CVE-2020-13949, CVE-2026-0300, CVE-2026-32934, CVE-2026-32936, CVE-2026-33190, CVE-2026-33489, CVE-2026-33845, CVE-2026-3832, CVE-2026-3833, CVE-2026-42151, CVE-2026-42154, CVE-2026-43185, CVE-2026-43868, CVE-2026-6383
Get tomorrow's brief in your inbox
Today: Iranian state-sponsored actors are masquerading ransomware attacks to hide espionage operations. Palo Alto Networks discloses critical zero-day CVE-2026-0300 under active exploitation, with CISA KEV deadline May 9. Backups continue failing during ransomware attacks because attackers destroy them first.
Palo Alto PAN-OS Zero-Day Exploitation (CVE-2026-0300)
A buffer overflow in the User-ID Authentication Portal (Captive Portal) of PAN-OS allows unauthenticated remote code execution with root privileges on PA-Series and VM-Series firewalls. CVSS 9.3, CISA added to KEV catalog with remediation deadline May 9, 2026. Exploitation began April 9 targeting limited number of customers with captive portal exposed to public internet or untrusted networks. Unit 42 tracks activity cluster CL-STA-1132 as likely state-sponsored. Post-exploitation includes deployment of EarthWorm and ReverseSocks5 tunneling tools, Active Directory enumeration using firewall service account credentials, and systematic log destruction. First patches expected May 13.
MuddyWater Uses Chaos Ransomware Brand as False Flag
Iranian state-sponsored group MuddyWater (Mango Sandstorm, Seedworm, Static Kitten) conducted espionage operation in early 2026 disguised as Chaos ransomware attack. Social engineering via Microsoft Teams involved screen-sharing sessions to harvest credentials and manipulate MFA. Attackers deployed custom Darkcomp RAT (Game.exe), established persistence via DWAgent and AnyDesk, exfiltrated data, and sent extortion emails directing victim to Chaos leak site. No file encryption occurred. Infrastructure overlaps with previous MuddyWater campaigns, and malware was signed with certificate linked to group's Stagecomp and Darkcomp operations. Rapid7 attributes with moderate confidence to Iranian Ministry of Intelligence and Security (MOIS). Pattern mirrors October 2025 attack where MuddyWater used Qilin ransomware against Israeli hospital. Chaos RaaS emerged early 2025, has claimed 36 victims as of late March 2026, primarily U.S. construction, manufacturing, and business services sectors.
Why Backups Fail During Ransomware Attacks
Backups are systematically destroyed before encryption in modern ransomware attacks. Acronis Cyberthreats Report H2 2025 shows 50% increase in attacks year-over-year. Attack sequence: initial access, credential theft, lateral movement, backup discovery, backup destruction, ransomware deployment. Attackers with admin credentials enumerate backup servers, delete or encrypt backup files and snapshots, disable backup agents, modify retention policies, delete Volume Shadow Copies on Windows, target hypervisor snapshots, and exploit API access to cloud backup storage. Common backup failures: no isolation between production and backup systems, weak access controls including shared admin credentials and lack of MFA, no immutability allowing modification or deletion, untested recovery processes revealing incomplete or corrupted backups, and siloed security tools preventing detection of attacks on backup infrastructure.
Threat Activity Enablers: Infrastructure Backbone for Ransomware and Botnets
Recorded Future identifies threat activity enablers (TAEs) as providers that support malicious cyber activity by providing infrastructure or services to threat actors. TAEs lack physical or virtual storefronts, conduct business only via email or messaging, do not enforce KYC policies, selectively respond to abuse reports to maintain plausible deniability, or openly ignore oversight. TAEs use corporate shell games with front companies across multiple jurisdictions, operate as local internet registries (LIRs) for direct control over IP resources and ASNs, and rapidly rebrand by transferring IP prefixes to newly registered clean-looking entities when scrutiny increases. Recorded Future's Network Threat Density List ranks high-risk TAE networks by Threat Density Score based on concentration of validated malicious activity relative to total IP address prefixes. Case study: Virtualine Technologies shifted IPv4 resources to fraudulently impersonate legitimate German firm metaspinner net GmbH in April 2025. New network became primary distribution hub for Latrodectus and AsyncRAT malware within weeks. When exposed, infrastructure pivoted to new identity within existing autonomous systems.
