← Carolina Clear Tech

Cyber Threat Brief

2026-05-01

Listen to this brief (21:20)

Download MP3
Show Notes

Show Notes - 2026-05-01

Stories Covered

CVEs Referenced

CVE-2023-39417, CVE-2023-5869, CVE-2024-30098, CVE-2025-14510, CVE-2026-0204, CVE-2026-0205, CVE-2026-0206, CVE-2026-31431, CVE-2026-41940

Indicators of Compromise

IP Addresses: 11.110.0.97, 11.118.0.63, 11.126.0.54, 11.132.0.29, 11.134.0.20, 11.136.0.5, 11.136.1.7, 6.5.5.2, 6.5.5.1

Read the full brief

Get tomorrow's brief in your inbox

Protect Your Business

Need a security assessment? See our cybersecurity packages.

View Services

Daily Cyber Threat Brief - 2026-05-01

Today: cPanel's CVE-2026-41940 authentication bypass is being actively exploited after months as a zero-day, giving attackers root access to 1.5 million exposed servers. Two former incident responders were sentenced to 4 years for using BlackCat ransomware against their own clients. Linux's "Copy Fail" vulnerability delivers 100% reliable root access on every major distribution since 2017, and PyTorch Lightning joins SAP packages in the latest TeamPCP supply chain offensive.

Critical Alerts

cPanel and WHM Authentication Bypass (CVE-2026-41940)

CISA added CVE-2026-41940 to its Known Exploited Vulnerabilities catalog on April 30. The critical (CVSS 9.8) flaw in cPanel, WHM, and WP Squared allows unauthenticated remote attackers to bypass authentication and gain administrative access. The vulnerability affects all versions after 11.40 and involves a CRLF injection in the login flow where user-controlled input from the Authorization header is written to session files before authentication without proper sanitization. Attackers can manipulate cookies to write plaintext credentials into session files and then reload those files to authenticate as root. KnownHost reports exploitation attempts as early as February 23, 2026, more than two months before the patch release. Shodan scans show approximately 1.5 million cPanel instances accessible online. EPSS score is 0.165 (95th percentile), indicating high exploitation probability.

Linux Copy Fail Local Privilege Escalation (CVE-2026-31431)

Security firm Theori published a proof-of-concept exploit for CVE-2026-31431, a local privilege escalation vulnerability affecting Linux kernels since 2017. The logic bug in the kernel's cryptographic template allows an authenticated user to perform a 4-byte controlled write to the page cache of any readable file. By combining the AF_ALG socket interface and splice() system call, an unprivileged user can alter setuid-root binaries and gain root privileges. The 732-byte Python exploit achieves 100% reliability on Ubuntu 24.04 LTS, Amazon Linux 2023, RHEL 10.1, and SUSE 16. The flaw was introduced when the kernel team added an "in-place" optimization to the crypto path, reusing the same buffer rather than keeping input and output separate. Theori claims the exploit "roots every Linux distribution shipped since 2017." EPSS score is currently 0.000 (1st percentile) but will increase rapidly as the exploit circulates.

Ransomware & Extortion

Former Incident Responders Sentenced for BlackCat Attacks

Two former cybersecurity professionals were sentenced to four years in prison each for using BlackCat (ALPHV) ransomware to attack U.S. businesses. Ryan Clifford Goldberg (40, former Sygnia incident response manager) and Kevin Tyler Martin (36, former DigitalMint ransomware negotiator) pleaded guilty to conspiracy to obstruct commerce by extortion. Between May 2023 and November 2023, they acted as BlackCat affiliates, paying 20% of ransom proceeds to the ransomware operators. Victims included a Tampa medical device manufacturer that paid $1.27 million after receiving a $10 million demand, a Maryland pharmaceutical company, a California engineering firm, a Virginia drone manufacturer, and a California doctor's office. Martin was arrested without incident in October 2023 and released on bond. Goldberg fled to Europe in June 2023 after an FBI interview, traveling through 10 countries before being arrested in Mexico City in September and deported. A third accomplice, Angelo John Martino III (41), also pleaded guilty and was involved in a broader ransomware scheme that extorted $75.3 million in total. Martino worked as a DigitalMint ransomware negotiator and exploited his position by sharing confidential information about victim organizations' internal negotiating positions and insurance policy limits.

