← Carolina Clear Tech

Cyber Threat Brief

2026-04-27

Listen to this brief (11:48)

Download MP3
Show Notes

Show Notes - 2026-04-27

Stories Covered

CVEs Referenced

CVE-2018-0734, CVE-2026-6770

Read the full brief

Get tomorrow's brief in your inbox

Protect Your Business

Need a security assessment? See our cybersecurity packages.

View Services

Daily IT Security Brief - April 27, 2026

Today: Firefox and Tor Browser patched a tracking vulnerability that defeats anonymity features. US government launched a major crackdown on Southeast Asian cyberscam operations with sanctions against a Cambodian senator and charges against Chinese nationals. Utility firm Itron disclosed a breach of internal systems. IRSF scammers are using fake CAPTCHA pages to drain $30 per victim through international SMS charges.

Critical Alerts

Firefox Vulnerability Allows Tor User Fingerprinting (CVE-2026-6770)

A vulnerability in Firefox's IndexedDB API allows threat actors to fingerprint users across different sessions and websites, including in Private Browsing mode and Tor Browser's "New Identity" feature. The bug returns IndexedDB database names in a consistent order that remains stable across different sites within the same browser process, creating a universal identifier for tracking. This defeats Tor Browser's session isolation, which is designed to prevent linking activity across different sites. The fingerprint persists across reloads and new private sessions until the browser is fully restarted. FingerprintJS discovered the issue, which stems from how IndexedDB exposes its internal storage ordering.

Business & Infrastructure Threats

American Utility Firm Itron Discloses Breach of Internal IT Network

Utility technology company Itron disclosed that an unauthorized third party accessed some of its internal systems on April 13. The company activated its cybersecurity response plan, notified law enforcement, and engaged external advisors. The unauthorized activity has been blocked with no follow-up activity observed. Itron provides utility technology for energy and water resource management, serving 7,700 customers in 100 countries with 112 million endpoints. The company reported 2025 revenue of $2.4 billion and employs roughly 5,600 people. Business operations recorded no material disruption, and the company expects insurance to cover a significant portion of incident-related costs. The unauthorized activity did not extend to customers, though the investigation is ongoing. No ransomware group has claimed the attack.

Fake CAPTCHA IRSF Scam and 120 Keitaro Campaigns Drive Global SMS, Crypto Fraud

A telecommunications fraud campaign uses fake CAPTCHA verification tricks to dupe users into sending international text messages that incur charges on their mobile bills. The operation has been active since at least June 2020. As many as 35 phone numbers spanning 17 countries have been observed as part of the international revenue share fraud (IRSF) campaign. The fake CAPTCHA has multiple steps, with each message preconfigured with over a dozen phone numbers. Victims are charged for sending SMS to over 50 international destinations, with costs potentially reaching $30 after four verification steps. The threat is notable for combining revenue share fraud with malicious traffic distribution systems (TDSs) traditionally used for routing traffic to malware or phishing pages. Fraudsters register phone numbers in countries with high termination fees or lax regulations, such as Azerbaijan, Kazakhstan, and certain premium-rate number ranges in Europe. The campaign uses back button hijacking and cookies to track progression through the fake verification flow.

US Launches Sweeping Crackdown on Southeast Asia Cyberscams and Sanctions Cambodian Senator

US officials announced a sweeping crackdown on Southeast Asian cyberscam operations led by a Scam Center Strike Force. The Treasury Department sanctioned Cambodian Senator Kok An and 28 other people and companies accused of operating from Cambodia. Criminal charges were filed against two Chinese nationals, Huang Xing Shan and Jiang Wen Jie, involved in a similar operation in Myanmar. The initiative includes a warrant to seize and shut down a major online recruitment channel on Telegram and freezing hundreds of millions of dollars in illicit assets. Americans lost nearly $21 billion to cyber-enabled crimes and online scams in 2025 alone. The illicit industry is closely involved in human trafficking, with foreign nationals employed to run romance and cryptocurrency scams after being recruited with false offers of legitimate jobs. FBI agents accessed evidence from an abandoned scam center in Myanmar in November, including over 8,000 phones and 1,500 computers.

