CyberSecBrief

Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks


Daily Cybersecurity Briefing (16 April 2026)

Published: Loading…

At a Glance

  • Model Context Protocol flaw enables widespread AI supply chain remote code execution affecting LangChain and LiteLLM systems.
  • Nginx UI authentication bypass vulnerability CVE-2026-33032 is being actively exploited allowing unauthenticated attackers full server takeover via MCP interface.
  • Signed adware update mechanism compromise exposed more than 20,000 Windows systems to arbitrary payload deployment and antivirus disabling worldwide.
  • Microsoft awarded 2.3 million dollars after Zero Day Quest 2026 identified over 80 cloud and AI vulnerabilities globally.
  • NIST will restrict CVE enrichment in NVD, prioritising exploited vulnerabilities and critical software amid rapidly increasing submission volumes in 2026.

Summary

AI supply chain vulnerabilities expanded through Model Context Protocol flaws enabling remote code execution across automation frameworks and widely used developer tooling ecosystems. GitHub-integrated AI agents were hijacked through prompt injection attacks that exposed credentials including API keys and repository tokens via comments and workflow commands.

Nginx UI authentication bypass vulnerability CVE-2026-33032 is actively exploited, enabling unauthenticated attackers to seize control of exposed server management interfaces. Signed software supply chain compromise distributed adware that disabled endpoint protection and affected tens of thousands of Windows systems across multiple sectors.

Microsoft awarded 2.3 million dollars during Zero Day Quest 2026 after identifying extensive cloud and AI vulnerabilities across global infrastructure. NIST announced restrictions on CVE enrichment, prioritising exploited vulnerabilities while leaving many records without severity scoring amid rapidly increasing submissions.

MiningDropper Android malware campaign used multi-stage payloads with encryption and obfuscation to deliver infostealers, banking trojans and remote access tools globally. Separately, XWorm malware spread through phishing-driven worm infections targeting operational technology environments via resume themed emails across multiple regions.

Highlights of the Day

Prompt Injection Hijacks GitHub AI Agents to Steal Credentials

Researchers from Johns Hopkins University demonstrated a “comment and control” prompt injection attack affecting Anthropic Claude Code, Google Gemini CLI Action, and GitHub Copilot Agent, exploiting GitHub pull request titles, issue bodies, and comments as attack vectors. The attacks trick agents into executing commands such as whoami or ps auxeww, exposing sensitive environment variables including ANTHROPIC_API_KEY, GEMINI_API_KEY, GITHUB_TOKEN, and other repository secrets through pull request comments, issue posts, or committed files. The Copilot variant bypassed environment filtering, secret scanning, and network firewall protections by embedding hidden instructions in HTML comments and exfiltrating base64-encoded credentials via GitHub commits.

MCP Protocol Flaw Enables Widespread AI Agent Remote Code Execution

OX Security researchers identified a systemic vulnerability in Anthropic’s Model Context Protocol that enables arbitrary command execution across implementations in Python, TypeScript, Java, and Rust, exposing API keys, databases, and chat histories. The flaw affects a supply chain with over 150 million downloads, 7,000 exposed servers, and up to 200,000 instances, with successful exploitation demonstrated on platforms including LiteLLM, LangChain, and IBM LangFlow. Researchers documented four attack vectors including unauthenticated UI injection, prompt injection, and malicious registry poisoning, and disclosed more than 10 critical CVEs affecting tools such as Windsurf, DocsGPT, and Langchain-Chatchat.

MiningDropper Android Malware Campaign Spreads Modular Multi-Stage Payloads Globally

Cyble researchers identified a surge in MiningDropper, a modular Android malware framework using multi-stage payload delivery with XOR obfuscation, AES-encrypted staging, dynamic DEX loading, and anti-emulation techniques to evade detection. The malware is distributed via phishing sites, social media, and fraudulent apps, including trojanised LumoLight builds, delivering payloads such as infostealers, banking trojans, cryptocurrency miners, and the BTMOB RAT across India, Europe, Asia, and Latin America. Analysis of over 1,500 samples shows more than 50% have low antivirus detection rates, with campaigns leveraging fake Google Play updates and split-APK installers to deploy credential theft, remote control, and data exfiltration capabilities.

Source: Cyble

Phishing Worm Campaign Targets Industrial Systems with XWorm Malware

Kaspersky ICS CERT reported that 19.7% of industrial control system computers blocked malicious objects in Q4 2025, with a global surge in worm infections driven by Backdoor.MSIL.XWorm distributed via phishing emails. The campaign used “Curriculum Vitae-Catalina” themed emails carrying executable files disguised as resumes, targeting HR-related roles and spreading in waves across Europe, Russia, the Americas, and other regions. Overall, threats originated primarily from internet sources, email clients, and removable media, with over 10,000 malware families detected and increased activity from worms and executable-based crypto miners.

Nginx-UI MCP Flaw Enables Unauthenticated Server Takeover

Pluto Security disclosed CVE-2026-33032, a critical CVSS 9.8 vulnerability in nginx-ui where the /mcp_message endpoint lacks authentication, exposing 12 MCP tools that allow configuration changes and server control. Attackers on the same network can send a single unauthenticated request to inject malicious nginx configurations, intercept traffic, exfiltrate data, and trigger automatic server reloads. The flaw affects versions up to 2.3.3, impacts over 2,600 exposed instances, and has been observed in active exploitation campaigns tracked by VulnCheck and Recorded Future.

