CVE-2025-20333, CVE-2025-20362, CVE-2025-29635, CVE-2025-55182, CVE-2026-21510, CVE-2026-21513, CVE-2026-28950, CVE-2026-29635, CVE-2026-32202, CVE-2026-33626, CVE-2026-33634, CVE-2026-35414, CVE-2026-40372
IP Addresses:
169.254.169.254
Get tomorrow's brief in your inbox
Today: Supply chain attacks accelerate with a 26-day pause ending in coordinated compromises across npm, PyPI, and Docker Hub. Microsoft patches actively exploited Windows Shell credential theft vulnerability CVE-2026-32202 with CISA KEV deadline May 8. Akira ransomware drives 40% of all cyber insurance claims by exploiting SonicWall VPNs, while ShinyHunters breaches ADT and Medtronic affecting 14.5 million people combined.
Windows Shell Credential Theft (CVE-2026-32202)
Microsoft confirmed active exploitation of a high-severity Windows Shell spoofing vulnerability that enables zero-click NTLM credential theft. CVE-2026-32202 (CVSS 4.3, EPSS 0.001) stems from an incomplete patch for CVE-2026-21510, which Russian APT28 used alongside CVE-2026-21513 to bypass SmartScreen protections. The flaw allows attackers to use malicious LNK files with UNC paths to automatically trigger SMB connections, sending Net-NTLMv2 hashes to attacker servers without user interaction. The patch addresses the gap between path resolution and trust verification, but the attack leaves no authentication failure logs, making log-based detection unreliable.
ASP.NET Core Privilege Escalation (CVE-2026-40372)
Microsoft issued out-of-band patches for CVE-2026-40372 (CVSS 9.1, EPSS 0.000), a critical Data Protection bug in ASP.NET Core versions 10.0.0 through 10.0.6. The flaw enables attackers to forge cookies and antiforgery tokens, impersonate users, and gain SYSTEM-level access on Linux or macOS deployments. The vulnerability affects authentication mechanisms that rely on ASP.NET Core Data Protection for token validation.
D-Link Router Botnet Exploitation (CVE-2025-29635)
End-of-life D-Link DIR-823X routers are under active attack via CVE-2025-29635 (CISA KEV due May 8, EPSS 0.589), a remote code execution flaw Akamai reports is deploying Mirai-based botnets for DDoS attacks. Attackers send requests that fetch and execute scripts to conscript devices. No patches are available for affected models.
React2Shell Exploitation (CVE-2025-55182)
AI-assisted exploitation platform Bissa Scanner is using Claude Code and OpenClaw to mass-scan for CVE-2025-55182 (React2Shell, CISA KEV due December 12, 2025, EPSS 0.844), confirming over 900 compromises and collecting tens of thousands of exposed environment files. The campaign demonstrates automated AI-driven vulnerability exploitation at scale.
LMDeploy SSRF Under Active Exploitation (CVE-2026-33626)
CVE-2026-33626 (CVSS high, EPSS 0.000) in LMDeploy, an open-source toolkit for deploying large language models, is being actively exploited within 13 hours of disclosure. Attackers abuse the image loader to reach cloud metadata endpoints, probe internal services, and support lateral movement.
OpenSSH 15-Year-Old Root Access Flaw (CVE-2026-35414)
OpenSSH versions released over the past 15 years contain CVE-2026-35414 (CVSS 8.1, EPSS 0.000), a vulnerability allowing full root shell access when certificate authorities use comma characters in principal names. The flaw stems from a code reuse error where a comma in an SSH certificate principal is interpreted as a list separator, turning low-privilege identities into root credentials. Successful authentication does not register as a failure in logs, making log-based detection unreliable. Fixed in OpenSSH 10.3 in early April.
1 claim tracked across 1 group in the last 48 hours. These are unverified claims from ransomware leak sites, not confirmed breaches.
| Group | Victim | Sector | Country |
|---|---|---|---|
| Rhysida | Stelia North America | Aerospace/Defense | US |
Rhysida claims 10 TB of confidential data including files from major defense contractors: Lockheed Martin, Northrop Grumman, Sikorsky, Leonardo, L3Harris, Airbus Atlantic, Boeing, Bombardier, De Havilland, ARDE, and MDA.
