← Carolina Clear Tech

Cyber Threat Brief

2026-05-04

Listen to this brief (16:16)

Download MP3
Show Notes

Show Notes - 2026-05-04

Stories Covered

CVEs Referenced

CVE-2026-41940

Indicators of Compromise

IP Addresses: 11.86.0.41, 11.110.0.97, 11.118.0.63, 11.124.0.35, 11.126.0.54, 11.130.0.19, 11.132.0.29, 11.134.0.20, 11.136.0.5

Read the full brief

Get tomorrow's brief in your inbox

Protect Your Business

Need a security assessment? See our cybersecurity packages.

View Services

Daily Cybersecurity Brief - 2026-05-04

Today: cPanel zero-day exploitation hits over 40,000 servers with CISA KEV deadline this week. ShinyHunters claims breach of 275 million education records from Instructure Canvas. DigiCert compromised via social engineering attack, 27 code signing certificates stolen and used to sign malware.

Critical Alerts

cPanel Zero-Day Exploitation (CVE-2026-41940)

Over 40,000 servers compromised in ongoing exploitation of CVE-2026-41940, a critical authentication bypass in cPanel & WebHost Manager. The vulnerability allows unauthenticated attackers to inject administrative credentials via special characters in authorization headers, granting full control over the host system and all managed configurations, databases, and websites. CISA added this to KEV catalog on May 1 with a deadline of May 5 (tomorrow). The vulnerability was likely exploited as a zero-day since late February, with activity spiking after public disclosure and WatchTowr's technical writeup.

Business & Infrastructure Threats

Instructure Canvas Data Breach (ShinyHunters Claims)

Educational technology company Instructure confirmed a cyberattack affecting its Canvas learning management system, with ShinyHunters claiming theft of 3.65 TB containing data on 275 million students, teachers, and staff from nearly 9,000 institutions worldwide. The breach exposed names, email addresses, student ID numbers, private messages between users, and enrollment information. Instructure confirmed personal information was stolen and has deployed patches, rotated API keys (requiring customer re-authorization), and revoked privileged credentials. The company states no evidence of passwords, dates of birth, government identifiers, or financial data exposure at this time.

DigiCert Code Signing Certificate Theft

DigiCert suffered a social engineering attack that compromised two tech support staff and resulted in the theft of 27 EV code signing certificates used to sign malware. Attackers posed as customers and tricked support staff into running malicious screensaver files (SCR format). One compromised system went undetected for nearly two weeks due to a misconfigured CrowdStrike EDR agent that wasn't connected to the central management server. The attacker accessed tech support tickets for pending EV certificate orders and stole initialization codes, which combined with approved orders allowed certificate theft. The stolen certificates were used to sign Zhong Stealer malware, linked to Chinese e-crime group GoldenEyeDog (APT-Q-27). All 60 certificates processed during the breach window have been revoked.

Microsoft Defender False Positive on DigiCert Certificates

Microsoft Defender flagged legitimate DigiCert root certificates as Trojan:Win32/Cerdigent.A!dha and in some cases removed them from the Windows trust store. The false positives began after Defender signature update on April 30, with widespread reports starting May 3. Two specific certificate thumbprints were affected: 0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43 and DDFB16CD4931C973A2037D3FC83A4D7D775D05E4. Microsoft confirmed the false positives were triggered by overly aggressive detections for compromised certificates from the DigiCert breach. The issue was fixed in Security Intelligence update version 1.449.430.0 (current is 1.449.431.0), which also restores previously removed certificates.

Telegram Mini Apps Used for Crypto Scams and Malware

Large-scale fraud operation dubbed FEMITBOT abuses Telegram's Mini App feature to run cryptocurrency scams, impersonate major brands, and distribute Android malware. The platform uses Telegram bots and embedded Mini Apps to create convincing app-like experiences within Telegram's built-in browser. Threat actors impersonated brands including Apple, Coca-Cola, Disney, eBay, IBM, MoonPay, NVIDIA, and YouKu using shared backend infrastructure. Victims are shown fake dashboards with fabricated balances and countdown timers to create urgency, then prompted to deposit funds or complete referral tasks when attempting withdrawals. Some campaigns distribute Android APKs impersonating BBC, NVIDIA, CineTV, CoreWeave, and Claro. The infrastructure uses tracking scripts (Meta and TikTok pixels) to measure and optimize performance.

