CVE-2025-55182, CVE-2026-31706, CVE-2026-31707, CVE-2026-31709, CVE-2026-31712, CVE-2026-41940, CVE-2026-42246, CVE-2026-43338
Get tomorrow's brief in your inbox
Today: Google catches the first confirmed AI-developed zero-day before mass exploitation. The Gentlemen ransomware explodes to third place globally after EtherRAT campaigns hit Windows targets. cPanel CVE-2026-41940 is under active exploitation with 2,000+ attacker IPs deploying backdoors worldwide.
cPanel CVE-2026-41940 Under Active Exploitation to Deploy Filemanager Backdoor
A threat actor named Mr_Rot13 is actively exploiting CVE-2026-41940, a critical authentication bypass in cPanel and WebHost Manager that allows remote attackers to gain elevated control. The vulnerability was added to CISA KEV with a due date of 2026-05-03 and has an EPSS score of 0.670 (99th percentile). Over 2,000 attacker source IPs worldwide are conducting automated attacks, primarily originating from Germany, the United States, Brazil, and the Netherlands. The attack deploys a Go-based infector that implants SSH public keys for persistence, drops PHP web shells for remote command execution, and injects JavaScript to serve fake login pages that steal credentials via ROT13-encoded exfiltration to attacker-controlled infrastructure. The campaign ultimately deploys a cross-platform backdoor called Filemanager capable of file management, remote command execution, and shell functionality across Windows, macOS, and Linux systems.
Google Detects First AI-Developed Zero-Day Exploit (2FA Bypass)
Google Threat Intelligence Group identified a zero-day exploit targeting a popular open-source web administration tool that was likely developed using an AI large language model. The vulnerability allows attackers to bypass two-factor authentication and requires valid user credentials for exploitation. Google assessed with high confidence that an AI model was used based on the exploit code structure, including excessive educational docstrings, a hallucinated CVSS score, and highly structured Pythonic formatting characteristic of LLM training data. The vulnerability stems from a high-level semantic logic flaw arising from hard-coded trust assumptions, which AI systems excel at identifying. The exploit was associated with a prominent cybercrime group planning a mass exploitation operation. Google worked with the impacted vendor to patch the flaw before attackers could deploy it at scale.
EtherRat and TukTuk C2 End in The Gentlemen Ransomware
The DFIR Report documented an intrusion where EtherRAT malware deployed via a malicious MSI masquerading as Sysinternals RAMMap led to The Gentlemen ransomware deployment. The initial infection vector was CVE-2025-55182 (React2Shell), a CISA KEV vulnerability with an EPSS score of 0.820 (99th percentile) and a due date of 2025-12-12. The malware deployed a portable Node.js runtime, used the Ethereum blockchain through EtherHiding for dynamic C2 configuration updates via 1rpc.io, and established persistence through registry Run keys. The threat actors later deployed TukTuk malware variants disguised as legitimate tools like Greenshot, SyncTrayzor, DocFX, and Cake build automation system via DLL sideloading. TukTuk established primary C2 channels through SaaS platforms ClickHouse and Supabase with backup channels via Ably, Dropbox, direct HTTP, GitHub Issues, and Arweave blockchain for dead-drop resolver capability. The actors conducted Kerberoasting operations, credential discovery targeting administrative accounts, and deployed GoTo Resolve RMM tooling laterally across multiple systems including servers and domain controllers before successfully exfiltrating data to cloud services and deploying The Gentlemen ransomware.
The State of Ransomware Q1 2026: Consolidation and The Gentlemen's Breakout
Check Point Research reports that ransomware operations are consolidating after two years of fragmentation. The top 10 ransomware groups accounted for 71% of all Q1 2026 victims, up from 57% in Q3 2025. There were 2,122 victims posted on data leak sites in Q1 2026, the second-highest Q1 on record. Qilin maintained dominance for the third consecutive quarter with 338 victims. The Gentlemen ransomware is the breakout story of Q1 2026, climbing to third place globally and increasing victim count from 40 in Q4 2025 to 166 in Q1 2026. LockBit 5.0 posted 163 victims in Q1 2026, climbing to fourth place. The number of active groups shrank from 85 to 71 as 14 groups disappeared entirely while 21 new groups appeared but posted fewer than 10 victims each. This consolidation pattern follows law enforcement disruptions where surviving groups absorb displaced talent pools and grow. Larger RaaS brands invest in operational consistency including functional decryption tools because their business model depends on the perception that victim payment results in data recovery, in contrast to transient operators with no such incentive.
Checkmarx Jenkins AST Plugin Compromised in Supply Chain Attack
Checkmarx warned users that a malicious version of its Jenkins AST plugin was published to the Jenkins Marketplace as part of a supply chain attack. The plugin integrates Checkmarx One platform functionality into Jenkins pipelines for source code scanning. Checkmarx confirmed that users should run version 2.0.13-829.vc72453fa_1c16 (published December 2025) and subsequently released new versions including 2.0.13-848.v76e89de8a_053. The incident is part of an ongoing supply chain attack that began in March when the TeamPCP hacker gang accessed Checkmarx's repositories through the Trivy supply chain attack. A second wave of malicious artifacts was published in April, and the Lapsus$ extortion group publicly released data stolen from the company's GitHub repositories in late March using credentials compromised through the Trivy attack.
