← Carolina Clear Tech

Cyber Threat Brief

2026-05-05

Listen to this brief (28:18)

Download MP3
Show Notes

Show Notes - 2026-05-05

Stories Covered

CVEs Referenced

CVE-2023-43896, CVE-2024-1708, CVE-2026-22679, CVE-2026-31431, CVE-2026-32202, CVE-2026-37457, CVE-2026-40170, CVE-2026-41940, CVE-2026-42798, CVE-2026-4670, CVE-2026-5174

Indicators of Compromise

IP Addresses: 95.111.250.175

Read the full brief

Get tomorrow's brief in your inbox

Protect Your Business

Need a security assessment? See our cybersecurity packages.

View Services

Daily Cybersecurity Brief

May 5, 2026

Today: cPanel exploitation reaches thousands of servers with Mirai and ransomware payloads. Copy Fail Linux flaw earns CISA KEV status with 100% reliable root exploit. RMM tools fuel phishing campaign hitting 80+ organizations through dual-channel persistence.

Critical Alerts

cPanel Authentication Bypass (CVE-2026-41940) Exploited at Scale

CVE-2026-41940 is a critical authentication bypass (CVSS 9.8) affecting all supported cPanel, WebHost Manager (WHM), and WP Squared versions. Threat actors began exploiting this flaw within 24 hours of public disclosure on April 29, with at least 44,000 IP addresses launching scanning and brute-force attacks against honeypots on April 30. KnownHost reports signs of exploitation dating back at least 30 days before disclosure, possibly as early as February 23. Attackers are deploying Mirai botnet variants and Sorry ransomware that encrypts files with a ".sorry" extension. Some victims report complete website and backup wipes. Government and military entities in Southeast Asia (Philippines .mil.ph, .ph, Laos *.gov.la) and MSPs in multiple countries are being targeted from IP 95.111.250.175. Censys observed 15,000 potentially compromised instances within the first 24 hours.

Copy Fail Linux Privilege Escalation (CVE-2026-31431) Under Active Exploitation

CVE-2026-31431 is a logic bug in the Linux kernel's algif_aead cryptographic interface allowing unprivileged local users to gain root privileges with 100% reliability. CISA added this to the KEV catalog on May 2, one day after public disclosure, citing active exploitation in the wild. The flaw affects all major Linux distributions from 2017 onward (Ubuntu 24.04 LTS, Amazon Linux 2023, RHEL 10.1, SUSE 16). A 732-byte Python exploit script works unmodified across every distribution with a vulnerable kernel built between 2017 and the patch. EPSS is 0.040 (88th percentile). Exploitation leaves no traces on disk because it occurs entirely in memory and enables container escape from any pod in a Kubernetes cluster. Theori researchers used AI to discover the flaw and generate disclosure content, resulting in some controversy over the AI-generated language in the initial advisory.

Ransomware Claims (Last 48h)

3 claims tracked across 1 group in the last 48 hours. These are unverified claims from ransomware leak sites, not confirmed breaches.

Group Victim Sector Country
cmd organization Cytek Biosciences Biotechnology US
cmd organization JG Stewart Construction Construction/Quarry UK
cmd organization Zampell Refractory Services/Petrochemicals UK

Ransomware & Extortion

Karakurt Member Sentenced to 102 Months

Deniss Zolotarjovs, a 35-year-old Latvian national operating from Moscow, was sentenced to 102 months in federal prison for his role in a Russian ransomware organization. Zolotarjovs was a member of multiple ransomware gangs including Karakurt and other groups that stole from and extorted over 54 companies. The Department of Justice confirmed the sentencing but did not release additional operational details.