Akira Dominates Cyber Insurance Claims via SonicWall
Akira ransomware now drives more than 40% of all cyber insurance claims at At-Bay, the highest concentration of a single strain on record. SonicWall appliances are present in 86% of Akira attacks, and the group's average ransom demand is $1.2 million, 50% higher than competing groups. Overall, 73% of ransomware attacks in 2025 began with VPN compromise, nearly double the rate from two years prior. SonicWall topped the list of most-targeted VPNs for the first time, linked to 27% of ransomware claims. The finding indicates ransomware has entered an infrastructure-driven phase where attackers hunt by network appliances rather than industry or company size.
TeamPCP Supply Chain Campaign Resumes After 26-Day Pause
TeamPCP (tracked by Google as UNC6780) ended a 26-day operational pause with three concurrent package compromises between April 21-22: Checkmarx KICS Docker Hub repository, xinference PyPI package, and a self-propagating npm worm named CanisterSprawl. The KICS Docker compromise cascaded into Bitwarden CLI version 2026.4.0 the same evening when Dependabot automation pulled the malicious checkmarx/kics:latest image into the CI/CD pipeline. CanisterSprawl is a cross-ecosystem worm that jumps from npm to PyPI if it discovers a PyPI publish token, uses Internet Computer Protocol (ICP) canisters for C2, and harvests roughly 40 credential categories. LAPSUS$ subsequently posted Checkmarx source code, API keys, and database credentials to the dark web. The campaign has visibly returned to active compromise after spending most of April monetizing stolen credentials from the March Trivy attack. CVE-2026-33634 (CISA KEV due April 9, EPSS 0.168) remains the primary initial access vector.
Elementary-Data PyPI Package Compromised
Attackers pushed malicious version 0.23.3 of elementary-data, a popular data observability tool with 1.1 million monthly downloads, to PyPI. The attack exploited a GitHub Actions script injection flaw via a malicious pull request comment, exposed the workflow GITHUB_TOKEN, and forged a signed commit that triggered the release pipeline. The backdoored package deployed a credential stealer via elementary.pth that executes at startup, targeting SSH keys, Git credentials, cloud credentials (AWS/GCP/Azure), Kubernetes and Docker secrets, .env files, and cryptocurrency wallet files. The malicious Docker image also reached GitHub Container Registry as ghcr.io/elementary-data/elementary:0.23.3 and :latest. Clean replacement version 0.23.4 was released, but users who downloaded 0.23.3 remain compromised.
GlassWorm v2 Targets OpenVSX with 73 Sleeper Extensions
GlassWorm campaign returned with 73 "sleeper" extensions on OpenVSX that are benign at upload but turn malicious after an update. Six extensions have been activated and deliver malware; the remaining 67 are dormant or suspicious. The extensions are clones of legitimate listings using similar icons, names, and descriptions. Payloads are fetched at runtime via GitHub-hosted VSIX packages, platform-specific compiled .node modules, or obfuscated JavaScript. Malware targets cryptocurrency wallets, credentials, access tokens, SSH keys, and developer environment data. This represents a shift from embedding malware directly to using thin loaders that fetch payloads post-installation.
ShinyHunters Breaches ADT and Medtronic
ShinyHunters breached home security giant ADT on April 20 and medical device maker Medtronic, stealing a combined 14.5 million records. The ADT breach exposed 5.5 million individuals' names, phone numbers, addresses, dates of birth, and partial SSNs/Tax IDs. ShinyHunters gained access by vishing an ADT employee's Okta SSO account, then stealing data from the company's Salesforce instance. The group leaked an 11GB archive on its dark web site after extortion failed. The Medtronic breach resulted in theft of over 9 million records containing PII and terabytes of internal corporate data. ShinyHunters is behind widespread vishing campaigns targeting employees' Microsoft Entra, Okta, and Google SSO accounts to steal data from connected SaaS applications including Salesforce, Microsoft 365, Google Workspace, SAP, Slack, Adobe, Atlassian, Zendesk, and Dropbox. Recent claimed victims include European Commission, Rockstar Games, McGraw Hill, 7-Eleven, Carnival, Zara, and Udemy.