New Scattered Spider-Affiliated Extortion Groups

CrowdStrike identified two new extortion groups, Cordial Spider and Snarky Spider, that are actively targeting U.S. organizations across academic, aviation, retail, hospitality, automotive, financial services, legal, and technology sectors. Both groups are affiliated with The Com and closely aligned with Scattered Spider, using voice phishing and social engineering to compromise identity platforms and traverse SaaS environments. Attacks involve phishing pages posing as employers' legitimate single sign-on pages to capture credentials, session keys, or tokens. After gaining access, attackers remove and establish multi-factor authentication devices, then delete emails and alerts that would warn organizations of malicious activity. The groups use residential proxy networks (Mullvad, Oxylabs, NetNut, 9Proxy, Infatica, NSOCKS) to evade IP-based detection. Cordial Spider's data leak site (BlackFile) was offline as of April 30. Extortion demands are typically in the seven-figure range. Some victims that didn't pay have been subjected to DDoS attacks, and Snarky Spider has used aggressive follow-on harassment including swatting of victim employees.

Business & Infrastructure Threats

PyTorch Lightning Supply Chain Attack

PyTorch Lightning versions 2.6.2 and 2.6.3 were compromised on April 30 and published with malicious code that steals developer credentials. The attack is assessed to be an extension of the Mini Shai-Hulud supply chain campaign that previously targeted SAP-related npm packages. The malicious package includes a hidden _runtime directory containing a downloader and an obfuscated JavaScript payload that executes automatically when the lightning module is imported. The attack chain downloads the Bun JavaScript runtime and executes an 11MB obfuscated payload that conducts comprehensive credential theft targeting GitHub tokens, npm credentials, AWS/Azure/GCP secrets, and local developer environment data. GitHub tokens are validated and then used to inject a worm-like payload into up to 50 branches in every repository the token can write to. The malware also modifies local npm packages by adding a postinstall hook to package.json files, increasing the patch version number, and repacking .tgz tarballs. If developers publish these tampered packages, the malware spreads to downstream users. The attack uses a hardcoded identity designed to impersonate Anthropic's Claude Code in commit messages. PyPI has quarantined the project. It's unclear how the compromise occurred, but indications suggest the project's GitHub account was compromised.

SAP npm Packages Compromised in Mini Shai-Hulud Campaign

Four official SAP npm packages were compromised on April 29 with malicious preinstall scripts. The affected packages are [email protected], @cap-js/[email protected], @cap-js/[email protected], and @cap-js/[email protected], which collectively receive about 572,000 weekly downloads. These packages are widely used by developers building SAP Cloud Application Programming (CAP) applications and Multi-Target Application archives. The malicious code executes automatically on every npm install and fetches the Bun JavaScript runtime from a GitHub repository, then executes an information stealer that targets local credentials, GitHub and npm tokens, and AWS, Azure, GCP, GitHub Actions, Kubernetes, and other cloud secrets. The malware exfiltrates stolen data to public GitHub repositories with the hardcoded description "A Mini Shai-Hulud has Appeared." The malware includes a propagation mechanism that modifies GitHub Actions release workflows, tampers with package tarballs, modifies versions, repackages them, and uses stolen GitHub Actions tokens to publish them. The malicious versions were available for 2-4 hours before being unpublished, and clean versions have been released. Wiz attributes the campaign to TeamPCP based on a shared RSA public key used to encrypt exfiltrated secrets. SAP's npm ecosystem was likely compromised through an exposed npm token in CircleCI pull request builds.

Ruby Gems and Go Modules Supply Chain Attack

A GitHub account "BufferZoneCorp" published malicious Ruby gems and Go modules targeting developers, CI runners, and build environments. The Ruby gems (knot-activesupport-logger, knot-devise-jwt-helper, knot-rack-session-store, knot-rails-assets-pipeline, knot-rspec-formatter-json, and two sleeper gems) masquerade as recognizable libraries and execute credential theft during install time, harvesting environment variables, SSH keys, AWS secrets, .npmrc, .netrc, GitHub CLI configuration, and RubyGems credentials. Data is exfiltrated to Webhook.site endpoints. The Go modules (go-metrics-sdk, go-weather-sdk, go-retryablehttp, go-stdlib-ext, grpc-client, net-helper, config-loader, and two sleeper modules) have broader capabilities to tamper with GitHub Actions workflows, plant fake Go wrappers, steal developer data, and add a hard-coded SSH public key to ~/.ssh/authorized_keys for remote access. The modules execute through init(), detect GITHUB_ENV and GITHUB_PATH environment variables, set HTTP_PROXY and HTTPS_PROXY, write a fake go executable to a cache directory, and append that directory to the workflow path so the wrapper intercepts later go executions. The packages have been yanked from RubyGems and blocked from Go module repositories.