Windows / AD Security

CVE-2018-0734 Timing Attack Against DSA

Microsoft Security Response Center published information about CVE-2018-0734, a timing attack against DSA. The advisory provides minimal detail beyond "Information published." This CVE has an EPSS score of 0.061 (91st percentile), indicating elevated exploit probability compared to most vulnerabilities. The lack of detail in the update suggests this may be an information disclosure or reference update rather than a new patch.

Go Straight to Sell! Windows Second-Chance Setup Hawks Microsoft Services at IT's Expense

Windows 11's Second Chance Out of Box Experience (SCOOBE) launches months or years after initial setup, often after a Windows update, pushing users through setup screens that advertise Microsoft services like Xbox Game Pass Premium ($14.99/month) and Office 365. The experience can appear multiple times in a PC's lifecycle. The pattern leads to support calls from less-tech-savvy employees who think something is wrong with their computers, costing organizations more than just lost productivity. IT professionals report numerous stories about support tickets and lost time due to SCOOBE. The experience presents screens that encourage linking phones, using recommended browser settings, and subscribing to Microsoft services, with "Skip" links less prominent than "Next" or purchase buttons.

General Security News

Anthropic's Magic Code-Sniffer: More Swiss Cheese Than Cheddar, for Now

Anthropic's Mythos AI code security model is proving to be effective at finding classes of vulnerability that humans already know about, while not finding ones they don't. Mythos found 271 Firefox flaws, but none a human couldn't spot. The tool can automate a lot of the things expert humans do, and it's the expert humans who get the most from it. Project Glasswing, limiting early use to trusted partners with a real need, is a responsible approach to using its powers. Early results suggest Mythos is less capable than the hype made it out to be. The effectiveness of tools like Mythos will continue to evolve, exposing more structural and individual code flaws. These tools will inevitably become generally available, creating a transition period where most running code has been written in the pre-industrial age of vulnerability detection.

Watch Out UK Taxpayers: 28,000 HMRC Staffers Just Got an AI Copilot

HMRC rolled out about 28,000 Microsoft Copilot licenses and is preparing to switch on agentic-style features. A June 2025 Government Digital Service trial across 20,000 civil servants reported an average time saving of 26 minutes a day, with over 70 percent saying it cut time spent searching for information. The report points to "limitations when dealing with complex, nuanced, or data-heavy aspects of work" and raises concerns about "security and the handling of sensitive data." HMRC is pushing Copilot into "Official Sensitive" workflows. Stale and duplicated gov.uk content has already tripped up AI systems, feeding them outdated or conflicting information. The system works well enough to rely on, not quite well enough to trust, and far too embedded to switch off when it inevitably gets something important wrong.

ICO Chief John Edwards Steps Back as Workplace Probe Quietly Unfolds

UK's Information Commissioner John Edwards stepped aside from his duties on February 26 to enable an independent workplace investigation which relates to him. The ICO confirmed Edwards formally stepped back to allow the investigation, which will produce a report with recommendations for the Department for Science, Innovation and Technology (DSIT). Edwards took up the post in 2022 after serving as New Zealand's privacy commissioner. The ICO board, chief executive Paul Arnold, and executive team are overseeing day-to-day operations under existing delegation arrangements, with the ICO stressing that its regulatory work continues uninterrupted.

Patch Priority

Trends & Context

Today's stories highlight the tension between AI-driven automation and traditional security expertise. Anthropic's Mythos proves effective at finding known vulnerability classes but struggles with novel exploits, while HMRC's massive Copilot deployment raises questions about deploying AI systems that work "well enough to rely on, not quite well enough to trust" into sensitive government operations. The Firefox tracking bug demonstrates that privacy features require constant vigilance, as implementation details like IndexedDB ordering can undermine anonymity guarantees. The US crackdown on Southeast Asian cyberscam operations represents a significant escalation in cross-border cybercrime enforcement, targeting both the infrastructure (Telegram recruitment channels) and the financial incentives (asset seizures) that enable these operations.