CyberSecBrief

Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks


Daily Cybersecurity Briefing (13 April 2026)

Published: Loading…

At a Glance

  • Adobe released emergency updates for Acrobat Reader CVE-2026-34621, exploited in the wild for months enabling arbitrary code execution.
  • Attackers compromised CPUID website hosting CPU-Z and HWMonitor installers, briefly distributing STX RAT through trojanised executable download files.
  • Compromised Axios package execution in GitHub Actions exposed OpenAI macOS signing workflow certificates for ChatGPT Desktop and Codex applications.
  • Marimo pre-authentication RCE vulnerability is actively exploited for credential theft across exposed Python notebook deployments.
  • Webloc geolocation surveillance system tracked hundreds of millions of devices using advertising identifiers and location data across law enforcement deployments.

Summary

Adobe Acrobat Reader CVE-2026-34621 has been patched following confirmation of in-the-wild exploitation enabling remote code execution across Windows and macOS systems. Marimo pre-authentication RCE vulnerability is being actively exploited, with attackers targeting exposed notebook deployments for credential theft and system compromise.

Compromised CPUID software distribution site delivered trojanised CPU-Z and HWMonitor installers, deploying STX RAT through malicious executable files downloads campaign. Compromised Axios version executed within GitHub Actions exposed macOS signing certificates used for ChatGPT Desktop and Codex application notarisation workflows.

Webloc surveillance platform aggregated mobile advertising identifiers and location data to enable large-scale tracking across law enforcement deployments globally operations. International law enforcement action identified over 20,000 cryptocurrency fraud victims across multiple countries and linked millions of dollars in stolen digital assets.

Security analysis uncovered hundreds of Hungarian government credentials exposed across breach datasets affecting defence, finance, and foreign affairs ministries accounts. Separate analysis of supply chain compromises highlighted credential theft across multiple open source tools affecting thousands of organisations worldwide campaigns.

Highlights of the Day

Global Crackdown Identifies 20,000 Crypto Fraud Victims

An international law enforcement operation led by the UK National Crime Agency identified over 20,000 cryptocurrency fraud victims across the United States, United Kingdom, and Canada during “Operation Atlantic”. Authorities disrupted multiple fraud networks and froze more than $12 million in proceeds linked to approval phishing attacks, where victims unknowingly granted wallet access to scammers. Investigators also traced over $45 million in stolen cryptocurrency tied to global fraud schemes, with intelligence shared among agencies including the US Secret Service and Ontario Provincial Police.

Analysis Details Trivy and Axios Supply Chain Compromises

The Register reports that attackers compromised the Trivy vulnerability scanner in March by injecting credential-stealing malware into binaries, GitHub Actions, and container images, enabling theft of CI/CD secrets, SSH keys, and cloud credentials. The analysis states the campaign extended to tools including KICS, LiteLLM, and Telnyx, with researchers estimating credentials from over 10,000 organisations were collected. It also describes a separate Axios incident attributed to a North Korean-linked actor, who used social engineering to compromise a maintainer account and publish trojanised packages that exfiltrated private keys and credentials.

Breach Data Exposes Hungarian Government Emails and Weak Passwords

Bellingcat analysis identified 795 Hungarian government email and password combinations across breach databases, affecting 12 of 13 ministries and exposing accounts linked to defence, foreign affairs, and finance departments. The data includes credentials of military personnel, diplomats, and security officials, with some records containing phone numbers, addresses, dates of birth, and IP information. The investigation also found stealer malware logs indicating 97 government machines were compromised, with recent infections recorded as recently as 2026.

Source: Bellingcat

Webloc Surveillance System Tracks Hundreds of Millions via Ad Data

The Citizen Lab reports that Webloc, developed by Cobwebs Technologies and now sold by Penlink, is a geolocation surveillance system that uses data derived from mobile apps and digital advertising to track hundreds of millions of devices globally. The analysis documents deployment by Hungarian domestic intelligence since at least 2022 and confirms use by agencies including ICE, the US military, and multiple law enforcement bodies in the United States and El Salvador National Civil Police. According to leaked contracts and technical documentation, the system processes mobile advertising IDs linked to GPS and Wi-Fi-derived location records, enabling historical and real-time tracking of devices over multi-year periods.

Axios Supply Chain Attack Hits OpenAI macOS Signing Workflow

OpenAI reports that a compromised version of the Axios library (1.14.1) was executed in a GitHub Actions workflow used for macOS application signing on 31 March 2026. The workflow processed signing certificates used for ChatGPT Desktop, Codex, and Atlas, which are required for macOS notarisation and software trust validation. OpenAI rotated and revoked its macOS code signing certificates and rebuilt affected applications after treating the credentials as potentially exposed.

Source: Socket

Adobe Fixes Acrobat Zero-Day Used in Ongoing Attacks

Adobe released emergency updates for CVE-2026-34621 affecting Acrobat and Reader on Windows and macOS, addressing a prototype attribute modification flaw enabling arbitrary code execution. The vulnerability carries a CVSS score of 9.6 and has been exploited in the wild since at least November 2025, according to analysis of a malicious PDF sample uploaded to VirusTotal. The issue was discovered by researcher Haifei Li, who reported exploitation involving weaponised PDFs using Russian-language lures and links to Russia’s oil and gas sector.

Daily Coverage

Developments
Adobe Rce ExploitCpuid Trojan BreachAxios Supply ChainMarimo Rce Exploit
Vulnerabilities
CVE-2026-34621Acrobat Reader (High)CVE-2026-0740Ninja Forms - File Uploads (Critical)CVE-2026-5173Gitlab 16.9.6 (High)CVE-2026-33439Openam < 16.0.6 (Critical)
Threat Groups
ScarCruft[Also known as: APT37] APT37 is a North Korean statesponsored cyber espionage group that has been active since at least 2012. The group has targeted victims primarily in South Korea, but also in Japan, Vietnam, Russia, Nepal, China, India, Romania, Kuwait, and other parts of the Middle East. APT37 has also been linked to the following campaigns between 20162018: Operation Daybreak, Operation Erebus, Golden Time, Evil New Year, Are you Happy?, FreeMilk, North Korean Human Rights, and Evil New Year 2018. North Korean group definitions are known to have significant overlap, and some security researchers report all North Korean statesponsored cyber activity under the name Lazarus Group instead of tracking clusters or subgroups.