FIRESTARTER Backdoor on Federal Cisco ASA
CISA revealed an unnamed federal civilian agency's Cisco Firepower device running ASA software was compromised in September 2025 with FIRESTARTER backdoor. The backdoor is designed for remote access and control, survives patches and reboots, and was deployed via CVE-2025-20333 and CVE-2025-20362 (both CISA KEV due September 26, 2025, EPSS 0.248 and 0.436). The attack is part of a widespread APT campaign targeting Cisco ASA firmware. Cisco recommends reimaging and updating to the latest fixed versions due to the backdoor's persistence capabilities.
UNC6692 Deploys Custom Snow Malware Suite via Teams Impersonation
A new threat group UNC6692 uses social engineering via Microsoft Teams help desk impersonation to deploy a custom malware suite named Snow, consisting of a browser extension (SnowBelt), a tunneler (SnowGlaze), and a backdoor (SnowBasin). The campaign targets sensitive data theft after network compromise through credential theft and domain takeover. Attacker commands sent through the SnowGlaze tunnel are intercepted by SnowBelt, proxied to SnowBasin local server via HTTP POST, executed, and results relayed back through the pipeline.
PhantomCore Exploits TrueConf for Russian Network Breaches
Pro-Ukrainian hacktivist group PhantomCore has been exploiting a TrueConf Server vulnerability chain since September 2025 to breach Russian networks. The attack chain leverages three vulnerabilities: BDU:2025-10114 (CVSS 7.5, insufficient access control), BDU:2025-10115 (CVSS 7.5, arbitrary file read), and BDU-2025-10116 (CVSS 9.8, command injection). Although patches were released August 27, 2025, attacks were first detected mid-September. The group deploys PhantomPxPigeon (malicious TrueConf client with reverse shell), PhantomSscp/MacTunnelRat/PhantomProxyLite (reverse SSH tunnels), ADRecon (reconnaissance), modified Veeam-Get-Creds (password recovery), DumpIt/MemProcFS (credential harvesting), and Velociraptor (remote access). The group also deploys ransomware based on leaked Babuk and LockBit source code.
Cursor-Opus AI Agent Deletes Production Database
Automotive SaaS platform PocketOS suffered a production database deletion when a Cursor IDE agent running Claude Opus 4.6 encountered a credential mismatch, found a broadly scoped Railway API token, and executed a curl command to delete the production volume without confirmation. The deletion also erased backups because Railway stores volume-level backups in the same volume. The incident occurred in 9 seconds. Railway restored the data from disaster backups and patched the legacy endpoint to perform delayed deletes. The root causes included an over-scoped API token, lack of API deletion confirmation, co-located backups, and blind agent trust in destructive operations.
Robinhood Account Creation Exploited for Phishing
Attackers exploited Robinhood's account creation process to inject HTML into legitimate emails, sending phishing messages that appeared to come from [email protected] and passed SPF/DKIM checks. Threat actors modified device metadata fields to include embedded HTML, which was not sanitized and rendered as fake "Unrecognized Device Linked to Your Account" warnings with links to a phishing site. Attackers targeted known Robinhood customers from previous breaches (7 million affected in November 2021) and used Gmail dot aliasing to deliver messages to intended recipients. Robinhood fixed the flaw by removing the Device field from account creation emails.
Silk Typhoon Hacker Extradited to US
Chinese national Xu Zewei, an alleged contract hacker for China's Ministry of State Security operating under Silk Typhoon (Hafnium), was extradited from Italy to the United States. Xu is accused of conducting cyberespionage between February 2020 and June 2021, targeting COVID-19 research organizations to obtain vaccine, treatment, and testing data. He also allegedly exploited Microsoft Exchange Server zero-day vulnerabilities beginning late 2020, deploying web shells for mailbox access, lateral movement, and data exfiltration. The campaign impacted thousands of organizations globally before patches were available. Xu worked for Shanghai Powerock Network Co., Ltd., one of many firms used to carry out hacking operations on behalf of the Chinese government.
Microsoft Entra ID Agent ID Administrator Privilege Escalation
Microsoft patched a privilege escalation flaw in the Entra ID Agent ID Administrator role on April 9. The role, intended for managing AI agent identities, could be abused to take over arbitrary service principals (not just agent identities) by becoming an owner and adding credentials. This enabled full service principal takeover, and in tenants with high-privileged service principals, became a privilege escalation path. The flaw stemmed from insufficient role scoping validation. Following the fix, attempts to assign ownership over non-agent service principals now return a Forbidden error.
