CVE-2022-0847, CVE-2024-41045, CVE-2024-41067, CVE-2024-41932, CVE-2024-57974, CVE-2024-57976, CVE-2025-48431, CVE-2026-21510, CVE-2026-21513, CVE-2026-31431, CVE-2026-31499, CVE-2026-31508, CVE-2026-31540, CVE-2026-31545, CVE-2026-31546, CVE-2026-32202, CVE-2026-3298, CVE-2026-34477, CVE-2026-3854, CVE-2026-41305, CVE-2026-41602, CVE-2026-41603, CVE-2026-41604, CVE-2026-41607, CVE-2026-41636, CVE-2026-6238, CVE-2026-6357
Get tomorrow's brief in your inbox
Today: Microsoft's February patch for a Russian zero-day fell short, leaving CVE-2026-32202 exploited in the wild with a May 12 federal deadline. GitHub patched a critical RCE flaw giving attackers access to millions of private repos, but 88% of enterprise servers remain unpatched. Linux distributions scramble to fix Copy Fail, a privilege escalation bug in every kernel since 2017, while TeamPCP's latest supply chain attack hits SAP packages and injects persistence hooks into Claude Code and VS Code.
Microsoft Windows CVE-2026-32202: Incomplete Patch Creates Zero-Click Credential Theft Flaw
Microsoft's February patch for CVE-2026-21510, a zero-day exploited by Russia's APT28 against Ukraine, failed to fully close the vulnerability. The incomplete fix left CVE-2026-32202, a zero-click authentication coercion flaw in Windows Shell that leaks Net-NTLMv2 hashes to attackers. Microsoft marked it as exploited on April 14, and CISA added it to the KEV catalog on April 29 with a May 12 deadline for federal agencies. The flaw (EPSS 7.2%, 92nd percentile) allows remote attackers to steal NTLM hashes by sending a malicious LNK file, enabling pass-the-hash attacks for lateral movement and data theft. Akamai researcher Maor Dahan discovered the flaw while testing Microsoft's February patches and found that victim machines still authenticated to attacker servers despite the RCE fix. APT28 originally exploited CVE-2026-21510 in January by chaining it with CVE-2026-21513 to bypass Defender SmartScreen and remotely execute code.
GitHub CVE-2026-3854: Critical RCE Allowed Access to Millions of Private Repos
GitHub patched a critical remote code execution flaw (CVE-2026-3854) on March 4 that allowed attackers with push access to execute arbitrary code on GitHub.com servers and GitHub Enterprise instances, potentially exposing millions of private repositories. Wiz researchers found the vulnerability affects shared storage nodes on GitHub.com and grants full server compromise on GitHub Enterprise Server. The flaw stems from insufficient sanitization of user-supplied options during git push operations, allowing attackers to inject additional fields that bypass sandboxing and execute code. GitHub deployed a fix to GitHub.com within 6 hours and found no evidence of exploitation before disclosure. However, 88% of reachable GitHub Enterprise Server instances remain vulnerable. Patches are available for all supported GHES releases (3.14.25, 3.15.20, 3.16.16, 3.17.13, 3.18.8, 3.19.4, 3.20.0 or later).
Linux CVE-2026-31431 (Copy Fail): Root Privilege Escalation in All Distributions Since 2017
A high-severity Linux kernel vulnerability (CVSS 7.8) allows unprivileged local users to gain root access on essentially all Linux distributions shipped since August 2017, including Amazon Linux, RHEL, SUSE, and Ubuntu. The flaw stems from a logic error in the algif_aead cryptographic module that allows writing four controlled bytes into the page cache of any readable file. A 732-byte Python exploit can edit a setuid binary to obtain root, and the vulnerability has cross-container impact since the page cache is shared across all processes. The exploit is portable across distributions, requires no race conditions or kernel offsets, is tiny and stealthy, and works reliably. Major distributions have released patches.
