Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks
Daily Cybersecurity Briefing (7 April 2026)
Published: Loading…
At a Glance
- Storm-1175 conducts high-tempo Medusa ransomware campaigns, exploiting zero-days and web-facing flaws, moving from initial access to data theft and encryption within 24 hours.
- Germany’s BKA identified Daniil Shchukin, alias UNKN, as the leader of GandCrab and REvil, responsible for at least 130 attacks from 2019 to 2021.
- Fortinet released an emergency hotfix for CVE-2026-35616 in FortiClient EMS, patched against unauthenticated remote code execution actively exploited in the wild.
- Google DeepMind researchers mapped six web-based AI agent attack classes, enabling manipulation, data theft, unauthorised transactions, and misinformation delivery via web content.
- Progress ShareFile SZC 5.x vulnerabilities CVE-2026-2699 and CVE-2026-2701 allow unauthenticated pre-authentication remote code execution through chained administrative and file upload flaws.
- Kubernetes attackers exploited service account tokens, including CVE-2025-55182 React2Shell, stealing credentials and pivoting into cloud backend and financial infrastructure.
Summary
Storm-1175 has executed high-tempo Medusa ransomware campaigns targeting web-facing systems. The group leverages zero-day and n-day vulnerabilities to move from initial access to data exfiltration and encryption in less than 24 hours.
Germany’s Federal Criminal Police identified 31-year-old Daniil Shchukin, known as UNKN, as the leader of the GandCrab and REvil ransomware groups. Shchukin is linked to at least 130 attacks between 2019 and 2021, resulting in over €35 million in economic damage.
Fortinet released a critical emergency hotfix for FortiClient EMS to address CVE-2026-35616. The flaw allows unauthenticated remote code execution and had been actively exploited in federal and enterprise environments.
Google DeepMind detailed six classes of web-based attacks against autonomous AI agents. These attacks enable manipulation, data theft, unauthorised transactions, and misinformation via web content elements such as scripts, metadata, and images.
Progress ShareFile SZC 5.x contains vulnerabilities CVE-2026-2699 and CVE-2026-2701, permitting unauthenticated remote code execution by chaining administrative access and arbitrary file uploads. Fixed versions 5.12.4 and above are available.
Kubernetes environments saw a surge in service account token theft, including exploitation of React2Shell (CVE-2025-55182). Threat actors leveraged stolen tokens to pivot into backend cloud systems, exfiltrating credentials and deploying backdoors or cryptominers.
Cybersecurity activity in cloud and enterprise environments continues to show sophisticated exploitation of software flaws. Organisations are advised to prioritise patches, monitor exposed systems, and audit token and administrative access.
Highlights of the Day
Microsoft Links Medusa Attacks to Fast-Moving Storm-1175
Microsoft said Storm-1175 is running high-tempo Medusa ransomware intrusions by exploiting vulnerable internet-facing systems, often moving from initial access to data theft and encryption within 24 hours to six days. Since 2023, the group has exploited more than 16 flaws across Exchange, Ivanti, ScreenConnect, TeamCity, CrushFTP, GoAnywhere, SmarterMail, BeyondTrust and SAP NetWeaver, including zero-days used before public disclosure. Post-compromise activity included web shells, new administrator accounts, Cloudflare Tunnels, RMM tools, LSASS credential dumping, Veeam password recovery, Rclone exfiltration, and PDQ Deployer or Group Policy for ransomware deployment.
Germany Names Alleged REvil and GandCrab Leader
Germany’s Federal Criminal Police identified 31-year-old Russian Daniil Maksimovich Shchukin as “UNKN”, alleging he led the GandCrab and REvil ransomware groups and helped carry out at least 130 attacks in Germany between 2019 and 2021. The BKA said Shchukin and alleged associate Anatoly Sergeevitsch Kravchuk extorted nearly €2 million across roughly two dozen incidents that caused more than €35 million in economic damage. US court filings from 2023 also linked Shchukin to cryptocurrency proceeds from REvil, while German authorities said he is believed to be residing in Krasnodar, Russia.
Google DeepMind Maps Web Traps for AI Agents
Google DeepMind researchers described “AI Agent Traps”, a web-based attack class that uses malicious content to manipulate autonomous agents into actions such as data theft, unauthorised transactions, and misinformation delivery. Their framework defines six attack categories, including hidden prompt injection, semantic manipulation, memory poisoning, behavioural hijacking, multi-agent systemic failure, and human-in-the-loop abuse. The paper says traps can be embedded in HTML comments, metadata, JavaScript, images, or external resources, exploiting gaps between human-visible pages and machine-parsed content.
Critical Pre-Auth RCE Found in Progress ShareFile SZC 5.x
Two high-severity vulnerabilities, CVE-2026-2699 and CVE-2026-2701, affect Progress ShareFile Storage Zones Controller 5.x, allowing unauthenticated actors to access administrative functions and upload arbitrary files to web-accessible paths. Chaining these flaws enables pre-authentication remote code execution on systems running versions 5.12.3 or below, potentially exposing sensitive configurations and executable deployment. Progress ShareFile released fixes on 10 March 2026, upgrading affected systems to v5.12.4 or any v6 version, with no active exploitation observed at the time of reporting.
Kubernetes Token Theft Surges as Attackers Pivot Into Cloud
Palo Alto Networks said Kubernetes-related threat activity involving service account token theft rose 282% year-on-year, with suspicious token theft observed in 22% of cloud environments during 2025. Unit 42 described one mid-2025 intrusion at a cryptocurrency exchange where attackers deployed a malicious pod, stole a high-privilege Kubernetes token, then pivoted into backend cloud systems and financial infrastructure. The report also said attackers exploited React2Shell (CVE-2025-55182) within two days of disclosure, using code execution in containers to harvest tokens, exfiltrate cloud credentials, and deploy backdoors or cryptominers.
Daily Coverage