Business & Infrastructure Threats

RMM Tools Abused in VENOMOUS#HELPER Phishing Campaign

An ongoing phishing campaign tracked as VENOMOUS#HELPER (also known as STAC6405) has compromised over 80 organizations since at least April 2025, primarily in the US with additional victims in Western Europe and Latin America. The campaign uses SSA-themed phishing emails directing victims to legitimate-but-compromised Mexican websites hosting malicious executables. The payload installs both SimpleHelp and ScreenConnect RMM tools, creating redundant dual-channel access. SimpleHelp (version 5.0.1) serves as the primary channel for scripts, automated tasks, and surveillance, while ScreenConnect provides interactive desktop control as a backup. Both tools are legitimately signed and use JWrapper packaging. SimpleHelp establishes Safe Mode persistence, self-healing watchdog processes, and polls security products every 67 seconds and user presence every 23 seconds. The operator gains SYSTEM-level privileges via SeDebugPrivilege and tracks cursor movement to execute hands-on attacks when users are away. Researchers at Huntress reported a 277% year-over-year increase in RMM tool misuse in 2025, with RMM tools appearing in nearly a quarter of all incidents.

Vishing Groups Operate Within SaaS Environments

Two cybercrime groups tracked as Cordial Spider and Snarky Spider are conducting rapid, high-impact attacks that operate almost entirely within SaaS environments while leaving minimal traces. The groups use voice calls, text messages, and emails to direct targeted employees to phishing pages masquerading as legitimate SSO pages. After capturing credentials, attackers remove existing MFA devices, set up new MFA under their control, and delete emails that would alert organizations to the malicious activity. The attacks bypass MFA and move laterally across entire SaaS ecosystems with a single authenticated session. Attackers mask their tracks through residential proxy networks to blend in as legitimate home user traffic. CrowdStrike notes this is part of a larger trend of English-speaking ransomware crews that share similar playbooks but are branching off into their own distinct groups.

TeamPCP Mini Shai-Hulud Worm Campaign (Week of April 27-May 3)

TeamPCP executed a self-propagating supply chain worm campaign April 29-30 compromising four official SAP npm packages (mbt, @cap-js/db-service, @cap-js/postgres, @cap-js/sqlite), two PyTorch Lightning PyPI versions, two intercom-client npm versions, and the intercom-php Packagist package. Combined weekly downloads exceed 500,000 for the SAP packages alone. OX Security tracked roughly 1,800 GitHub repositories created with stolen credentials during the two-day campaign. The malicious preinstall hook downloads the Bun runtime from the legitimate oven-sh GitHub release and executes execution.js, an obfuscated information stealer targeting npm and GitHub tokens, SSH keys, AWS/Azure/GCP credentials, Kubernetes configs, CI/CD secrets, and environment variables. The worm uniquely weaponizes .claude/settings files. Wiz attributed the operation to TeamPCP at high confidence based on a shared RSA public key with prior Bitwarden CLI and Checkmarx KICS operations. Check Point Research also disclosed that TeamPCP's extortion partner Vect 2.0 ships a ChaCha20-IETF nonce-reuse flaw that effectively turns the ransomware into a data wiper for any file larger than 128 KB, making it impossible to recover files even if the ransom is paid. CISA added CVE-2024-1708 (ConnectWise ScreenConnect path traversal) and CVE-2026-32202 (Microsoft Windows Shell spoofing) to the KEV catalog on April 28, neither TeamPCP-related.

DigiCert Revokes 60 Certificates After Support Portal Compromise

DigiCert disclosed a support portal compromise that resulted in fraudulent EV Code Signing certificates. The attack occurred on April 2 when a threat actor delivered malware via a customer chat channel disguised as a screenshot. The malware infected two endpoints, one detected on April 3 and another not discovered until April 14 due to malfunctioning security solutions. Attackers pivoted to the internal support portal using a limited access function to obtain EV Code Signing certificates. DigiCert's support analysts can proxy into customer accounts, providing access to initialization codes for pending Code Signing certificate orders. Possession of an initialization code combined with an approved order is sufficient to obtain the resulting certificate. DigiCert identified and revoked 60 certificates by April 17, including 27 explicitly linked to the threat actor. Eleven were reported by the community and used to sign Zhong Stealer malware. DigiCert improved security controls to enforce MFA for administrative workflows, prevent access to initialization codes from proxied support users, restrict file types in support chat and Salesforce attachments, and improve logging.