3 claims tracked across 2 groups in the last 48 hours. These are unverified claims from ransomware leak sites, not confirmed breaches.
| Group | Victim | Sector | Country |
|---|---|---|---|
| Aurora | Costa Solutions, LLC | Warehousing & Logistics | United States |
| Aurora | Bayou Title, Inc. | Title Insurance & Real Estate | United States |
| Aurora | Advanta Genetics LLC | Clinical Laboratory Services | United States |
| Radar | Bentley Capital Ventures | Financial Services | United States |
Aurora posted 3 claims on April 29, including detailed exfiltration inventories. Costa Solutions breach includes SSNs for 3,000-8,000+ individuals from W-2s, I-9s, background checks, 150+ medical injury files, CEO financial documents, client contracts (HEB, CVS, Sysco, Amazon), and infrastructure secrets. Bayou Title breach spans 20+ years (2004-2026) with 70,000-100,000+ SSNs from real estate closing documents, complete Sage 50 payroll databases, 103 GB of title abstracts, and plaintext credentials for government portals. Radar posted Bentley Capital Ventures on April 29.
Vect 2.0 Ransomware Functions as Wiper Due to Design Flaw
Vect 2.0 ransomware, deployed in TeamPCP supply chain attacks, acts as a wiper rather than ransomware due to a critical design flaw. Check Point researchers discovered that Vect 2.0 discards three of four decryption nonces for every file above 128 KB, making 75% of large files permanently unrecoverable, even with the decryption key. The flaw exists across Windows, Linux, and VMware ESXi variants. Vect's ChaCha20-IETF encryption generates four random nonces per large file but only appends the final nonce to disk, discarding the first three. Since ChaCha20-IETF requires both the 32-byte key and exact 12-byte nonce to decrypt, the first three quarters of every large file are unrecoverable by anyone, including the ransomware operators. Vect targets manufacturing, education, healthcare, and technology sectors. A Japanese survey found that 222 companies paid ransomware attackers, yet 60% failed to recover their data.
Sandhills Medical Foundation Breach Affects 170,000
South Carolina healthcare provider Sandhills Medical Foundation disclosed a ransomware breach affecting nearly 170,000 individuals. The organization discovered the attack on May 8, 2025, and disclosed it publicly nearly one year later on April 29, 2026. Compromised data includes names, dates of birth, SSNs, taxpayer IDs, driver's licenses, government IDs, passports, financial information, and personal health information. Inc Ransom ransomware group listed Sandhills Medical on its leak site in early June 2025 and has since made stolen files available for download.
Pine Bluff School District Loses $3.2 Million in Business Email Compromise
Arkansas' Pine Bluff School District lost more than $3.2 million in a business email compromise attack on December 17, 2025. Superintendent Dr. Jennifer Barbaree confirmed the wire transfer during a board meeting on April 28, 2026.
TeamPCP Supply Chain Attack Targets SAP npm Packages with Credential Stealer
TeamPCP launched a supply chain attack on April 29 targeting SAP-related npm packages with credential-stealing malware. The campaign, dubbed "mini Shai-Hulud," compromised [email protected], @cap-js/[email protected], @cap-js/[email protected], and @cap-js/[email protected]. The malicious versions added a preinstall script that downloads platform-specific Bun runtime, extracts it, and executes credential-stealing payload. The malware harvests GitHub and npm tokens, GitHub Actions secrets, and cloud secrets from AWS, Azure, GCP, and Kubernetes. Stolen data is AES-256-GCM encrypted with RSA-4096 key encapsulation and exfiltrated to public GitHub repositories on the victim's own account with description "A Mini Shai-Hulud has Appeared." Over 1,100 repositories now have this description. The attack self-propagates through developer workflows by injecting malicious GitHub Actions workflows and publishes poisoned npm package versions. New features in this attack include encrypting all exfiltrated data (making it decipherable only to the attacker), exiting on Russian-locale systems, and abusing .claude/settings.json SessionStart hook and .vscode/tasks.json with runOn folderOpen to execute malware when repositories are opened in VS Code or Claude Code.