Build Application Firewalls Aim to Stop Supply Chain Attacks
Many serious supply chain attacks are caused by flaws built into applications during the CI/CD build process. The same approach of compromising the development cycle of widely used tools successfully repeated since the 2020 SolarWinds attack continues. In March 2026, North Korean actors hijacked an Axios npm library maintainer account and published two malicious versions downloaded by around 3% of the Axios userbase during the brief period before removal. TeamPCP compromised Aqua's Trivy vulnerability scanner, BerriAI's LiteLLM, and Checkmarx/kics in February/March 2026 to get into CI/CD of widely used tools. Mercor announced itself as one of thousands of companies impacted by the LiteLLM supply chain attack. The European Commission lost 300GB of data to hackers using an API key compromised in the Trivy supply chain attack. The problem is bad code being introduced into the CI/CD application build process, often invisible to developers. Most build systems pull in npm or PyPI packages automatically, but a compromised package, typo-squatted dependency, or malicious version will still get included. Scanners designed to check what goes into CI/CD can often detect problematic code but sometimes cannot, especially when the bad intent doesn't appear malicious or when unknown zero-days are present.
Why Changing Passwords Doesn't End an Active Directory Breach
Password resets do not immediately invalidate old credentials across every authentication path in Active Directory and hybrid Entra ID environments. Windows systems cache password hashes locally to support offline logon, creating three possible states after a password reset: the user logged in with the new credential while connected to AD (cached credential store updates), the user has not logged in to a particular machine since reset (old cached credential may still be usable), or in hybrid deployments the password was reset in AD but has not yet synchronized to Entra ID (old password may still authenticate during the sync interval). Attackers exploit this gap through pass-the-hash attacks where the hash itself is used instead of the plaintext password, meaning changing the password doesn't immediately invalidate it everywhere. Active sessions using Kerberos tickets remain authenticated even after password changes because tickets are valid for a set period. Service accounts with long-lived passwords and elevated privileges are less likely to be reset quickly due to disruption risk, making them a reliable fallback for attackers. Unless sessions are explicitly invalidated through logoff, reboot, or ticket purging, access can continue well beyond the reset.
AI-Augmented Threat Operations: Autonomous Malware and Defense Evasion
Google Threat Intelligence Group's latest report documents AI's dual role as a sophisticated engine for adversary operations and a high-value target for attacks. Chinese actors APT27 and UNC2814 deployed agentic tools like Strix and Hexstrike in attacks targeting Japanese tech firms and East Asian cybersecurity companies, using persona-driven jailbreaks to enhance vulnerability research on embedded devices including TP-Link firmware. North Korean APT45 sent thousands of repetitive prompts to recursively analyze CVEs and validate PoC exploits, creating a more robust arsenal of exploit capabilities impractical to manage without AI assistance. Russia-linked actors used AI-generated decoy code to obfuscate malware such as CANFAIL and LONGSTREAM. The PromptSpy Android backdoor integrates with Gemini APIs for autonomous device interaction using a hardcoded prompt to assign a benign persona and bypass LLM safety features. PromptSpy calculates the geometry of user interface bounds to interact with devices autonomously, can replay authentication gestures such as lock screen PINs or patterns using captured biometric data, and prevents uninstallation by identifying the on-screen coordinates of the Uninstall button and serving an invisible overlay to block touch events. Threat actors are industrializing access to premium AI models using automated account creation, proxy relays, and account-pooling infrastructure. The Russian operation "Overload" used AI voice cloning to impersonate real journalists in fake videos promoting anti-Ukraine narratives.
FCC Relaxes Foreign Router Ban to Allow Security Updates Until 2029
The US Federal Communications Commission updated its ban on foreign-made routers to allow vendors to ship security updates until January 1, 2029. The FCC banned the sale of foreign routers in March but initially allowed companies to ship security updates for one more year until March 2027. Based on comments from government and private sector, the cutoff date was extended to January 2029. The exemption applies only to security updates that mitigate harm to consumers and foreign companies are not allowed to ship new features via this mechanism. The same exemption and cutoff date applies to foreign-made drones, which the FCC banned in December with an initial cutoff date of January 1, 2027. While the US government hinted at banning Chinese companies DJI and TP-Link, a blanket ban on foreign-made drones and routers came unexpectedly. The constant updates these two bans have received on an almost bi-weekly pace shows how little the agency considered possible long-term consequences. Routers and hotspots usually remain in networks for at least a decade and need to receive security updates.
ShinyHunters Disrupts US Schools via Instructure Canvas Platform
Hackers breached and defaced the student management platform of edTech company Instructure. The company placed the Canvas platform in maintenance mode after the ShinyHunters group posted ransom notes on the login screens of some schools. The initial breach took place last month but ShinyHunters defaced the login portals after Instructure failed to pay a ransom. The defacement prevented some schools from accessing the platform during end-of-year exams.
Microsoft Security Update Guide - Linux Kernel CVEs
Microsoft published multiple Linux kernel CVEs affecting Windows Subsystem for Linux (WSL) and related components. Notable disclosures include CVE-2026-31706, CVE-2026-31707, CVE-2026-31709, and CVE-2026-31712, all related to ksmbd ACE validation and response size validation issues with EPSS scores ranging from 0.000 (2nd percentile) to 0.000 (15th percentile). Additional CVEs include CVE-2026-42246 (net-imap STARTTLS stripping vulnerability, EPSS 0.001/16th percentile), CVE-2026-43338 (btrfs transaction items issue, EPSS 0.000/5th percentile), and multiple RDMA, AMD GPU, and Bluetooth vulnerabilities with low EPSS scores indicating minimal observed exploitation activity.
AI is now confirmed as an active tool in the vulnerability discovery and exploit development pipeline, with Google's detection of the first AI-generated zero-day marking a watershed moment. The ransomware ecosystem is consolidating around fewer, more dominant operators like Qilin and The Gentlemen, moving away from the fragmentation seen in 2025. Supply chain attacks continue to target CI/CD pipelines with sophisticated techniques that bypass traditional scanning tools, demonstrating the need for deeper inspection capabilities at the build stage.