Real Estate Giant Confirms Vishing Incident as ShinyHunters and Qilin Claim Involvement
Title references Cushman & Wakefield vishing incident with competing claims from ShinyHunters and Qilin ransomware groups. Article content was truncated and did not contain substantive details beyond headline reference.
Vendor Breach Litigation: Banks Face Lawsuits After Third-Party Provider Incidents
Recent high-profile incident shows financial institutions face growing litigation and regulatory risks from vendor-driven data breaches. Within weeks of national bank confirming data security incident at third-party service provider, at least two putative class actions were filed. Financial institutions remain legally liable for vendor security failures under various regulatory frameworks and contract law principles.
AI Agent Identity Governance Gap
Gartner Market Guide for Guardian Agents states enterprise adoption of AI agents is accelerating and outpacing maturity of governance policy controls. Traditional IAM designed for human login patterns fails to manage AI agents that run continuously, span multiple applications, acquire permissions opportunistically, and generate activity at machine speed. Orchid Security analysis shows roughly half of enterprise identity activity occurs outside centralized IAM visibility because identities and controls live in applications themselves, not central directories. Ask Orchid AI agent applies identity observability at the source inside applications at binary and configuration layer to answer questions about full identity estate including AI agent inventory, NIST compliance status, and runtime activity monitoring.
CopyFail Linux Flaw Under Active Exploitation
Article title indicates fresh Linux vulnerability dubbed "CopyFail" is being exploited by attackers. Content was truncated and did not contain technical details, CVE identifier, or specific exploitation information.
GnuTLS Certificate and DTLS Vulnerabilities
CVE-2026-3832 allows attackers to bypass certificate revocation checks by crafting malicious OCSP responses, enabling acceptance of revoked server certificates. EPSS 0.000 (8th percentile). CVE-2026-33845 enables DoS attacks via DTLS zero-length fragments. EPSS 0.000 (14th percentile). CVE-2026-3833 bypasses name constraints policies due to case-sensitive comparison, allowing certificates for domains that should be restricted. EPSS 0.000 (13th percentile).
CoreDNS Authentication and DoS Vulnerabilities
CVE-2026-33190 bypasses TSIG authentication on DNS-over-TLS and DNS-over-HTTPS transports, allowing unauthorized zone transfers or updates. EPSS 0.001 (21st percentile). CVE-2026-32936 in DoH GET path lacks size validation, allowing attackers to cause CPU and memory amplification via oversized queries. EPSS 0.001 (28th percentile). CVE-2026-32934 affects DNS-over-QUIC implementation with unbounded goroutine growth leading to resource exhaustion. EPSS 0.001 (34th percentile). CVE-2026-33489 in transfer plugin allows subzone ACL bypass via lexicographic zone comparison, enabling unauthorized zone transfers. EPSS 0.000 (12th percentile).
Prometheus Configuration and DoS Issues
CVE-2026-42151 exposes Azure AD remote write OAuth client secrets via config API, allowing unauthorized access to monitoring data or write endpoints. EPSS 0.000 (1st percentile). CVE-2026-42154 allows DoS attacks against remote read endpoint via crafted Snappy-compressed payloads. EPSS 0.000 (6th percentile).
Additional CVE Disclosures
Microsoft Security Response Center published multiple Linux kernel and infrastructure CVEs: CVE-2026-43185 (ksmbd signedness bug in SMB Direct negotiation), CVE-2026-43868 (Apache Thrift Rust implementation vulnerable to CVE-2020-13949 pattern, EPSS 0.000), CVE-2026-6383 (KubeVirt unauthorized subresource access due to improper RBAC evaluation, EPSS 0.000), and numerous other Linux kernel fixes affecting NTFS3, XFS, networking, and device drivers. All have low EPSS scores indicating minimal observed exploitation risk currently.
Three converging patterns define today's threat landscape. State-sponsored actors increasingly masquerade as cybercriminals to complicate attribution and maintain plausible deniability, as demonstrated by MuddyWater's use of Chaos ransomware branding. Infrastructure providers operating as threat activity enablers provide persistent, resilient backbone for ransomware operations by obscuring ownership through shell companies and rapidly rebranding when exposed. Backup infrastructure continues to be primary target for destruction before ransomware deployment, with successful attacks leveraging inadequate isolation, lack of immutability, and weak access controls to eliminate recovery options before encryption begins.