Checkmarx Data Stolen in TeamPCP Supply Chain Attack
Checkmarx confirmed that the March 23 supply chain attack targeting its KICS open source project resulted in data theft. The attack, attributed to TeamPCP, used credentials compromised via the Trivy hack to access Checkmarx's GitHub environment. Attackers poisoned two OpenVSX plugins and two GitHub Actions workflows on March 23, then retained or regained access and published fresh malicious code on April 22 (DockerHub KICS image, GitHub action, VS Code extension, Developer Assist extension). The second incident resulted in the compromise of Bitwarden CLI NPM package. Lapsus$ added Checkmarx to its leak site on April 27, claiming theft of source code, employee databases, API keys, and MongoDB/MySQL credentials. Checkmarx confirmed data exfiltration occurred on March 30, 2026, and published a 96 GB archive. The company retained Mandiant for investigation, performed broader credential reset, strengthened security controls, locked down GitHub repository access, and launched code audit.
Claude Mythos Finds 271 Zero-Days in Firefox
Anthropic's Claude Mythos Preview AI model identified 271 vulnerabilities in Firefox, all fixed in Firefox 150 released this week. This follows 22 security bugs found by Opus 4.6 and fixed in Firefox 148. Anthropic announced it will not release Mythos to the public due to exploitation risk, stating the model is capable of scanning for weaknesses faster and more persistently than hundreds of human hackers. The model discovered vulnerabilities that had existed in major operating systems and browsers for nearly three decades. Schneier notes that assuming defenders can patch and push updates quickly, this technology favors defenders.
GitHub Apologizes as Uptime Drops Below 85%
GitHub published an apology after availability dropped below 85% in April 2026, down from already-low 90% in 2025. The platform blamed agentic development workflows that accelerated sharply since December 2025. Recent incidents include a Merge Queue bug on April 23 that reverted previously merged changes, and an Elasticsearch cluster overload on April 27 (likely botnet attack) that broke search-dependent UI. HashiCorp co-founder Mitchell Hashimoto announced plans to move his Ghostty terminal emulator project off GitHub, stating "GitHub is no longer a place for serious work" and noting daily outages for the past month. GitHub planned 10x capacity increase in October 2025 but determined by February 2026 that 30x capacity is required. CTO Vlad Fedorov stated priorities are "availability first, then capacity, then new features."
AWS Engineers: AI Development Requires Human Review for Everything
AWS StoreGen director Steve Tarcza stated that despite AI coding advancements, nothing ships without human review. In contrast to AWS keynote claims of "magic" AI building infrastructure around the clock, Tarcza confirmed hallucinations, guardrail violations, and AI doing work beyond specifications remain unresolved. He emphasized spec-driven development "reduces hallucinations at best" but doesn't solve the problem. Tarcza stated AWS takes a strong stance that companies "can't get to the point where we don't have more junior engineers coming in. We have to continue to grow the talent." Engineers spend less than 30% of their time on core engineering, with AI removing friction in other areas rather than replacing engineering judgment.
CISA Releases Zero Trust Guidance for Operational Technology
CISA, in coordination with Department of War, Department of Energy, FBI, and State Department, released guidance for applying zero trust principles to operational technology environments. The guidance addresses IT-OT convergence risks and supports OT owners in transitioning to zero trust architecture while considering legacy infrastructure, operational constraints, and safety requirements. It focuses on comprehensive asset visibility, supply chain risk management, identity and access management, network segmentation, secure communication protocols, and vulnerability management.
AI Agent Identity Security Gap Emerging
Cyberscoop analysis highlights the identity security gap created by AI agents that can act autonomously while traditional security models assume a human is behind every action. Anthropic's decision not to release Mythos publicly underscores the risk that AI systems capable of helpful tasks can also exploit systems faster than human hackers. Legitimate agents need credentials to act on behalf of users (OpenAI Operator, Google Gemini, Visa Intelligence Commerce Connect), while adversaries can fake humanity at scale using the same capabilities. The economics favor attackers: one person can supervise an army of autonomous systems running valid personas across multiple interactions simultaneously. Most organizations treat identity as a login problem rather than addressing the question of who or what they've already let in.
