Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks
Daily Cybersecurity Briefing (13 April 2026)
Published: Loading…
At a Glance
- Adobe released emergency updates for Acrobat Reader CVE-2026-34621, exploited in the wild for months enabling arbitrary code execution.
- Attackers compromised CPUID website hosting CPU-Z and HWMonitor installers, briefly distributing STX RAT through trojanised executable download files.
- Compromised Axios package execution in GitHub Actions exposed OpenAI macOS signing workflow certificates for ChatGPT Desktop and Codex applications.
- Marimo pre-authentication RCE vulnerability is actively exploited for credential theft across exposed Python notebook deployments.
- Webloc geolocation surveillance system tracked hundreds of millions of devices using advertising identifiers and location data across law enforcement deployments.
Summary
Adobe Acrobat Reader CVE-2026-34621 has been patched following confirmation of in-the-wild exploitation enabling remote code execution across Windows and macOS systems. Marimo pre-authentication RCE vulnerability is being actively exploited, with attackers targeting exposed notebook deployments for credential theft and system compromise.
Compromised CPUID software distribution site delivered trojanised CPU-Z and HWMonitor installers, deploying STX RAT through malicious executable files downloads campaign. Compromised Axios version executed within GitHub Actions exposed macOS signing certificates used for ChatGPT Desktop and Codex application notarisation workflows.
Webloc surveillance platform aggregated mobile advertising identifiers and location data to enable large-scale tracking across law enforcement deployments globally operations. International law enforcement action identified over 20,000 cryptocurrency fraud victims across multiple countries and linked millions of dollars in stolen digital assets.
Security analysis uncovered hundreds of Hungarian government credentials exposed across breach datasets affecting defence, finance, and foreign affairs ministries accounts. Separate analysis of supply chain compromises highlighted credential theft across multiple open source tools affecting thousands of organisations worldwide campaigns.
Highlights of the Day
Global Crackdown Identifies 20,000 Crypto Fraud Victims
An international law enforcement operation led by the UK National Crime Agency identified over 20,000 cryptocurrency fraud victims across the United States, United Kingdom, and Canada during “Operation Atlantic”. Authorities disrupted multiple fraud networks and froze more than $12 million in proceeds linked to approval phishing attacks, where victims unknowingly granted wallet access to scammers. Investigators also traced over $45 million in stolen cryptocurrency tied to global fraud schemes, with intelligence shared among agencies including the US Secret Service and Ontario Provincial Police.
Analysis Details Trivy and Axios Supply Chain Compromises
The Register reports that attackers compromised the Trivy vulnerability scanner in March by injecting credential-stealing malware into binaries, GitHub Actions, and container images, enabling theft of CI/CD secrets, SSH keys, and cloud credentials. The analysis states the campaign extended to tools including KICS, LiteLLM, and Telnyx, with researchers estimating credentials from over 10,000 organisations were collected. It also describes a separate Axios incident attributed to a North Korean-linked actor, who used social engineering to compromise a maintainer account and publish trojanised packages that exfiltrated private keys and credentials.
Breach Data Exposes Hungarian Government Emails and Weak Passwords
Bellingcat analysis identified 795 Hungarian government email and password combinations across breach databases, affecting 12 of 13 ministries and exposing accounts linked to defence, foreign affairs, and finance departments. The data includes credentials of military personnel, diplomats, and security officials, with some records containing phone numbers, addresses, dates of birth, and IP information. The investigation also found stealer malware logs indicating 97 government machines were compromised, with recent infections recorded as recently as 2026.
Webloc Surveillance System Tracks Hundreds of Millions via Ad Data
The Citizen Lab reports that Webloc, developed by Cobwebs Technologies and now sold by Penlink, is a geolocation surveillance system that uses data derived from mobile apps and digital advertising to track hundreds of millions of devices globally. The analysis documents deployment by Hungarian domestic intelligence since at least 2022 and confirms use by agencies including ICE, the US military, and multiple law enforcement bodies in the United States and El Salvador National Civil Police. According to leaked contracts and technical documentation, the system processes mobile advertising IDs linked to GPS and Wi-Fi-derived location records, enabling historical and real-time tracking of devices over multi-year periods.
Axios Supply Chain Attack Hits OpenAI macOS Signing Workflow
OpenAI reports that a compromised version of the Axios library (1.14.1) was executed in a GitHub Actions workflow used for macOS application signing on 31 March 2026. The workflow processed signing certificates used for ChatGPT Desktop, Codex, and Atlas, which are required for macOS notarisation and software trust validation. OpenAI rotated and revoked its macOS code signing certificates and rebuilt affected applications after treating the credentials as potentially exposed.
Adobe Fixes Acrobat Zero-Day Used in Ongoing Attacks
Adobe released emergency updates for CVE-2026-34621 affecting Acrobat and Reader on Windows and macOS, addressing a prototype attribute modification flaw enabling arbitrary code execution. The vulnerability carries a CVSS score of 9.6 and has been exploited in the wild since at least November 2025, according to analysis of a malicious PDF sample uploaded to VirusTotal. The issue was discovered by researcher Haifei Li, who reported exploitation involving weaponised PDFs using Russian-language lures and links to Russia’s oil and gas sector.
Daily Coverage