Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks
Daily Cybersecurity Briefing (22 April 2026)
Published: Loading…
At a Glance
- Scattered Spider member pleaded guilty to wire fraud conspiracy from 2022 SMS phishing enabling SIM-swapping crypto theft exceeding eight million dollars.
- Mustang Panda deployed updated LOTUSLITE backdoor via CHM phishing and Microsoft-signed DLL sideloading targeting Indian banking sector and Korean policy entities.
- NGate Android malware variant uses trojanised HandyPay NFC application to steal payment card data and PINs in Brazil campaign.
- Microsoft GitHub Windows-driver-samples repository workflow flaw enables remote code execution via unsanitised issue body injection into Python script.
- CISA added eight actively exploited vulnerabilities affecting Cisco SD-WAN, Zimbra, and other platforms, enforcing federal remediation deadlines under KEV programme.
Summary
Scattered Spider member pleaded guilty to wire fraud conspiracy from 2022 SMS phishing enabling SIM-swapping cryptocurrency theft exceeding eight million dollars. The campaign targeted major technology platforms using credential harvesting techniques. Stolen access enabled cryptocurrency diversion through mobile number takeover.
CISA added eight actively exploited vulnerabilities to its KEV catalogue, including Cisco Catalyst SD-WAN Manager, Zimbra, Kentico, and PaperCut flaws requiring urgent remediation across federal systems. The update includes multiple vendors with confirmed exploitation across enterprise environments. Federal agencies face mandated deadlines for patch deployment under KEV requirements.
Microsoft GitHub Windows-driver-samples workflow flaw enables remote code execution through unsanitised issue body injection into Python execution context on GitHub Actions runners exposing repository secrets. The vulnerability allows unauthorised code execution within CI pipelines. Repository secrets are at risk of exposure through compromised workflow execution.
Google Antigravity IDE flaw combines prompt injection and unsafe file search handling to achieve remote code execution and sandbox escape within agentic development environment. The issue impacts tool execution chains within the IDE. Sandbox protections are bypassed through native tool call exploitation.
Mustang Panda deployed updated LOTUSLITE backdoor through CHM phishing and DLL sideloading using Microsoft-signed executables to target Indian banking and Korean policy sectors. The campaign uses dynamic DNS infrastructure for command-and-control communication. Execution chains rely on legitimate signed binaries for payload delivery.
North Korea-linked Void Dokkaebi operation spreads malware via compromised code repositories, injecting malicious VS Code tasks and committing infected configuration files across developer platforms. The campaign propagates through developer workflows and source control systems. Over 750 repositories have been affected across multiple platforms.
NGate Android malware abuses trojanised HandyPay NFC application to steal payment card data and PINs in Brazil contactless fraud campaign. The malware relays NFC data to attacker-controlled infrastructure. PIN exfiltration supports unauthorised transaction authorisation.
Former ransomware negotiator Angelo Martino pleaded guilty to assisting BlackCat ransomware attacks against US companies while working within cyber incident response industry. The scheme involved facilitating extortion operations during negotiation processes. Insider access was leveraged for ransomware campaign support.
Phishing campaigns increasingly leverage valid credentials and MFA workflow exploitation, using trusted accounts to deliver internal-style business email lures and credential harvesting attacks. Attackers rely on compromised identity trust to bypass security controls. Business communication patterns are used for malicious message delivery.
Cloud platform Vercel confirmed breach involving third-party tool compromise and OAuth abuse, leading to credential exposure affecting a limited subset of customers. Attackers exploited connected application permissions for access. OAuth token misuse enabled unauthorised data exposure.
North Korea’s Lazarus Group attributed to $290 million KelpDAO crypto theft, exploiting blockchain routing dependencies and triggering failover to poisoned infrastructure nodes. The attack targeted decentralised finance routing mechanisms. Compromised infrastructure nodes facilitated transaction manipulation.
Healthcare data breaches affecting multiple US organisations exposed records of approximately 600,000 individuals amid ransomware-related intrusions and credential-based network access incidents. Sensitive patient data was accessed through compromised credentials. Multiple healthcare providers reported coordinated intrusion activity.