Intercom-client npm Package Compromised

Version 7.0.4 (according to Socket) and 7.0.5 (according to Wiz) of the intercom-client npm package were compromised as part of the Mini Shai-Hulud campaign. The package was injected with the same credential-stealing malware that previously poisoned SAP packages. The attack follows the same operational pattern: preinstall scripts that fetch the Bun runtime and execute obfuscated payloads targeting developer credentials and environment secrets.

AI Phishing Campaigns Dominate Threat Landscape

KnowBe4's seventh Phishing Threat Trends report shows that 86% of phishing campaigns in the past six months involved AI, up from 84% in 2025 and 80% in 2024. AI is being used to automate reconnaissance and information gathering phases, speeding up the phishing process and enabling multi-vector attacks. Calendar invite phishing attacks increased 49%, and Microsoft Teams phishing attacks (impersonating IT support) increased 41%. Attackers use AI to comb through masses of information, extract target data, and feed it into AI-generated email lures that are personalized to each individual. These polymorphic phishing campaigns take a base template and customize it uniquely for each target. Emails are often followed by calendar invites or Teams messages from someone claiming to be from the help desk, demanding credential resets or policy acknowledgments via links. Microsoft reports that AI-generated phishing campaigns are 4.5 times more effective than human-crafted ones. The FBI says US cybercrime losses hit $20.87 billion in 2026, with phishing the most common complaint and AI-related fraud accounting for $893 million.

18 AI Browser Extensions Deliver RATs and Infostealers

Palo Alto Networks Unit 42 identified 18 AI browser extensions marketed as productivity tools that deliver remote access Trojans, man-in-the-middle attacks, and infostealers targeting prompts, user behavior, and browser sessions. Examples include extensions that surveil emails as users compose them, intercept ChatGPT prompts, and exfiltrate passwords. Attackers blend established techniques (API interception, passive DOM observation, traffic proxying, HTTPS response decryption) with AI productivity lures. Multiple samples contained AI-generated code, indicating threat actors used LLMs to accelerate malware production. Google either removed the reported extensions or sent warnings to owners to address policy violations. Browser extensions operate within the browser's trusted process with user-granted permissions, allowing them to read and modify web content, intercept network requests, access cookies, and communicate with external servers. GenAI amplifies the risk because users routinely share proprietary code, draft communications, and strategic plans with AI services, and malicious extensions positioned between the user and AI service can intercept this sensitive data.

Gemini CLI Vulnerability Enabled Supply Chain Attacks

Novee Security researchers discovered a critical RCE vulnerability in Gemini CLI, an open source AI agent providing lightweight access to Gemini from a terminal. The vulnerability allowed host code execution and supply chain attacks because Gemini CLI automatically trusted the current workspace folder, loading any agent configuration found there without review, sandboxing, or human approval. An attacker who could plant a malicious configuration in that folder could cause the AI agent to execute arbitrary commands on the host before sandbox initialization. In CI/CD pipelines, the vulnerability could be leveraged to steal tokens, gain lateral movement to downstream systems, and carry out supply chain attacks. Google has patched both Gemini CLI and the run-gemini-cli GitHub Action. The attack did not involve prompt injection or model decision.

Windows / AD Security

Windows 11 KB5083631 Optional Update Released

Microsoft released KB5083631 optional cumulative update for Windows 11 with 34 changes including a new Xbox mode, enhanced security and performance for batch files, and performance improvements for startup apps. The update improves batch file security by allowing administrators to enable a more secure processing mode that prevents batch files from changing during execution. It also improves Kerberos authentication for Remote Desktop sessions using Remote Credential Guard, addressing error 0xc000009a. Windows Security event logging related to CVE-2024-30098 now includes the name of the affected application, making it easier to identify applications relying on smart card certificates that may need updates. Secure Boot certificates are rolling out to replace the original 2011 certificates expiring in late June 2026. The update targets Windows 11 24H2 and 25H2 devices, updating them to builds 26100.8328 and 26200.8328. Microsoft warns that some Windows Server 2025 devices with "an unrecommended BitLocker Group Policy configuration" will boot into BitLocker recovery and require users to enter the recovery key.

April KB5083769 Update Breaks Backup Software

The April 2026 KB5083769 security update breaks third-party backup applications from multiple vendors on Windows 11 24H2 and 25H2 systems. Affected software includes products from Acronis (Cyber Protect Cloud), Macrium (Reflect), NinjaOne Backup, and UrBackup Server. The issue affects software using VSS (Volume Shadow Copy Service) snapshots and causes failures due to a VSS service timeout. Backup operations fail with the error "The backup has failed because Microsoft VSS has timed out during the snapshot creation." In some cases, affected machines also lose connectivity with cloud consoles and appear offline. As a temporary workaround, users are advised to uninstall KB5083769 from Settings > Windows Update > Update history > Related settings > Uninstall updates, pause Windows updates, and reboot.