Amazon SES Abused for Phishing at Scale

Kaspersky researchers report a spike in phishing attacks leveraging Amazon Simple Email Service (SES) to send convincing emails that bypass standard security filters. The primary driver is the increasing exposure of AWS IAM access keys in GitHub repositories, .ENV files, Docker images, backups, and publicly accessible S3 buckets. Threat actors use automated bots built on TruffleHog to scan for leaked secrets, then verify the key's permissions and email sending limits before spreading massive volumes of phishing messages. Because Amazon SES is a legitimate, trusted resource, phishing operations can send malicious emails that pass SPF, DKIM, and DMARC authentication checks. Observed attacks include fake DocuSign document-signing notifications leading to AWS-hosted phishing pages and business email compromise (BEC) attacks with fabricated email threads and fake invoices. Blocking offending IP addresses is not an acceptable solution because it would block all emails coming through Amazon SES.

Trellix Discloses Source Code Repository Breach

Cybersecurity firm Trellix disclosed unauthorized access to a portion of its source code repository. Trellix is a global cybersecurity company serving over 50,000 business and government customers worldwide, protecting more than 200 million endpoints. The company is investigating the incident with outside forensic experts and has notified law enforcement. Trellix has found no evidence that the source code release or distribution process was affected or that the source code has been exploited. The company has not disclosed when the breach was detected, whether attackers stole corporate or customer data, or whether a ransom demand was made.

Windows / AD Security

Code of Conduct Phishing Campaign Targets 35,000 Users with AiTM Token Theft

A large-scale credential theft campaign observed between April 14-16 targeted more than 35,000 users across over 13,000 organizations in 26 countries, with 92% of targets in the US. The campaign impacted Healthcare & life sciences (19%), Financial services (18%), Professional services (11%), and Technology & software (11%). Emails posed as internal compliance or regulatory communications using display names like "Internal Regulatory COC", "Workforce Communications", and "Team Conduct Report" with subject lines claiming code of conduct reviews. Messages were sent from a legitimate email delivery service and included PDF attachments with links to multi-stage CAPTCHA and intermediate staging pages designed to reinforce legitimacy and filter out automated defenses. The attack chain led to an adversary-in-the-middle (AiTM) phishing flow that proxied the authentication session and captured authentication tokens in real time, bypassing non-phishing-resistant multifactor authentication. Messages included preemptive authenticity statements claiming the message was "issued through an authorized internal channel" and links were "reviewed and approved for secure access". A green Paubox banner at the end of each message reinforced confidentiality claims.

April Windows Updates Cause Backup Failures

Microsoft confirmed that April 2026 security updates are causing failures in third-party backup applications using the psmounterex.sys driver. The April updates include a security hardening change that adds psmounterex.sys to Microsoft's vulnerable driver blocklist to defend against CVE-2023-43896, a high-severity buffer overflow vulnerability allowing privilege escalation or arbitrary code execution. Software impacted includes Macrium Reflect, Acronis Cyber Protect Cloud, UrBackup Server, and NinjaOne Backup running on Windows 11, Windows Server, and Windows 10. Backup applications using VSS snapshots may fail with VSS service timeouts. Backup creation (full image backups) may still succeed, but image-mount operations will fail. Event Viewer shows Code Integrity errors indicating psmounterex.sys was blocked. Microsoft advises customers to update to newer versions of affected applications that use newer drivers with required protections, not to uninstall or pause the update.

General Security News

Weaver E-cology RCE (CVE-2026-22679) Exploited Since March

CVE-2026-22679 is a critical unauthenticated remote code execution vulnerability (CVSS 9.8) affecting Weaver E-cology 10.0 versions prior to build 20260312. Weaver E-cology is an enterprise office automation and collaboration platform used primarily by Chinese organizations. The flaw resides in the /papi/esearch/data/devops/dubboApi/debug/method endpoint, allowing attackers to craft POST requests with controlled interfaceName and methodName parameters to execute arbitrary commands. Vega Research Team identified active exploitation dating back to March 17, five days after patches were shipped. The intrusion unfolded over roughly a week with RCE verification, three failed payload drops, an attempted pivot to an MSI implant (fanwei0324.msi), and attempts to retrieve PowerShell payloads from attacker-controlled infrastructure. Attackers ran discovery commands (whoami, ipconfig, tasklist) throughout the campaign. Shadowserver Foundation observed the first signs of exploitation on March 31.

