CyberSecBrief

Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks


Daily Cybersecurity Briefing (8 April 2026)

Published: Loading…

At a Glance

  • Threat actors are exploiting CVE-2025-59528, a critical Flowise RCE vulnerability affecting over 12,000 exposed AI agent builder instances worldwide.
  • APT28 has hijacked vulnerable TP-Link and MikroTik routers to redirect Outlook and Office 365 traffic, capturing credentials and OAuth tokens globally.
  • GPUBreach demonstrates GPU Rowhammer attacks on NVIDIA GDDR6 memory can escalate to CPU root privileges and compromise sensitive host systems.
  • Anthropic’s Claude Mythos AI autonomously identified zero-day vulnerabilities in OpenBSD, FFmpeg, and FreeBSD NFS, limiting disclosure through Project Glasswing.
  • EvilTokens leverages AI and automation to conduct device-code phishing at scale, stealing Microsoft account tokens for business email compromise campaigns.
  • CloudSEK researchers found a global traffic brokerage campaign using 300+ trusted brands to funnel victims into scams and account takeover operations.

Summary

Critical vulnerabilities in AI development platforms remain under active exploitation, with CVE-2025-59528 in Flowise’s CustomMCP node affecting over 12,000 exposed instances. Attackers are executing arbitrary code with full Node.js privileges, targeting internet-facing systems across multiple sectors. Patch deployment for version 3.0.6 mitigates the highest-severity risk but widespread exposure persists.

Russian state-linked threat actor APT28 has continued compromising vulnerable MikroTik and TP-Link routers to hijack DNS and DHCP settings. The activity redirected Outlook and Office 365 traffic through attacker-controlled servers, harvesting passwords and OAuth tokens. International law enforcement and private sector partners have disrupted parts of the infrastructure but thousands of devices remain impacted.

GPUBreach demonstrates that GPU Rowhammer attacks on NVIDIA GDDR6 memory can escalate to CPU root privileges. Researchers verified cross-process memory access and kernel-level exploitation, potentially exposing post-quantum cryptography keys and sensitive ML model data. The technique bypasses IOMMU protections and highlights risks in high-performance GPU environments.

Anthropic introduced Claude Mythos, an AI model capable of autonomously identifying zero-day vulnerabilities. Access is restricted through Project Glasswing, with more than 99% of discovered vulnerabilities undisclosed pending mitigation. The model represents an intersection of AI research and security testing, with controlled release for critical software assessment.

AI-assisted phishing campaigns, including EvilTokens, continue targeting organizational accounts at scale. Attackers automate Microsoft device code authentication to steal access tokens, generate realistic business email compromise scenarios, and maintain persistence across victim mailboxes.

Large-scale traffic brokerage campaigns exploit over 300 trusted brands worldwide to funnel users into crypto scams and account takeovers. The infrastructure leverages disposable websites, localized content, and messaging platforms such as WhatsApp and Telegram. Targeted regions include India, South Asia, East and Southern Africa, the Middle East, and Latin America.

Highlights of the Day

Flowise flaw hit in active attacks against exposed AI servers

Attackers are exploiting CVE-2025-59528, a critical remote code execution flaw in Flowise’s CustomMCP node that affects version 3.0.5 and was patched in 3.0.6. The bug stems from unsafe use of the JavaScript Function() constructor when parsing the mcpServerConfig parameter sent to /api/v1/node-load-method/customMCP, allowing arbitrary code execution with full Node.js privileges. VulnCheck said exploitation attempts originated from a single Starlink IP address, while more than 12,000 internet-exposed Flowise instances remain reachable and potentially vulnerable.

EvilTokens uses AI to automate Microsoft BEC fraud

Sekoia said the EvilTokens phishing service uses Microsoft device code phishing to steal access and refresh tokens, then abuse them for mailbox access, Graph API reconnaissance, and persistence. The platform is sold through Telegram bots, offers a built-in Outlook-style webmail panel, and reportedly includes products priced from $600 to $1,500 plus a $500 monthly licence for the phishing kit. Its backend analyses up to 5,000 stolen emails with Groq-hosted Llama models and OpenAI’s gpt-4o-mini, then generates finance-focused attack scenarios and draft business email compromise messages from real threads.

Source: Sekoia.io

Global traffic broker campaign exploits 300+ brands for scams

CloudSEK researchers uncovered a large-scale traffic brokerage infrastructure using over 300 local and international brands across 100+ countries to funnel victims into scams like crypto fraud and account takeovers. The campaign operates thousands of short-lived websites on disposable TLDs, dynamically localising content for holidays, sales, and regional events, and filters traffic to target mobile users via WhatsApp, Telegram, and Messenger. Heavy targeting occurs in India, South Asia, East and Southern Africa, Middle East, and Latin America, while Europe, North America, and East Asia see lower-volume persistent activity exploiting retail and airline brands.

Source: CloudSEK

White House proposes $707M cut to CISA budget

The Trump administration’s FY2027 budget proposal seeks to reduce the Cybersecurity and Infrastructure Security Agency (CISA) funding by $707 million, refocusing the agency on federal network and critical infrastructure protection. The plan includes eliminating programs on school safety, international affairs, and misinformation, reducing the budget to roughly $2 billion, and follows prior staff reductions and resignations at CISA. Acting director Nick Andersen leads the agency, with Sean Plankey renominated for the permanent director role amid ongoing recruitment for over 300 mission-critical positions.