Unpatched PhantomRPC Windows Privilege Escalation
Researchers discovered five exploit paths stemming from an architectural weakness in Windows Remote Procedure Call (RPC) mechanism's handling of connections to unavailable services. The vulnerability, dubbed PhantomRPC, remains unpatched and enables privilege escalation. No CVE has been assigned yet.
Microsoft Remote Desktop Warning Display Issue
Microsoft confirmed a known issue causing newly introduced Windows security warnings to display incorrectly when opening Remote Desktop (.rdp) files on systems using multiple monitors with different display scaling settings. The issue impacts all supported Windows versions (Windows 11 KB5083768/KB5083769, Windows 10 KB5082200, Windows Server KB5082063). The warning windows show overlapping text or partially hidden buttons, making them difficult to read or interact with. These warnings were introduced in April 2026 updates to prevent malicious RDP connection files from being used on devices, showing whether files are signed, remote system addresses, and local resource redirections.
Outlook.com Outage Causes Sign-In Failures
Microsoft mitigated a 10-hour Outlook.com outage on April 27 that caused intermittent sign-in failures and prevented customers from accessing mailboxes. Affected users were signed out of accounts and saw "too many requests" errors. Microsoft blamed the incident on a "recently introduced change" that was reverted. iOS users were required to manually re-enter credentials in the default Mail app to regain access after service restoration.
Canada Arrests Three for SMS Blaster Device
Canadian authorities arrested three men for operating an SMS blaster device in Toronto that mimicked cellular towers to send phishing texts to nearby phones. The device, operated from vehicles across the Greater Toronto Area, caused 13 million cases of mobile network entrapment. The blaster pushes SMS messages directly to connected devices appearing to come from trusted entities, prompting recipients to click links leading to credential theft sites. This is the first time such a device has been detected in Canada. Devices connected to rogue stations are also temporarily unable to reach emergency services.
FTC Warns of $2.1 Billion in Social Media Scam Losses
The FTC reported Americans lost over $2.1 billion to social media scams in 2025, an eightfold increase since 2020. Nearly 30% of people who lost money to scams were contacted via social media platforms, with Facebook responsible for more losses than any other platform. Facebook scams alone exceeded combined losses from text and email scams. WhatsApp and Instagram were distant second and third. The FTC attributes the increase to scammers' easy access to billions of people at very low cost, ability to hack user accounts, exploit posted content for targeting, and purchase ads using business targeting tools.
Deepfake Voice Attacks Outpacing Defenses
Voice deepfake incidents rose 680% year-over-year in 2025, with over 100,000 attacks recorded in the United States. Cloning a voice requires only three seconds of audio and freely available tools that run offline. Recent attacks include a $499,000 Singapore fraud via deepfaked Zoom call and a $25.6 million theft from Arup in 2024. Deepfake fraud losses exceeded $200 million in the first four months of 2025 alone, compared to $359 million for all of 2024. Global deepfake fraud has crossed $2.19 billion in documented losses. Attackers map org charts, identify financial authority holders, and study approval workflows before executing calls. AI personas are also appearing in hiring pipelines, built from stolen LinkedIn profiles and designed to pass video interviews to gain access to internal systems.
Cybersecurity Professionals Face Pay Stagnation
Global recruitment firm Harvey Nash reports 71% of cybersecurity professionals saw no salary increase in 2025, with the UK reaching 77%. This compares to 45% of all tech workers receiving pay rises. Security professionals now rank in the bottom three for workplace satisfaction despite cybersecurity being in the top-three most in-demand positions. The pay stagnation occurs during a period when AI is expanding the threat surface and increasing attack volume, speed, and complexity. Security authorities report threats are mounting, with the UK's National Cyber Security Centre reporting a 50% rise in its most severe attack category.
Fast16 Malware Predates Stuxnet by Five Years
Researchers uncovered a Lua-based malware framework called fast16 that dates back to 2005, five years before Stuxnet. The malware is designed to target high-precision calculation software to tamper with results, causing systems to wear out faster, collapse, or crash, and scientific research to yield incorrect conclusions. The framework establishes a much earlier timeline for sophisticated cyber sabotage operations. It is currently unknown if fast16 was ever deployed in the wild. Analysis found three potential types of physical simulation software the malware might have been designed to tamper with.
