermine traditional IP-blocking defenses and mask attack geographic origins. Targets include governments, telecom providers, defense contractors, and critical infrastructure.
Microsoft Now Lets Admins Uninstall Copilot on Enterprise Devices
Microsoft released the RemoveMicrosoftCopilotApp policy (Policy CSP and Group Policy) after April 2026 Patch Tuesday. The policy allows IT administrators to uninstall Copilot from Windows 11 25H2 devices where Microsoft 365 Copilot and Microsoft Copilot are both installed, the user did not install the app, and the app was not launched in the last 28 days. Available for Enterprise, Professional, and Education SKUs only via Intune or SCCM. Users can reinstall if they choose. Microsoft also stopped automatically installing Microsoft 365 Copilot app on Windows devices with Microsoft 365 desktop client apps and is reportedly canceling Copilot features for Windows 11 system notifications, Settings app, and File Explorer. In February, Microsoft disclosed a Copilot bug that summarized confidential emails bypassing DLP policies.
Microsoft to Roll Out Entra Passkeys on Windows in Late April
Microsoft will roll out passkey support for phishing-resistant passwordless authentication to Microsoft Entra-protected resources from Windows devices starting late April, with general availability expected mid-June 2026. Users can create device-bound passkeys stored in Windows Hello container and authenticate using face, fingerprint, or PIN. The feature extends passwordless sign-in to unmanaged Windows devices (not Microsoft Entra-joined or registered), supporting corporate, personal, and shared devices. Passkeys are cryptographically bound to each device and never transmitted over the network, preventing credential theft during phishing or malware attacks. Admin controls available via Conditional Access and Authentication Methods policies.
Windows Update Gets New Controls to Reduce Forced Restarts
Microsoft is rolling out improvements to Windows Insiders (Dev and Experimental channels) giving users more control over update installation. Changes include: pause updates for up to 35 days using a flyout calendar interface with unlimited extensions, separate Power menu options for "Restart" and "Shut down" that do not trigger updates, device type displayed in driver update titles (display, audio, battery), and consolidated monthly restarts that combine Driver, .NET, and firmware updates with monthly cumulative updates. Updates download in background and wait for coordinated installation aligned with the next Windows quality update or user-initiated approval.
New 'Pack2TheRoot' Flaw Gives Hackers Root Linux Access (CVE-2026-41651)
CVE-2026-41651 (CVSS 8.8) is a 12-year-old vulnerability in PackageKit daemon allowing local Linux users to install or remove system packages and gain root permissions. The flaw affects PackageKit versions 1.0.2 (November 2014) through 1.3.4. Deutsche Telekom Red Team discovered that commands like pkcon install could execute without authentication under certain conditions. Confirmed vulnerable distributions include Ubuntu Desktop 18.04/24.04.4/26.04, Ubuntu Server 22.04-24.04, Debian Trixie 13.4, RockyLinux Desktop 10.1, and Fedora 43 Desktop/Server. PackageKit version 1.3.5 addresses the issue. Exploitation leads to PackageKit daemon crash observable in system logs.
dpkg -l | grep -i packagekit or rpm -qa | grep -i packagekit. Verify daemon status with systemctl status packagekit or pkmon. Any Linux distribution with PackageKit pre-installed and enabled out-of-the-box should be considered vulnerable.UNC3944 Leader and DigitalMint Ransomware Negotiator Plead Guilty
Tyler Robert Buchanan (24, British national, UNC3944/0ktapus/Scattered Spider leader) pleaded guilty to wire fraud and aggravated identity theft for stealing at least $8 million in cryptocurrency through SMS phishing attacks from 2021-2023. Arrested in Spain 2024, extradited to U.S., faces up to 22 years in prison at August sentencing. UNC3944 linked to major breaches at MGM Resorts, Twilio, and Caesars Entertainment. Angelo Martino (former DigitalMint ransomware negotiator) pleaded guilty to helping BlackCat ransomware gang extort U.S. companies by sharing clients' confidential negotiation strategies and insurance policy limits. Martino also launched ransomware attacks with accomplices targeting law firms, school districts, medical facilities, and financial firms in 2023. One victim paid over $25 million. Authorities seized $10 million in Martino's assets. Faces up to 20 years in prison at July sentencing.