GPUBreach Exploits GPU Rowhammer for Full System Privilege Escalation

GPUBreach demonstrates that targeted Rowhammer attacks on NVIDIA GPU page tables can achieve arbitrary GPU memory read/write and cross-process access. Exploiting memory-safety bugs in the GPU driver, the attack escalates to CPU kernel privileges and spawns a root shell even with IOMMU enabled, bypassing standard DMA protections. Evaluations show the technique can leak post-quantum cryptography keys, manipulate ML model weights stealthily, and compromise sensitive GPU data across time-shared workloads.

Hardcoded Android keys expose Gemini access in popular apps

CloudSEK found 32 hardcoded Google API keys across 22 Android apps with a combined install base above 500 million, and verified that each key could access Gemini API endpoints. The issue stems from previously embedded AIza keys silently gaining Gemini privileges when developers enable the Generative Language API on the same Google Cloud project. Researchers confirmed active data exposure in ELSA Speak, where an exposed key returned stored audio files, metadata, file URIs, and pagination tokens from the Gemini Files API.

Source: CloudSEK

Attackers abuse GitHub and Jira emails for phishing delivery

Cisco Talos said attackers are abusing GitHub commit notifications and Jira invitation workflows to send phishing and scam emails through the platforms’ legitimate mail infrastructure. The messages inherit valid SPF, DKIM and DMARC authentication, with GitHub-themed lures peaking at about 2.89% of Talos’ observed daily noreply@github.com traffic on 17 February 2026. In the GitHub cases, attackers embedded fake billing content in commit summaries and descriptions, while Jira abuse relied on malicious project names, welcome messages and customer invites to impersonate trusted business alerts.

APT28 Hijacks Routers to Steal Outlook Credentials

The UK NCSC says APT28 has exploited vulnerable TP-Link and MikroTik routers since 2024 to overwrite DHCP and DNS settings and redirect traffic through attacker-controlled servers. The hijacked DNS infrastructure selectively redirected Outlook and Office 365 domains, including outlook.office365.com and autodiscover-s.outlook.com, to adversary-in-the-middle systems designed to capture passwords and OAuth tokens. One documented technique used CVE-2023-50224 on TP-Link WR841N routers, allowing attackers to extract router credentials via crafted HTTP GET requests before changing DNS settings.

FrostArmada Campaign Exploits Routers for Global Credential Theft

The Forest Blizzard threat actor leveraged MikroTik and TP-Link routers to modify DNS settings, redirecting authentication traffic to attacker-controlled servers for credential and OAuth token collection. Lumen observed the campaign scale from initial May 2025 activity to over 18,000 moderate-confidence victims worldwide by December 2025, targeting government agencies, third-party IT providers, and email services. Following the UK NCSC’s August 2025 report on Forest Blizzard activity, the actor rapidly adapted its tactics, prompting disruption of the infrastructure in collaboration with Microsoft, the FBI, and DOJ.

Anthropic’s Claude Mythos AI Identifies and Exploits Zero-Day Bugs

Anthropic has unveiled Claude Mythos Preview, a new AI model that it says can identify and exploit zero-day vulnerabilities across major operating systems, web browsers and widely used open-source software. According to Anthropic, the model autonomously discovered vulnerabilities including a 27-year-old OpenBSD flaw, a 16-year-old FFmpeg bug and a FreeBSD NFS remote code execution issue tracked as CVE-2026-4747. The company said it is limiting access through Project Glasswing, a programme involving firms including Microsoft, Cisco and CrowdStrike, while more than 99% of discovered vulnerabilities remain undisclosed pending patching.

Daily Coverage

Developments
Flowise RceApt28 Router HijacksGpubreach Gpu ExploitClaude Mythos Zero-Days
Vulnerabilities
CVE-2026-31790CVE-2026-2673CVE-2026-28386CVE-2026-34078CVE-2026-34079CVE-2026-23226CVE-2025-59528Flowise = 3.0.5 (Critical)CVE-2026-4747CVE-2023-50224Tl-Wr841N_Firmware 3.16.9 (Medium)CVE-2025-58434Flowise 3.0.6 (Critical)
Threat Groups
APT28[Also known as: Forest Blizzard, Fancy Bear, Pawn Storm] APT28 is a threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) 85th Main Special Service Center (GTsSS) military unit 26165. This group has been active since at least 2004. APT28 reportedly compromised the Hillary Clinton campaign, the Democratic National Committee, and the Democratic Congressional Campaign Committee in 2016 in an attempt to interfere with the U. S. presidential election. In 2018, the US indicted five GRU Unit 26165 officers associated with APT28 for cyber operations (including closeaccess operations) conducted between 2014 and 2018 against the World AntiDoping Agency (WADA), the US AntiDoping Agency, a US nuclear facility, the Organization for the Prohibition of Chemical Weapons (OPCW), the Spiez Swiss Chemicals Laboratory, and other organizations. Some of these were conducted with the assistance of GRU Unit 74455, which is also referred to as Sandworm Team.Contagious InterviewContagious Interview is a North Korea–aligned threat group active since 2023. The group conducts both cyberespionage and financially motivated operations, including the theft of cryptocurrency and user credentials. Contagious Interview targets Windows, Linux, and macOS systems, with a particular focus on individuals engaged in software development and cryptocurrencyrelated activities.