CyberSecBrief

Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks


Daily Cybersecurity Briefing (7 April 2026)

Published: Loading…

At a Glance

  • Storm-1175 conducts high-tempo Medusa ransomware campaigns, exploiting zero-days and web-facing flaws, moving from initial access to data theft and encryption within 24 hours.
  • Germany’s BKA identified Daniil Shchukin, alias UNKN, as the leader of GandCrab and REvil, responsible for at least 130 attacks from 2019 to 2021.
  • Fortinet released an emergency hotfix for CVE-2026-35616 in FortiClient EMS, patched against unauthenticated remote code execution actively exploited in the wild.
  • Google DeepMind researchers mapped six web-based AI agent attack classes, enabling manipulation, data theft, unauthorised transactions, and misinformation delivery via web content.
  • Progress ShareFile SZC 5.x vulnerabilities CVE-2026-2699 and CVE-2026-2701 allow unauthenticated pre-authentication remote code execution through chained administrative and file upload flaws.
  • Kubernetes attackers exploited service account tokens, including CVE-2025-55182 React2Shell, stealing credentials and pivoting into cloud backend and financial infrastructure.

Summary

Storm-1175 has executed high-tempo Medusa ransomware campaigns targeting web-facing systems. The group leverages zero-day and n-day vulnerabilities to move from initial access to data exfiltration and encryption in less than 24 hours.

Germany’s Federal Criminal Police identified 31-year-old Daniil Shchukin, known as UNKN, as the leader of the GandCrab and REvil ransomware groups. Shchukin is linked to at least 130 attacks between 2019 and 2021, resulting in over €35 million in economic damage.

Fortinet released a critical emergency hotfix for FortiClient EMS to address CVE-2026-35616. The flaw allows unauthenticated remote code execution and had been actively exploited in federal and enterprise environments.

Google DeepMind detailed six classes of web-based attacks against autonomous AI agents. These attacks enable manipulation, data theft, unauthorised transactions, and misinformation via web content elements such as scripts, metadata, and images.

Progress ShareFile SZC 5.x contains vulnerabilities CVE-2026-2699 and CVE-2026-2701, permitting unauthenticated remote code execution by chaining administrative access and arbitrary file uploads. Fixed versions 5.12.4 and above are available.

Kubernetes environments saw a surge in service account token theft, including exploitation of React2Shell (CVE-2025-55182). Threat actors leveraged stolen tokens to pivot into backend cloud systems, exfiltrating credentials and deploying backdoors or cryptominers.

Cybersecurity activity in cloud and enterprise environments continues to show sophisticated exploitation of software flaws. Organisations are advised to prioritise patches, monitor exposed systems, and audit token and administrative access.

Highlights of the Day

Microsoft said Storm-1175 is running high-tempo Medusa ransomware intrusions by exploiting vulnerable internet-facing systems, often moving from initial access to data theft and encryption within 24 hours to six days. Since 2023, the group has exploited more than 16 flaws across Exchange, Ivanti, ScreenConnect, TeamCity, CrushFTP, GoAnywhere, SmarterMail, BeyondTrust and SAP NetWeaver, including zero-days used before public disclosure. Post-compromise activity included web shells, new administrator accounts, Cloudflare Tunnels, RMM tools, LSASS credential dumping, Veeam password recovery, Rclone exfiltration, and PDQ Deployer or Group Policy for ransomware deployment.

Germany Names Alleged REvil and GandCrab Leader

Germany’s Federal Criminal Police identified 31-year-old Russian Daniil Maksimovich Shchukin as “UNKN”, alleging he led the GandCrab and REvil ransomware groups and helped carry out at least 130 attacks in Germany between 2019 and 2021. The BKA said Shchukin and alleged associate Anatoly Sergeevitsch Kravchuk extorted nearly €2 million across roughly two dozen incidents that caused more than €35 million in economic damage. US court filings from 2023 also linked Shchukin to cryptocurrency proceeds from REvil, while German authorities said he is believed to be residing in Krasnodar, Russia.