General Security News

Public Voter Records as Re-identification Attack Surface

Research by Noah Kenney (Digital 520) demonstrates that public voter registration data can be cross-referenced with other datasets to re-identify individuals and enable targeted attacks. Analysis of Texas and North Carolina voter files shows 52-58% match rates to FEC political contribution data using basic exact-match joins on name and ZIP code, which would increase to 90-95% with commercial data broker tools. In North Carolina files that include phone numbers, 88.53% of voters have unique numbers within their county, enabling high-confidence joins to external phone datasets. Kenney outlined threat scenarios including identifying military family members via social media correlation, political affiliation screening by employers, and identity fraud targeting voters with returned mail indicators.

Five Eyes Agencies Warn on Agentic AI Risks

CISA, NSA, and Five Eyes partner agencies released guidance warning that agentic AI systems amplify existing organizational security weaknesses and introduce interconnected attack surfaces. The document cautions that until security practices and evaluation methods mature, organizations should assume agentic AI may behave unexpectedly. Key risks include privilege escalation (agents given overly broad permissions), lateral movement (compromised low-risk tools inheriting agent privileges), and audit log manipulation. The guidance includes 23 risk categories and over 100 best practices, urging slow and careful adoption prioritizing resilience over productivity gains. Vendors are urged to implement fail-safe defaults requiring human escalation in uncertain scenarios.

OpenAI Advanced Account Security for High-Risk Users

OpenAI launched Advanced Account Security, an opt-in feature for ChatGPT and Codex users at increased risk of targeted attacks. The feature is recommended for journalists, researchers, political dissidents, and elected officials. When enabled, it disables password-based login and requires physical security keys or passkeys, replaces email/SMS recovery with backup passkeys and recovery keys, shortens sign-in sessions, provides login alerts and session management, and automatically excludes conversations from AI training. OpenAI partnered with Yubico to offer discounted YubiKey devices. Once enabled, OpenAI support cannot assist with account recovery.

Global Crypto Scam Center Crackdown (276 Arrests)

International operation led by Dubai Police with FBI and Chinese Ministry of Public Security arrested 276 suspects, shut down 9 scam centers, and seized $701 million in assets tied to cryptocurrency investment fraud (pig butchering/romance baiting). Five individuals charged in U.S. courts allegedly managed scam centers under Ko Thet Company, Sanduo Group, and Giant Company, recruiting workers and operating fraudulent cryptocurrency investment platforms. Victims were manipulated into transferring funds to fake platforms after trust was established through romantic or friendly relationships. FBI's Operation Level Up has notified nearly 9,000 victims and prevented an estimated $562 million in losses since January 2024. Separately, two Chinese nationals were charged for running the Shunda scam compound in Myanmar and planning a second facility in Cambodia.

Patch Priority

Vulnerability Disclosures

Wireshark 4.6.5 Released

Wireshark 4.6.5 patches 43 vulnerabilities (38 CVEs) and 35 bugs. The high volume of fixes is attributed to a recent trend in AI-assisted vulnerability reports. No specific CVE details or exploitation evidence provided, but update is recommended for all Wireshark users.

Trends & Context

cPanel exploitation demonstrates the persistent threat of credential injection vulnerabilities in server management platforms, with millions of internet-accessible instances and slow patch adoption creating extended windows for mass compromise. The education sector continues to be a high-value target for data theft operations, with Instructure marking the second major EdTech breach disclosed this year. The DigiCert incident highlights the supply chain risk in code signing infrastructure and the critical importance of EDR configuration management to prevent prolonged compromise of high-trust systems.