Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks
Daily Cybersecurity Briefing (15 April 2026)
Published: Loading…
At a Glance
- Microsoft patched 167 vulnerabilities including exploited SharePoint flaw CVE-2026-32201 enabling spoofing attacks and Windows Defender BlueHammer privilege escalation vulnerability.
- CISA added seven actively exploited vulnerabilities affecting Microsoft Windows, Exchange, Adobe Acrobat, and Fortinet products to its Known Exploited Vulnerabilities catalogue.
- ShowDoc CVE-2025-0520 unrestricted file upload vulnerability is actively exploited to achieve remote code execution on unpatched document management servers.
- Mirax Android RAT campaigns reached over 220,000 users via Meta ads, turning infected devices into SOCKS5 proxies with full remote access capabilities.
- 108 malicious Chrome extensions connected to a single C2 infrastructure stole Google and Telegram data while injecting ads and arbitrary JavaScript into web sessions.
- Obsidian plugins were abused in social engineering attacks to deploy PhantomPulse RAT using blockchain-based command-and-control and cross-platform execution techniques.
Summary
Microsoft released April 2026 Patch Tuesday updates addressing 167 vulnerabilities, including eight critical flaws and two zero-days affecting widely deployed enterprise software components. The actively exploited CVE-2026-32201 SharePoint vulnerability enables spoofing attacks that manipulate trusted content, while the BlueHammer flaw allows privilege escalation within Windows Defender.
CISA expanded its Known Exploited Vulnerabilities catalogue with seven additional flaws affecting Windows, Exchange Server, Adobe Acrobat, and Fortinet products confirmed under active exploitation. These vulnerabilities include SQL injection, insecure deserialisation, use-after-free, and prototype pollution weaknesses enabling unauthorised access, remote execution, and privilege escalation.
Active exploitation activity also targets exposed services, including the ShowDoc CVE-2025-0520 vulnerability that enables unrestricted file upload and remote code execution on unpatched servers. Two command injection flaws in PHP Composer allow arbitrary command execution through crafted package metadata, affecting dependency installations from compromised repositories.
Malware campaigns continue to leverage diverse delivery methods, including PhantomPulse RAT distributed through malicious Obsidian plugins executing payloads via PowerShell and AppleScript across Windows and macOS systems. The Mirax Android RAT spreads through Meta advertising campaigns, converting infected devices into SOCKS5 proxies while enabling full remote control and data access.
Browser-based threats remain prevalent, with over 100 malicious Chrome extensions stealing authentication tokens, injecting scripts, and exfiltrating Google and Telegram data via shared command-and-control infrastructure. The Omnistealer malware uses blockchain transactions on networks such as TRON and Binance Smart Chain to host persistent payloads resistant to takedown efforts.
Ransomware and cybercrime operations show continued evolution, as JanaWare ransomware targets Turkish users through Adwind RAT infections that disable defences and deploy encryption modules via Tor infrastructure. The Triad Nexus network maintains large-scale fraud operations exceeding $200 million by laundering infrastructure and using geofencing to evade investigative tracking.
Data breach disclosures include incidents affecting Basic-Fit, exposing personal and financial data of up to one million members, and Booking.com, where attackers accessed reservation details through undisclosed systems. Additional breaches involving RCI Hospitality and McGraw-Hill highlight vulnerabilities such as IDOR flaws and Salesforce misconfigurations enabling unauthorised data access.
Highlights of the Day
CISA Adds Seven Actively Exploited Vulnerabilities to KEV List
CISA added seven vulnerabilities to its Known Exploited Vulnerabilities catalogue, including flaws in Microsoft Windows, Exchange Server, Visual Basic for Applications, Adobe Acrobat, and Fortinet products, all confirmed as actively exploited. The listed issues include insecure library loading, use-after-free, deserialisation of untrusted data, out-of-bounds read, link following, SQL injection, and prototype pollution vulnerabilities.
Obsidian Plugins Abused to Deliver PhantomPulse RAT Malware
Elastic Security Labs identified a social engineering campaign targeting financial and cryptocurrency sectors that abuses Obsidian note-taking app plugins to execute malicious code when victims open attacker-controlled synced vaults. The attack chain uses trojanised Shell Commands and Hider plugins to launch PowerShell or AppleScript payloads, deploying the PHANTOMPULL loader and PHANTOMPULSE RAT with in-memory execution, AES-256-CBC decryption, and anti-analysis techniques. PHANTOMPULSE establishes command-and-control via blockchain transaction data on Ethereum networks, supports process injection, keylogging, screenshot capture, and uses fallback infrastructure including Telegram-based resolution on macOS systems.
Claude Mythos AI Executes Multi-Stage Network Attacks in Tests
The UK AI Security Institute found Anthropic’s Claude Mythos Preview can autonomously discover and exploit vulnerabilities and execute multi-stage cyber attacks on simulated networks with provided access and direction. In controlled testing, the model completed a 32-step corporate network attack simulation end-to-end in three out of ten attempts and achieved a 73% success rate on expert-level capture-the-flag challenges. The evaluation showed the model using chained attack techniques across systems, though testing environments lacked active defences and real-world detection constraints.
PHP Composer Fixes Perforce Command Injection Vulnerabilities
Composer versions prior to 2.9.6 and 2.2.27 contain two command injection vulnerabilities, CVE-2026-40261 and CVE-2026-40176, in the Perforce VCS driver caused by improper escaping of user-supplied input in shell command construction. The flaws allow attackers to execute arbitrary commands via malicious composer.json configuration parameters or crafted package metadata, including source references and URLs, even without Perforce installed. Packagist disabled Perforce metadata publishing and found no exploitation attempts, while the vulnerabilities affect dependency installation from compromised repositories using source-based installs.
Axios CVE Rated Critical but Blocked by Node Runtime
CVE-2026-40175 in Axios involves a prototype pollution gadget chain enabling CRLF header injection, request smuggling, SSRF, and potential AWS metadata access under specific conditions. In standard Node.js, Bun, and Deno environments, the exploit chain fails because runtimes reject malformed headers containing CRLF characters before requests are sent. Exploitation would require non-standard configurations such as custom Axios adapters that bypass built-in HTTP clients and header validation mechanisms.
JanaWare Ransomware Targets Turkey Using Adwind RAT Campaign
Acronis researchers identified a ransomware campaign delivering JanaWare via a customised Adwind Java RAT, targeting Turkish users through phishing emails that distribute malicious JAR files executed with javaw.exe. The malware uses geofencing checks based on system locale and IP location, disables security controls including Microsoft Defender and Volume Shadow Copies, then downloads a Tor-based ransomware module to encrypt files using AES. The operation employs polymorphic JAR modification, obfuscation tools such as Stringer and Allatori, and command-and-control infrastructure with hardcoded domains, ports, and authentication parameters active since at least 2020.
Microsoft Patches 167 Flaws Including Exploited SharePoint Zero-Day
Microsoft’s April 2026 Patch Tuesday resolves 167 vulnerabilities, including eight critical issues, with seven remote code execution flaws and two zero-days, one publicly disclosed and one actively exploited. The exploited zero-day, CVE-2026-32201, is a SharePoint Server spoofing flaw enabling unauthorised attackers to manipulate trusted content and access sensitive information over a network. Microsoft also fixed a Windows Defender privilege escalation flaw known as BlueHammer, alongside multiple Office vulnerabilities allowing remote code execution via malicious documents or preview pane exploitation.
Daily Coverage