CyberSecBrief

Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks


Daily Cybersecurity Briefing (6 April 2026)

Published: Loading…

At a Glance

  • FortiClient EMS flaw CVE-2026-35616 enables pre-authentication API bypass and unauthorised code execution on versions 7.4.5 and 7.4.6.
  • Attackers exploited React2Shell CVE-2025-55182 in vulnerable Next.js applications to automate credential theft at large scale.
  • A GitHub Actions campaign abused pull_request_target to open more than 500 malicious pull requests and compromise two npm packages.
  • The European Commission breach exposed 91.7 GB of data after attackers used a Trivy-stolen AWS key against cloud infrastructure.
  • Thirty-six malicious npm packages posed as Strapi plugins to exploit Redis and PostgreSQL, deploy reverse shells, and install persistent implants.
  • Traffic violation phishing texts used QR codes and fake court notices to steal payment card and personal data.

Summary

FortiClient EMS is under active exploitation through CVE-2026-35616, a critical improper access control flaw affecting versions 7.4.5 and 7.4.6. The vulnerability allows pre-authentication API bypass and may let attackers execute unauthorised code or commands via crafted requests..

React2Shell exploitation is driving an automated credential theft campaign against vulnerable Next.js applications. Device code phishing activity also surged 37-fold this year, abusing the OAuth 2.0 Device Authorization Grant flow to hijack user accounts.

A GitHub Actions campaign abused pull_request_target to open more than 500 malicious pull requests between 11 March and 3 April 2026. The payloads targeted files including conftest.py, package.json, Makefile, and build.rs, and led to compromise of two npm packages across 106 versions.

The European Commission breach began after attackers used an AWS API key stolen through the Trivy supply chain compromise on 19 March. The intrusion exposed about 91.7 GB of compressed data from infrastructure serving 71 clients, including at least 29 other Union entities.

Thirty-six malicious npm packages masquerading as Strapi plugins targeted Redis and PostgreSQL environments with reverse shells, credential theft, and persistent implants. A separate software supply chain wave also involved attackers posting the leaked Claude Code source together with malware.

Fake traffic violation text messages impersonating U.S. state courts used QR codes to direct victims to phishing pages requesting a $6.99 payment. The Drift cryptocurrency theft, which resulted in losses of $285 million, was attributed to a six-month DPRK social engineering operation.

Highlights of the Day

GitHub PR Campaign Exploits GitHub Actions at Scale

Wiz traced a GitHub Actions campaign to one actor using six accounts from 11 March to 3 April 2026, opening more than 500 malicious pull requests. The attacker abused the pull_request_target trigger, injecting payloads into files such as conftest.py, package.json, Makefile, and build.rs to steal tokens and enumerate secrets. Wiz said the largest wave generated over 475 pull requests in 26 hours and led to confirmed compromise of two npm packages across 106 malicious versions.

Source: Wiz

EU Cloud Breach Linked to Trivy Supply Chain Attack

CERT-EU said attackers stole an AWS API key on 19 March through the Trivy supply chain compromise and used it to access European Commission cloud infrastructure. The actor created a new access key for an existing user, ran TruffleHog to search for additional secrets, and conducted reconnaissance inside the AWS environment. CERT-EU said about 91.7 GB of compressed data was exfiltrated, affecting infrastructure serving 71 clients, with ShinyHunters later publishing the stolen dataset.

Source: CERT-EU

Fortinet Confirms Active Exploitation of FortiClient EMS Zero-Day

Fortinet said attackers are exploiting CVE-2026-35616, a critical improper access control flaw in FortiClient EMS that allows unauthenticated API authentication and authorisation bypass. The vulnerability affects FortiClient EMS 7.4.5 and 7.4.6 and may let remote attackers execute unauthorised code or commands through crafted requests. Fortinet assigned the flaw a CVSS score of 9.1 and released emergency hotfixes, while stating that the 7.2 branch is not affected.

Daily Coverage

Developments
Forticlient Zero-DayReact2Shell ExploitationGithub Pr AbuseTrivy Cloud Breach
Vulnerabilities
CVE-2026-35616Forticlientems 7.4.5 (Critical)CVE-2026-2699Sharefile Storage Zones ControllerCVE-2026-2701Sharefile Storage Zones ControllerCVE-2025-55182A Pre-Authentication Remote Code Execution Vulnerability Exists In React Server Components Versions 19.0.0, 19.1.0, 19.1.1, And 19.2.0 Including The Following Packages: React-Server-Dom-Parcel, React-Server-Dom-Turbopack, And React-Server-Dom-Webpack. The Vulnerable Code Unsafely Deserializes Payloads From Http Requests To Server Function Endpoints.CVE-2026-5495CVE-2026-5494CVE-2026-5493CVE-2026-5496
Threat Groups
SilenceSilence is a financially motivated threat actor targeting financial institutions in different countries. The group was first seen in June 2016. Their main targets reside in Russia, Ukraine, Belarus, Azerbaijan, Poland and Kazakhstan. They compromised various banking systems, including the Russian Central Bank's Automated Workstation Client, ATMs, and card processing.