Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks
Daily Cybersecurity Briefing (18 April 2026)
Published: Loading…
At a Glance
- Threat actors are exploiting Windows zero-days BlueHammer, RedSun, and UnDefend to gain SYSTEM privileges and disable Microsoft Defender protections in active attacks.
- CISA added Apache ActiveMQ CVE-2026-34197 to KEV after active exploitation enabling authenticated remote code execution via the Jolokia API component.
- Operation PowerOFF seized 53 DDoS-for-hire domains, analysed 3 million accounts, and targeted over 75,000 users in a coordinated international law enforcement action.
- NIST will stop enriching most CVEs, limiting analysis to KEV-listed and critical systems after a 263% surge in vulnerability submissions overwhelmed processing capacity.
- ZionSiphon malware targets Israeli water infrastructure, scanning OT protocols and attempting to manipulate industrial control parameters such as chlorine dosing and pressure.
- A Mirai-based Nexcorium botnet exploits TBK DVR CVE-2024-3721 to deploy multi-architecture malware enabling persistence, brute-force propagation, and DDoS attacks.
Summary
Multiple Windows zero-day vulnerabilities including BlueHammer, RedSun, and UnDefend are being exploited to gain SYSTEM privileges and interfere with Microsoft Defender functionality. RedSun abuses Defender file restoration behaviour to overwrite system files, while UnDefend can disable security updates, leaving two of the three flaws currently unpatched.
Apache ActiveMQ CVE-2026-34197 is under active exploitation, enabling authenticated remote code execution through the Jolokia API, with potential chaining to older flaws for unauthenticated attacks. The vulnerability remained undiscovered for 13 years and has been added to the CISA Known Exploited Vulnerabilities catalogue, mandating remediation across federal systems.
A coordinated international operation, Operation PowerOFF, seized 53 domains linked to DDoS-for-hire services and analysed databases containing over 3 million user accounts. Authorities across 21 countries targeted more than 75,000 users, conducted arrests, and disrupted infrastructure supporting commercialised distributed denial-of-service attacks.
The NIST National Vulnerability Database will now prioritise enrichment of CVEs tied to KEV-listed vulnerabilities, federal systems, or critical infrastructure following a 263% increase in submissions. Vulnerabilities outside these categories will remain listed but marked “Not Scheduled”, often without CVSS scores or detailed platform data.
The ZionSiphon malware targets industrial control systems in Israeli water facilities, scanning for OT protocols such as Modbus, DNP3, and S7comm while checking for desalination-related processes. The malware includes logic to alter chlorine dosing and pressure settings, though analysis shows incomplete implementations preventing execution of sabotage routines.
A Nexcorium Mirai variant exploits CVE-2024-3721 in TBK DVR devices to deploy multi-architecture malware with persistence mechanisms and Telnet-based brute-force propagation. Separately, adversarial image-based prompt injection attacks manipulated Claude Opus 4.7 into storing false persistent memory entries, demonstrating risks in AI tool invocation mechanisms.
Highlights of the Day
NIST Limits CVE Enrichment Amid Surge in Vulnerability Reports
NIST has adopted a risk-based approach for the National Vulnerability Database, enriching only CVEs tied to CISA’s Known Exploited Vulnerabilities catalogue, federal software, or critical systems under Executive Order 14028. The change follows a 263% increase in CVE submissions between 2020 and 2025, with 2026 volumes already significantly higher, outpacing NIST’s ability to analyse and process vulnerabilities. Unenriched CVEs marked “Not Scheduled” will lack CVSS severity scores and Common Platform Enumeration data, limiting their usability in security tools and vulnerability management workflows. NIST will also stop issuing its own CVSS scores when provided by CVE Numbering Authorities, despite documented inconsistencies of up to 6.9 points between scoring sources.
Global Operation Targets 75,000 DDoS-for-Hire Service Users
A Europol-supported operation involving 21 countries targeted over 75,000 users of DDoS-for-hire services, issuing warning messages, making four arrests, seizing infrastructure, and taking down 53 domains. Authorities analysed seized databases containing more than 3 million user accounts, enabling coordinated enforcement actions and the issuance of 25 search warrants across participating countries. The crackdown disrupted booter service infrastructure including servers and databases, while prevention measures removed over 100 related URLs and delivered warnings via search engines and blockchain transactions.
Leaked Windows Zero-Days Exploited for Privilege Escalation Attacks
Threat actors are actively exploiting three Windows zero-day vulnerabilities known as BlueHammer, RedSun, and UnDefend to gain SYSTEM or administrator privileges and disrupt Microsoft Defender functionality. Huntress researchers observed the exploits in live attacks, including breaches via compromised SSLVPN accounts, with evidence of hands-on-keyboard activity and BlueHammer exploitation dating back to 10 April 2026. Microsoft has patched BlueHammer as CVE-2026-33825, while RedSun and UnDefend remain unpatched, with RedSun enabling privilege escalation by abusing Defender behaviour to overwrite system files.
ZionSiphon Malware Targets Israeli Water Infrastructure Systems
Darktrace analysed ZionSiphon malware featuring privilege escalation, persistence, USB propagation, and subnet scanning for OT protocols including Modbus, DNP3, and S7comm within water treatment environments. The malware contains hardcoded Israeli IP ranges and checks for desalination-related processes, directories, and files, then attempts configuration tampering by modifying chlorine dosing and pressure settings in industrial control systems. Researchers found the sample includes incomplete protocol implementations and a faulty country validation routine, preventing activation despite embedded sabotage logic and politically motivated targeting strings.
ActiveMQ Flaw Exploited for Remote Code Execution Attacks
Attackers are exploiting CVE-2026-34197, a vulnerability in Apache ActiveMQ Classic’s Jolokia API that enables authenticated remote code execution and remained undiscovered in the codebase for 13 years. The flaw can be combined with CVE-2024-32114 to achieve unauthenticated exploitation, while many exposed instances rely on default credentials, increasing exposure. CISA added the vulnerability to its Known Exploited Vulnerabilities catalogue as Fortinet reported dozens of exploitation attempts within a week of disclosure.
Nexcorium Mirai Variant Exploits DVR Flaw to Build IoT Botnet
Fortinet researchers identified a Nexcorium Mirai variant exploiting CVE-2024-3721, an OS command injection flaw in TBK DVR devices, to deploy multi-architecture malware targeting Linux systems. The malware uses XOR-encoded configuration, brute-force Telnet credential lists, and exploits including CVE-2017-17215 to spread, while establishing persistence via system services, cron jobs, and startup scripts. Infected devices connect to a command-and-control server to execute DDoS attacks using multiple flood techniques including TCP SYN, UDP, and SMTP floods.
Adversarial Image Attack Hijacks AI Memory Tool in Tests
A researcher demonstrated an indirect prompt injection attack where a ChatGPT-generated image tricked Claude Opus 4.7 into invoking its memory tool and storing false user information. The attack embedded hidden instructions in a puzzle image, leading the model to add fabricated personal details such as age, occupation, and preferences into persistent memory. Testing showed a 50% success rate across ten attempts, with the model detecting suspicious behaviour but still executing memory writes despite built-in safeguards.
Daily Coverage