Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks
Daily Cybersecurity Briefing (16 April 2026)
Published: Loading…
At a Glance
- Model Context Protocol flaw enables widespread AI supply chain remote code execution affecting LangChain and LiteLLM systems.
- Nginx UI authentication bypass vulnerability CVE-2026-33032 is being actively exploited allowing unauthenticated attackers full server takeover via MCP interface.
- Signed adware update mechanism compromise exposed more than 20,000 Windows systems to arbitrary payload deployment and antivirus disabling worldwide.
- Microsoft awarded 2.3 million dollars after Zero Day Quest 2026 identified over 80 cloud and AI vulnerabilities globally.
- NIST will restrict CVE enrichment in NVD, prioritising exploited vulnerabilities and critical software amid rapidly increasing submission volumes in 2026.
Summary
AI supply chain vulnerabilities expanded through Model Context Protocol flaws enabling remote code execution across automation frameworks and widely used developer tooling ecosystems. GitHub-integrated AI agents were hijacked through prompt injection attacks that exposed credentials including API keys and repository tokens via comments and workflow commands.
Nginx UI authentication bypass vulnerability CVE-2026-33032 is actively exploited, enabling unauthenticated attackers to seize control of exposed server management interfaces. Signed software supply chain compromise distributed adware that disabled endpoint protection and affected tens of thousands of Windows systems across multiple sectors.
Microsoft awarded 2.3 million dollars during Zero Day Quest 2026 after identifying extensive cloud and AI vulnerabilities across global infrastructure. NIST announced restrictions on CVE enrichment, prioritising exploited vulnerabilities while leaving many records without severity scoring amid rapidly increasing submissions.
MiningDropper Android malware campaign used multi-stage payloads with encryption and obfuscation to deliver infostealers, banking trojans and remote access tools globally. Separately, XWorm malware spread through phishing-driven worm infections targeting operational technology environments via resume themed emails across multiple regions.
Highlights of the Day
Prompt Injection Hijacks GitHub AI Agents to Steal Credentials
Researchers from Johns Hopkins University demonstrated a “comment and control” prompt injection attack affecting Anthropic Claude Code, Google Gemini CLI Action, and GitHub Copilot Agent, exploiting GitHub pull request titles, issue bodies, and comments as attack vectors. The attacks trick agents into executing commands such as whoami or ps auxeww, exposing sensitive environment variables including ANTHROPIC_API_KEY, GEMINI_API_KEY, GITHUB_TOKEN, and other repository secrets through pull request comments, issue posts, or committed files. The Copilot variant bypassed environment filtering, secret scanning, and network firewall protections by embedding hidden instructions in HTML comments and exfiltrating base64-encoded credentials via GitHub commits.
MCP Protocol Flaw Enables Widespread AI Agent Remote Code Execution
OX Security researchers identified a systemic vulnerability in Anthropic’s Model Context Protocol that enables arbitrary command execution across implementations in Python, TypeScript, Java, and Rust, exposing API keys, databases, and chat histories. The flaw affects a supply chain with over 150 million downloads, 7,000 exposed servers, and up to 200,000 instances, with successful exploitation demonstrated on platforms including LiteLLM, LangChain, and IBM LangFlow. Researchers documented four attack vectors including unauthenticated UI injection, prompt injection, and malicious registry poisoning, and disclosed more than 10 critical CVEs affecting tools such as Windsurf, DocsGPT, and Langchain-Chatchat.
MiningDropper Android Malware Campaign Spreads Modular Multi-Stage Payloads Globally
Cyble researchers identified a surge in MiningDropper, a modular Android malware framework using multi-stage payload delivery with XOR obfuscation, AES-encrypted staging, dynamic DEX loading, and anti-emulation techniques to evade detection. The malware is distributed via phishing sites, social media, and fraudulent apps, including trojanised LumoLight builds, delivering payloads such as infostealers, banking trojans, cryptocurrency miners, and the BTMOB RAT across India, Europe, Asia, and Latin America. Analysis of over 1,500 samples shows more than 50% have low antivirus detection rates, with campaigns leveraging fake Google Play updates and split-APK installers to deploy credential theft, remote control, and data exfiltration capabilities.
Phishing Worm Campaign Targets Industrial Systems with XWorm Malware
Kaspersky ICS CERT reported that 19.7% of industrial control system computers blocked malicious objects in Q4 2025, with a global surge in worm infections driven by Backdoor.MSIL.XWorm distributed via phishing emails. The campaign used “Curriculum Vitae-Catalina” themed emails carrying executable files disguised as resumes, targeting HR-related roles and spreading in waves across Europe, Russia, the Americas, and other regions. Overall, threats originated primarily from internet sources, email clients, and removable media, with over 10,000 malware families detected and increased activity from worms and executable-based crypto miners.
Nginx-UI MCP Flaw Enables Unauthenticated Server Takeover
Pluto Security disclosed CVE-2026-33032, a critical CVSS 9.8 vulnerability in nginx-ui where the /mcp_message endpoint lacks authentication, exposing 12 MCP tools that allow configuration changes and server control. Attackers on the same network can send a single unauthenticated request to inject malicious nginx configurations, intercept traffic, exfiltrate data, and trigger automatic server reloads. The flaw affects versions up to 2.3.3, impacts over 2,600 exposed instances, and has been observed in active exploitation campaigns tracked by VulnCheck and Recorded Future.
McGraw Hill Data Leak Linked to Salesforce Misconfiguration
McGraw Hill disclosed unauthorised access to a limited set of non-sensitive data from a Salesforce-hosted webpage, attributing the incident to a broader misconfiguration affecting multiple organisations. The breach follows claims by the ShinyHunters group of stealing 45 million Salesforce records, with McGraw Hill and other companies listed on its leak site. The company confirmed no access to its Salesforce accounts, internal systems, customer databases, or sensitive data such as financial information or student records.
Signed PUP Opens 25,000 Systems to Supply Chain Takeover
Huntress identified signed adware from Dragon Boss Solutions deploying MSI and PowerShell payloads that disable antivirus tools, establish WMI persistence, and run with SYSTEM privileges across infected Windows endpoints. Researchers discovered the software’s update mechanism relied on unregistered domains, allowing any attacker to register them and deliver arbitrary payloads to affected systems, effectively creating a supply chain compromise vector. Sinkholing one such domain revealed 23,565 infected hosts across 124 countries, including networks in universities, government entities, and critical infrastructure environments.
Microsoft Awards $2.3M for 80 Cloud, AI Vulnerabilities
Microsoft’s Zero Day Quest 2026 programme awarded $2.3 million after researchers from over 20 countries submitted nearly 700 reports, identifying more than 80 high-impact vulnerabilities across cloud and AI services. Findings included weaknesses in identity controls, cross-tenant isolation flaws, credential exposure risks, and SSRF chains that could enable access beyond authorised environments when combined with other vulnerabilities.
NIST Limits CVE Enrichment Amid Surge in Submissions
NIST announced it will restrict enrichment of CVE records in the National Vulnerability Database, citing a sharp rise in submissions, with early 2026 volumes nearly one-third higher than the previous year. The agency will prioritise vulnerabilities listed in CISA’s Known Exploited Vulnerabilities catalogue and critical software, while others will remain without added metadata such as severity scores. NIST also confirmed it cannot clear a backlog of older CVEs and will shift many pre-March 2026 entries to an unscheduled status.
Daily Coverage