Highlights of the Day
CISA Adds Eight Actively Exploited Vulnerabilities to KEV Catalogue
CISA added eight vulnerabilities to its Known Exploited Vulnerabilities catalogue, including flaws affecting PaperCut NG/MF, JetBrains TeamCity, Kentico Xperience, Quest KACE SMA, Synacor Zimbra, and Cisco Catalyst SD-WAN Manager. The listed issues include improper authentication, path traversal, cross-site scripting, and sensitive information exposure vulnerabilities, all confirmed to be actively exploited in the wild. The update follows Binding Operational Directive 22-01, which mandates remediation deadlines for US federal agencies to address vulnerabilities posing significant risk to federal networks.
NGate Malware Variant Uses Trojanised NFC App to Steal Cards
ESET researchers identified a new NGate malware variant that abuses a trojanised version of the legitimate Android NFC relay app HandyPay to capture and transmit payment card data. The malware relays NFC data from victims’ cards to attacker-controlled devices for contactless ATM withdrawals and payments, while separately capturing PIN codes and exfiltrating them to a command-and-control server over HTTP. The campaign, active since November 2025 and targeting Android users in Brazil, distributes the malicious app via a fake lottery website and a counterfeit Google Play page hosting download links.
Prompt Injection Flaw Enables RCE in Google Antigravity IDE
Pillar Security researchers discovered a prompt injection vulnerability in Google’s Antigravity agentic IDE, where the find_by_name tool passes unsanitised input to the fd utility, enabling command injection. Attackers can exploit the Pattern parameter using the -X flag to execute arbitrary code, staging payloads within the workspace and triggering execution without additional user interaction. The flaw bypasses Antigravity Secure Mode protections because native tool calls execute before sandbox restrictions, enabling remote code execution and sandbox escape even under the strictest configuration.
Void Dokkaebi Spreads Malware Through Infected Code Repositories
Trend Micro reports that North Korea-linked Void Dokkaebi targets developers with fake job interviews, tricking them into running malicious repositories that deploy malware via VS Code tasks and injected JavaScript. Compromised machines propagate the attack by committing infected .vscode configurations and obfuscated code into repositories, enabling worm-like spread across GitHub, GitLab, Bitbucket, and downstream projects. Analysis identified over 750 infected repositories, malicious commit tampering tools, and blockchain-based payload delivery retrieving and executing malware such as DEV#POPPER RAT from Tron, Aptos, and Binance Smart Chain.
GitHub Workflow Flaw Enabled RCE in Microsoft Sample Repo
Tenable researchers disclosed a critical vulnerability in Microsoft’s Windows-driver-samples GitHub repository, where a GitHub Actions workflow improperly interpolated user-controlled issue content into a Python script without sanitisation. Attackers could inject arbitrary Python code via crafted issue bodies, enabling remote code execution on the GitHub runner and access to repository secrets. Microsoft confirmed and patched the issue in March 2026 after responsible disclosure, addressing the insecure handling of untrusted input in the workflow configuration.
Mustang Panda Targets Banks With Updated LOTUSLITE Backdoor
Acronis researchers identified a new LOTUSLITE backdoor variant attributed to Mustang Panda, delivered via spear-phishing CHM files that deploy malware using JavaScript loaders and DLL sideloading through a Microsoft-signed executable. The implant communicates with command-and-control servers over HTTPS using dynamic DNS infrastructure, providing remote shell access, file operations, and session management capabilities. The campaign targets India’s banking sector and Korean policy entities, with updated code including modified packet signatures, API resolution techniques, and persistence mechanisms while maintaining core command structures from earlier LOTUSLITE versions.
Scattered Spider Member Pleads Guilty to Phishing and Crypto Theft
A British national linked to the Scattered Spider cybercrime group pleaded guilty to wire fraud conspiracy and aggravated identity theft tied to large-scale SMS phishing attacks in 2022. The campaign targeted companies including Twilio, LastPass, DoorDash, and Mailchimp, enabling intrusions that supported SIM-swapping operations and cryptocurrency theft totalling at least $8 million. Investigators linked the suspect to phishing infrastructure through domain registrations and seized devices containing stolen data, with sentencing scheduled for August 2026.
Daily Coverage