Google DeepMind Maps Web Traps for AI Agents

Google DeepMind researchers described “AI Agent Traps”, a web-based attack class that uses malicious content to manipulate autonomous agents into actions such as data theft, unauthorised transactions, and misinformation delivery. Their framework defines six attack categories, including hidden prompt injection, semantic manipulation, memory poisoning, behavioural hijacking, multi-agent systemic failure, and human-in-the-loop abuse. The paper says traps can be embedded in HTML comments, metadata, JavaScript, images, or external resources, exploiting gaps between human-visible pages and machine-parsed content.

Critical Pre-Auth RCE Found in Progress ShareFile SZC 5.x

Two high-severity vulnerabilities, CVE-2026-2699 and CVE-2026-2701, affect Progress ShareFile Storage Zones Controller 5.x, allowing unauthenticated actors to access administrative functions and upload arbitrary files to web-accessible paths. Chaining these flaws enables pre-authentication remote code execution on systems running versions 5.12.3 or below, potentially exposing sensitive configurations and executable deployment. Progress ShareFile released fixes on 10 March 2026, upgrading affected systems to v5.12.4 or any v6 version, with no active exploitation observed at the time of reporting.

Kubernetes Token Theft Surges as Attackers Pivot Into Cloud

Palo Alto Networks said Kubernetes-related threat activity involving service account token theft rose 282% year-on-year, with suspicious token theft observed in 22% of cloud environments during 2025. Unit 42 described one mid-2025 intrusion at a cryptocurrency exchange where attackers deployed a malicious pod, stole a high-privilege Kubernetes token, then pivoted into backend cloud systems and financial infrastructure. The report also said attackers exploited React2Shell (CVE-2025-55182) within two days of disclosure, using code execution in containers to harvest tokens, exfiltrate cloud credentials, and deploy backdoors or cryptominers.

Source: Unit 42

Daily Coverage

Developments
Unkn IdentifiedMedusa RansomwareForticlient Ems PatchAi Agent Traps
Vulnerabilities
CVE-2025-59528Flowise = 3.0.5 (Critical)CVE-2026-34040CVE-2024-41110CVE-2026-35616Forticlientems 7.4.5 (Critical)CVE-2026-2699Sharefile Storage Zones ControllerCVE-2026-2701Sharefile Storage Zones ControllerCVE-2025-55182A Pre-Authentication Remote Code Execution Vulnerability Exists In React Server Components Versions 19.0.0, 19.1.0, 19.1.1, And 19.2.0 Including The Following Packages: React-Server-Dom-Parcel, React-Server-Dom-Turbopack, And React-Server-Dom-Webpack. The Vulnerable Code Unsafely Deserializes Payloads From Http Requests To Server Function Endpoints.
Threat Groups
APT28[Also known as: Forest Blizzard, Fancy Bear] APT28 is a threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) 85th Main Special Service Center (GTsSS) military unit 26165. This group has been active since at least 2004. APT28 reportedly compromised the Hillary Clinton campaign, the Democratic National Committee, and the Democratic Congressional Campaign Committee in 2016 in an attempt to interfere with the U. S. presidential election. In 2018, the US indicted five GRU Unit 26165 officers associated with APT28 for cyber operations (including closeaccess operations) conducted between 2014 and 2018 against the World AntiDoping Agency (WADA), the US AntiDoping Agency, a US nuclear facility, the Organization for the Prohibition of Chemical Weapons (OPCW), the Spiez Swiss Chemicals Laboratory, and other organizations. Some of these were conducted with the assistance of GRU Unit 74455, which is also referred to as Sandworm Team.Contagious InterviewContagious Interview is a North Korea–aligned threat group active since 2023. The group conducts both cyberespionage and financially motivated operations, including the theft of cryptocurrency and user credentials. Contagious Interview targets Windows, Linux, and macOS systems, with a particular focus on individuals engaged in software development and cryptocurrencyrelated activities.