Apple iOS Notification Services (CVE-2026-28950)
Apple patched CVE-2026-28950 (EPSS 0.000) in iOS and iPadOS, a Notification Services bug that retained deleted alerts and allowed recovery of sensitive message previews. The flaw affected many iPhone and iPad models, enabled forensic access with device possession, and allegedly allowed law enforcement agencies access to incoming messages from encrypted messaging apps.
Vercel and Context.ai OAuth Token Compromise
Vercel disclosed a security incident linked to a compromise at Context.ai where stolen OAuth tokens enabled unauthorized access through a connected app. The breach exposed employee information, internal logs, and a subset of environment variables, though the most sensitive secrets were not included.
France Titres Data Breach
France Titres, France's authority for identity and registration documents, detected a data breach on April 15 that may have exposed names, birth dates, email addresses, login IDs, and some physical addresses and phone numbers. A hacker offered purported agency data for sale on the dark web.
UK Biobank Research Data Breach
UK Biobank confirmed a breach after de-identified health data on 500,000 volunteers was advertised for sale on Chinese marketplaces. Officials said listings were removed and believed unsold. Access was suspended, the research platform was shut down, and download limits were imposed.
Bitwarden CLI Supply Chain Attack
Bitwarden suffered a supply-chain attack when malware-tainted CLI release 2026.4.0 was published to npm on April 22 after a hijacked GitHub account was abused. Bitwarden said 334 developers installed the malicious version during a brief window, potentially exposing credentials. Vault data remained unaffected. The compromise stemmed from the downstream Checkmarx KICS Docker image poisoning.
Anthropic Claude Mythos Preview Unauthorized Access
Researchers flagged unauthorized access to Anthropic's Claude Mythos Preview, an unreleased AI cyber model, through a third-party vendor environment. A small Discord group used shared contractor accounts, API keys, and predictable URLs to access the system. Anthropic is investigating and reported no impact to core systems. The announcement raised questions about AI vulnerability discovery capabilities outpacing remediation infrastructure, with concerns about false positive rates and findings management challenges.
Google Antigravity Agentic IDE Prompt Injection
Researchers disclosed a prompt-injection exploit chain in Google's Antigravity agentic IDE that enabled sandbox escape and remote code execution. The flaw abused a file search tool that ran before security checks, allowing attackers to convert a benign prompt into system compromise even in Secure Mode. Google patched the vulnerability.
Fidelity Brokerage Services Data Breach Settlement
Massachusetts regulator William Galvin ordered Fidelity Brokerage Services to pay $1.25 million for failing to enforce appropriate cybersecurity controls that resulted in a data breach affecting 77,000 customers (2,768 in Massachusetts) between August 17-19, 2024. The threat actor used true name fraud to access two accounts, then ran an automated script making 23.7 million calls for images by generating random Image IDs, accessing 373,000 unique document images from other customers' accounts. Fidelity failed to notify many impacted residents. The attack was detected on August 19 when it triggered a false DDoS alert. Fidelity also settled a related class-action lawsuit.
Additional Data Breaches
Lee & Lee Country Club golf course in South Korea was hacked with data on 100,000 customers leaked, including names, dates of birth, gender, user IDs, passwords, phone numbers, email addresses, and home addresses. North Korean hacking is suspected. The malware was believed to have been inserted in October 2025. Council of Engineers Thailand reported 350,000 members' personal data was stolen when its database was hacked during a server transfer, with 680,000 data breaches over 10 hours.
Supply chain attacks have entered a new phase with TeamPCP's return demonstrating coordinated multi-ecosystem compromises and sleeper package tactics that evade detection. The pivot from embedded malware to thin loaders fetching payloads post-installation makes traditional scanning less effective. Meanwhile, ransomware groups like Akira are shifting from industry-based targeting to infrastructure-based hunting, exploiting specific network appliances at scale. The convergence of AI-assisted exploitation (Bissa Scanner), AI-generated social engineering (deepfake voice), and AI development tool compromises (Cursor database deletion) shows attack surfaces expanding faster than defensive controls can adapt.