ScarCruft Deploys BirdCall Android Malware via Supply Chain Attack

North Korean APT37 (ScarCruft, Ricochet Chollima) has been delivering an Android version of the BirdCall backdoor through a supply-chain attack on sqgame.net, a Chinese video game platform catering to Koreans in China's autonomous Yanbian region. The Android variant was developed around October 2024 with at least seven versions. BirdCall for Android extracts geolocation information, collects contacts, call logs, SMS, device details (OS, kernel, IMEI, MAC address), takes periodic screenshots, records audio via microphone from 7-10 PM local time, plays a silent MP3 in a loop to prevent process suspension, and exfiltrates files. Windows infections begin with a trojanized mono.dll that downloads RokRAT, which then deploys the Windows version of BirdCall. The Android version does not yet feature shell command execution, traffic proxying, browser/messenger data targeting, file deletion/dropping, or process killing capabilities present in the Windows version.

Cisco Acquires Astrix Security for Non-Human Identity Management

Cisco announced its intent to acquire Astrix Security, a startup focused on securing non-human identities (NHIs) such as API keys, service accounts, and OAuth tokens increasingly used by applications and AI agents. Calcalist reports the deal is valued at roughly $400 million. Astrix provides visibility into non-human identities and AI-driven agent activity, along with lifecycle management and automated detection and remediation of over-privileged, unnecessary, or malicious access. Cisco plans to integrate these capabilities into its broader security platform, including identity intelligence, secure access, and Duo IAM. The acquisition reflects growing industry concern over risks tied to autonomous AI agents and machine-to-machine access.

Patch Priority

Vulnerability Disclosures

MOVEit Automation Critical Authentication Bypass (CVE-2026-4670)

Progress Software patched CVE-2026-4670, a critical authentication bypass vulnerability (CVSS score not disclosed) in MOVEit Automation versions before 2025.1.5, 2025.0.9, and 2024.1.8. Remote threat actors can exploit this flaw without privileges in low-complexity attacks that don't require user interaction. Over 1,400 MOVEit Automation instances are exposed online, with over a dozen linked to U.S. local and state government agencies. Progress also addressed CVE-2026-5174, a high-severity privilege escalation vulnerability stemming from improper input validation. Upgrading to a patched release using the full installer is the only remediation. MFT software is an attractive target for ransomware actors, as seen in previous Clop campaigns targeting Accellion FTA, SolarWinds Serv-U, Gladinet CentreStack, GoAnywhere MFT, and Cleo. Clop exploited a MOVEit Transfer zero-day in 2023, affecting more than 2,100 organizations and over 62 million individuals.

Microsoft CVEs Published with Minimal Details

Microsoft published three CVEs in the MSRC Security Update Guide with no technical details beyond "Information published": CVE-2026-42798 (EPSS 0.000, 2nd percentile), CVE-2026-40170 (ngtcp2 qlog transport parameter serialization stack buffer overflow, EPSS 0.001, 15th percentile), and CVE-2026-37457 (EPSS 0.000, 12th percentile). No severity scores, affected products, or mitigation guidance are currently available.

Trends & Context

The week's stories reveal a consistent pattern: legitimate infrastructure is the new attack surface. RMM tools, email services like Amazon SES, and supply chain platforms are all being weaponized because defenders trust them by default. Meanwhile, exploitation timelines continue to compress. cPanel attacks began within 24 hours of disclosure, and Copy Fail moved from public PoC to CISA KEV in one day. The Weaver E-cology timeline shows exploitation starting five days after patch release and two weeks before public disclosure, suggesting either patch diffing or insider knowledge. TeamPCP's supply chain worm demonstrated cross-ecosystem propagation in production (npm to PyPI to Packagist), realizing a theoretical risk that is now operational reality.