The npm Threat Landscape: Shai-Hulud Worm Marks New Era of Supply Chain Attacks
Unit 42 reports that the Shai-Hulud worm (September 2025) marked the end of the "nuisance" era of npm attacks and the beginning of high-consequence supply chain threats. The self-replicating malware automated compromise and redistribution of malicious packages. Since then, attacks evolved with wormable propagation (stealing npm tokens and GitHub PATs to automatically infect legitimate packages), infrastructure-level persistence (embedding into CI/CD pipelines), and multi-stage payloads (dormant dependencies activating under specific conditions). Recent campaigns include Shai-Hulud 2.0 (TeamPCP, April 2026) impersonating @bitwarden/cli, deploying across Docker Hub, GitHub Actions, and VS Code extensions, and the March 2026 Axios compromise. Attacks now prioritize long-term undetectable access to enterprise environments.
26 FakeWallet Apps Found on Apple App Store Targeting Crypto Seed Phrases
Kaspersky discovered 26 malicious apps on Apple App Store impersonating popular cryptocurrency wallets (Bitpie, Coinbase, imToken, Ledger, MetaMask, TokenPocket, Trust Wallet) to steal recovery phrases and private keys since fall 2025. Apps redirect users to browser pages resembling the App Store and distribute trojanized versions of legitimate wallets. Apps have intentional typos in names (e.g., LeddgerNew) or use placeholder icons claiming official apps are "unavailable in the App Store" due to regulatory reasons. Malware captures seed phrases via code hooks or phishing pages instructing victims to enter mnemonics for verification. Some apps leverage enterprise provisioning profiles to install wallet apps. Campaign linked to native Chinese speakers specifically targeting cryptocurrency assets, with similarities to SparkKitty trojan campaign.
Researchers Uncover Pre-Stuxnet 'fast16' Malware Targeting Engineering Software
SentinelOne discovered fast16, a Lua-based malware created in 2005 that predates Stuxnet by at least five years. The malware targets high-precision calculation software to tamper with results, aiming to produce inaccurate calculations across an entire facility. Fast16 is the first known Windows malware to embed a Lua engine. The implant includes a kernel driver (fast16.sys, created July 2005) that intercepts and modifies executable code as it's read from disk. The "fast16" string was found in a "drv_list.txt" file leaked by The Shadow Brokers in 2016-2017 as part of data allegedly stolen from the Equation Group (suspected NSA ties). The carrier module (svcmgmt.exe) can alter behavior based on command-line arguments and includes propagation logic scanning for network servers to spread to Windows 2000/XP environments with weak credentials.
Microsoft Security Update Guide CVEs (Low Priority)
Microsoft published multiple low-severity CVEs with minimal detail: CVE-2025-13763 (Libopensc uninitialized variable, EPSS 5th percentile), CVE-2026-23428 (ksmbd use-after-free, EPSS 2nd percentile), CVE-2026-41080 (no description, EPSS 9th percentile), CVE-2026-23438 (net: mvpp2 flow control, EPSS 2nd percentile), CVE-2026-23439 (udp_tunnel NULL deref, EPSS 2nd percentile), CVE-2026-23446 (net: usb: aqc111, EPSS 2nd percentile), CVE-2026-23447 (net: usb: cdc_ncm, EPSS 2nd percentile), CVE-2026-23434 (mtd: rawnand, EPSS 2nd percentile), CVE-2026-41205 (Mako path traversal, EPSS 14th percentile). All have extremely low EPSS scores indicating minimal active exploitation risk.
Persistence mechanisms are evolving beyond traditional patch-and-forget security models. Firestarter demonstrates that sophisticated attackers now build malware resilient to firmware updates and security patches, requiring hard resets and reimaging. The convergence of vishing (BlackFile, ADT/ShinyHunters, UNC6692) with SSO exploitation shows credential theft has shifted from phishing emails to phone calls and Microsoft Teams messages, bypassing technical controls through human manipulation. Supply chain attacks have industrialized with wormable propagation (Shai-Hulud, npm ecosystem) that automates compromise at scale, turning trusted package registries into force multipliers for malware distribution.