Patch Priority

Vulnerability Disclosures

SonicWall Firewall Vulnerabilities

SonicWall released fixes for three vulnerabilities in Gen 6, Gen 7, and Gen 8 firewalls. CVE-2026-0204 (high severity) allows attackers to bypass access controls and access certain management interface functions, potentially modifying firewall configurations and disabling security protections. CVE-2026-0205 (medium severity) is a path traversal weakness that could be exploited to interact with restricted services. CVE-2026-0206 (medium severity) allows remote attackers to crash vulnerable firewalls. Both medium-severity vulnerabilities require authentication. Affected firmware versions: up to 6.5.5.1-6n, 7.0.1-5169, 7.3.1-7013, and 8.1.0-8017. Fixes are available in 6.5.5.2-28n, 7.3.2-7010, and 8.2.0-8009. As a temporary mitigation, restrict management access to SSH only by disabling HTTP/HTTPS-based management and SSLVPN on all interfaces. No evidence of exploitation in the wild.

ABB Ability Symphony Plus PostgreSQL Vulnerabilities

ABB Ability Symphony Plus Engineering versions 2.2 through 2.4 SP2 are affected by vulnerabilities in PostgreSQL version 13.11 and earlier. CVE-2023-5869 allows an authenticated PostgreSQL user to provide crafted data and trigger an integer overflow, enabling execution of arbitrary code. CVE-2023-39417 allows administrators who have installed Extension scripts to execute arbitrary code if specific data is used inside a quoting construct. Both vulnerabilities require that the attacker has access to the site's S+ client/server network. Fixed in Symphony Plus S+ Engineering 2.4 SP2 RU1 (released December 2024). Affected critical infrastructure sectors: chemical, critical manufacturing, energy, water and wastewater.

ABB Ability OPTIMAX Azure AD Authentication Bypass

CVE-2025-14510 allows attackers to bypass user authentication on OPTIMAX installations that use Azure Active Directory Single-Sign On integration. Affected versions: 6.1 (all), 6.2 (all), 6.3 (prior to 6.3.1-251120), and 6.4 (prior to 6.4.1-251120). Fixed versions: 6.3.1-251120 and 6.4.1-251120. Affected critical infrastructure sectors: energy, water and wastewater.

General Security News

Versus Project Marketplace Operator Extradited

A German national living in Colombia was extradited to the United States on charges that he owned and operated "The Versus Project," a dark web marketplace. The case is part of broader law enforcement actions against dark web marketplaces and cybercrime operations.

Transnational Business Email Compromise Scheme

Four defendants were sentenced for their roles in a transnational business email compromise (BEC) scheme that stole more than $38 million from victims across the United States and abroad. The case demonstrates continued law enforcement focus on BEC operations and international cooperation in cybercrime prosecutions.

15-Year-Old Arrested in French Government Data Leak

French authorities arrested a 15-year-old in connection with a massive French government data leak. France has arrested numerous young hackers over the past decade, raising questions about the effectiveness of diversion programs versus prosecution.

DPRK IT Worker Fraud and Insider Risk

NISOS published research on DPRK IT worker fraud following NBC News coverage in March. Security teams, hiring managers, and executives report this is happening and many organizations aren't equipped to detect it. The threat is characterized as a human threat rather than a traditional cyber threat, involving fraudulent employment to gain insider access to organizations.

Trends & Context

Today's brief is dominated by supply chain attacks and zero-day exploitation. The TeamPCP campaign has compromised PyTorch Lightning, four SAP npm packages, and the intercom-client package within 48 hours, demonstrating the group's operational tempo and broad targeting across ecosystems. The cPanel CVE-2026-41940 vulnerability represents a significant threat to web hosting infrastructure, with evidence of exploitation dating back to February and 1.5 million potentially vulnerable instances exposed. The Linux Copy Fail vulnerability (CVE-2026-31431) is particularly concerning because it affects all major distributions since 2017 and has a published 100% reliable exploit. The sentencing of former incident responders for ransomware attacks highlights insider risk in cybersecurity roles, while new Scattered Spider-affiliated groups demonstrate the continued evolution of social engineering and identity-focused extortion campaigns. Organizations should prioritize supply chain security controls, credential rotation, and identity platform hardening in response to today's threat landscape.


Generated 2026-05-01 from 40 articles across 28+ security feeds