Microsoft to Block TLS 1.0/1.1 on Exchange Online POP3/IMAP4 in July 2026
Microsoft will block legacy TLS 1.0 and 1.1 connections to Exchange Online for POP3 and IMAP4 clients starting July 2026. Support for TLS 1.0/1.1 in Exchange Online ended in 2020, and both protocols were deprecated in 2021. Microsoft added an opt-in endpoint in 2023 for clients that didn't support TLS 1.2 or later, but that option expires in July. Microsoft expects minimal impact, stating modern email clients already support TLS 1.2 or higher and the vast majority of POP/IMAP traffic uses newer protocols. Legacy devices or software that opted into the legacy endpoints may stop working when connections fail.
CVE-2026-32202: Windows Shell Authentication Coercion (Zero-Day)
Microsoft Windows Shell authentication coercion vulnerability (CISA KEV due May 12, EPSS 7.2%, 92nd percentile) allows remote attackers to expose sensitive information via network spoofing. The flaw is an incomplete patch for CVE-2026-21510, which APT28 exploited against Ukraine in January. Actively exploited, marked by Microsoft on April 14 and added to CISA KEV catalog on April 29. Allows zero-click Net-NTLMv2 hash theft via malicious LNK files.
CVE-2026-3854: GitHub Remote Code Execution (Critical)
GitHub.com and GitHub Enterprise Server remote code execution vulnerability (EPSS 0.4%, 58th percentile) allows attackers with push access to execute arbitrary code on servers via maliciously crafted git push command. Discovered by Wiz on March 4, patched on GitHub.com within 6 hours. No evidence of exploitation before disclosure, but 88% of GitHub Enterprise Server instances remain vulnerable. Patches available for all supported GHES releases.
CVE-2026-31431: Linux Copy Fail Privilege Escalation (High)
Linux kernel local privilege escalation (CVSS 7.8, EPSS 0.0%, 1st percentile) in algif_aead cryptographic subsystem allows unprivileged users to write controlled bytes into page cache of readable files to gain root. Introduced in August 2017 commit, affects all major distributions. 732-byte Python exploit is portable, reliable, and works across distributions. Patches released by major distributions.
Apache Thrift, Log4j, Python, and PostCSS Vulnerabilities
Microsoft Security Update Guide published advisories for multiple third-party vulnerabilities: CVE-2026-34477 (Apache Log4j Core hostname verification bypass), CVE-2026-41603 (Apache Thrift Java hostname verification), CVE-2026-41607 (Apache Thrift C++ JSON OOB read), CVE-2026-41636 (Apache Thrift Node.js recursion), CVE-2026-41602 (Apache Thrift Go overflow), CVE-2026-41604 (Apache Thrift Swift crash), CVE-2025-48431 (Apache Thrift c_glib crash), CVE-2026-3298 (Python Windows asyncio OOB write), CVE-2026-41305 (PostCSS XSS), CVE-2026-6357 (pip self-update vulnerability), and various Linux kernel issues (CVE-2024-41045, CVE-2024-41067, CVE-2024-57974, CVE-2024-57976, CVE-2024-41932, CVE-2026-31545, CVE-2026-31546, CVE-2026-31508, CVE-2026-31540, CVE-2026-6238, CVE-2026-31499). All show low EPSS scores (0.0-0.2%) indicating minimal exploitation likelihood.
Incomplete patches are emerging as a critical risk, with Microsoft's CVE-2026-32202 demonstrating how initial fixes can leave exploitable gaps that sophisticated attackers discover and abuse. Supply chain attacks have evolved to target AI development tooling, with TeamPCP's latest campaign injecting persistence mechanisms into Claude Code and VS Code configuration files, turning the tools developers use to write secure code into infection vectors. The gap between AI capability announcements and operational reality is widening, with AWS internal practices contradicting keynote claims and GitHub's infrastructure buckling under agentic development workloads that exceeded capacity planning by 3x.