McGraw Hill Data Leak Linked to Salesforce Misconfiguration

McGraw Hill disclosed unauthorised access to a limited set of non-sensitive data from a Salesforce-hosted webpage, attributing the incident to a broader misconfiguration affecting multiple organisations. The breach follows claims by the ShinyHunters group of stealing 45 million Salesforce records, with McGraw Hill and other companies listed on its leak site. The company confirmed no access to its Salesforce accounts, internal systems, customer databases, or sensitive data such as financial information or student records.

Signed PUP Opens 25,000 Systems to Supply Chain Takeover

Huntress identified signed adware from Dragon Boss Solutions deploying MSI and PowerShell payloads that disable antivirus tools, establish WMI persistence, and run with SYSTEM privileges across infected Windows endpoints. Researchers discovered the software’s update mechanism relied on unregistered domains, allowing any attacker to register them and deliver arbitrary payloads to affected systems, effectively creating a supply chain compromise vector. Sinkholing one such domain revealed 23,565 infected hosts across 124 countries, including networks in universities, government entities, and critical infrastructure environments.

Source: Huntress

Microsoft Awards $2.3M for 80 Cloud, AI Vulnerabilities

Microsoft’s Zero Day Quest 2026 programme awarded $2.3 million after researchers from over 20 countries submitted nearly 700 reports, identifying more than 80 high-impact vulnerabilities across cloud and AI services. Findings included weaknesses in identity controls, cross-tenant isolation flaws, credential exposure risks, and SSRF chains that could enable access beyond authorised environments when combined with other vulnerabilities.

NIST Limits CVE Enrichment Amid Surge in Submissions

NIST announced it will restrict enrichment of CVE records in the National Vulnerability Database, citing a sharp rise in submissions, with early 2026 volumes nearly one-third higher than the previous year. The agency will prioritise vulnerabilities listed in CISA’s Known Exploited Vulnerabilities catalogue and critical software, while others will remain without added metadata such as severity scores. NIST also confirmed it cannot clear a backlog of older CVEs and will shift many pre-March 2026 entries to an unscheduled status.

Daily Coverage

Developments
Microsoft Bounty AwardsCVE Enrichment LimitsMcp Supply Chain RceNginx Ui Takeover
Vulnerabilities
CVE-2026-32213CVE-2026-20184CVE-2026-39813Fortisandbox 5.0.0 (Critical)CVE-2026-39808Fortisandbox 4.4.0 (Critical)CVE-2026-40478CVE-2026-3779CVE-2023-33538CVE-2026-33032Nginx-Ui <= 2.3.5 (Critical)
Threat Groups
CHROMIUMEarth Lusca is a suspected Chinabased cyber espionage group that has been active since at least April 2019. Earth Lusca has targeted organizations in Australia, China, Hong Kong, Mongolia, Nepal, the Philippines, Taiwan, Thailand, Vietnam, the United Arab Emirates, Nigeria, Germany, France, and the United States. Targets included government institutions, news media outlets, gambling companies, educational institutions, COVID19 research organizations, telecommunications companies, religious movements banned in China, and cryptocurrency trading platforms; security researchers assess some Earth Lusca operations may be financially motivated. Earth Lusca has used malware commonly used by other Chinese threat groups, including APT41 and the Winnti Group cluster, however security researchers assess Earth Lusca's techniques and infrastructure are separate.APT28APT28 is a threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) 85th Main Special Service Center (GTsSS) military unit 26165. This group has been active since at least 2004. APT28 reportedly compromised the Hillary Clinton campaign, the Democratic National Committee, and the Democratic Congressional Campaign Committee in 2016 in an attempt to interfere with the U. S. presidential election. In 2018, the US indicted five GRU Unit 26165 officers associated with APT28 for cyber operations (including closeaccess operations) conducted between 2014 and 2018 against the World AntiDoping Agency (WADA), the US AntiDoping Agency, a US nuclear facility, the Organization for the Prohibition of Chemical Weapons (OPCW), the Spiez Swiss Chemicals Laboratory, and other organizations. Some of these were conducted with the assistance of GRU Unit 74455, which is also referred to as Sandworm Team.Sapphire SleetAPT38 is a North Korean statesponsored threat group that specializes in financial cyber operations; it has been attributed to the Reconnaissance General Bureau. Active since at least 2014, APT38 has targeted banks, financial institutions, casinos, cryptocurrency exchanges, SWIFT system endpoints, and ATMs in at least 38 countries worldwide. Significant operations include the 2016 Bank of Bangladesh heist, during which APT38 stole $81 million, as well as attacks against Bancomext and Banco de Chile; some of their attacks have been destructive. North Korean group definitions are known to have significant overlap, and some security researchers report all North Korean statesponsored cyber activity under the name Lazarus Group instead of tracking clusters or subgroups.PlayPlay is a ransomware group that has been active since at least 2022 deploying Playcrypt ransomware against the business, government, critical infrastructure, healthcare, and media sectors in North America, South America, and Europe. Play actors employ a doubleextortion model, encrypting systems after exfiltrating data, and are presumed by security researchers to operate as a closed group.