Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks
Daily Cybersecurity Briefing (28 April 2026)
Published: Loading…
At a Glance
- Checkmarx confirmed GitHub repository exposure linked to March 23 supply chain attack involving compromised Trivy scanner CI/CD secrets.
- A phishing campaign impersonating Meta verification collects credentials and live two-factor authentication tokens via Google Forms and fake pages.
- BlueNoroff deployed fake Zoom meeting lures with ClickFix injection stealing crypto wallet credentials, browser sessions, and Telegram authentication data.
- Akamai reported Windows zero-click authentication flaw CVE-2026-32202 enabling SMB hash leakage via shortcut parsing exploited by APT28 campaigns.
- OpenSSH CVE-2026-35414 allows certificate principal comma parsing bypass resulting in root access without authentication failure logging on affected servers.
- ShinyHunters breached ADT via Okta single sign-on compromise, exposing data from 5.5 million customers including names, addresses, and partial identifiers.
Summary
Compromised CI/CD tooling linked to Checkmarx and the Trivy scanner exposed GitHub repositories and developer pipelines across multiple software supply-chain environments. Lapsus$ claims and related intrusions impacted GitHub Actions workflows, OpenVSX extensions, and Bitwarden CLI secrets within developer infrastructure systems.
Meta verification-themed phishing campaigns harvested passwords and live two-factor authentication tokens through Google Forms and spoofed verification pages. ShinyHunters breached ADT systems via voice phishing targeting Okta single sign-on, exposing customer data including names, addresses, and partial identifiers.
Windows shortcut parsing flaw CVE-2026-32202 enabled zero-click SMB authentication coercion, while OpenSSH CVE-2026-35414 allowed certificate-based root access bypass affecting SSH authentication systems. PackageKit race condition vulnerability Pack2TheRoot enabled privilege escalation, while Firefox CVE-2026-6770 enabled Tor user fingerprinting via browser behaviour tracking.
BlueNoroff campaigns used fake Zoom meetings and ClickFix injection to steal cryptocurrency wallet credentials, browser sessions, and authentication tokens. GlassWorm malicious VS Code extensions, UNC6692 Snow malware variants, and BlackFile vishing campaigns enabled credential theft and persistent access operations.
Itron and Medtronic reported network intrusions affecting industrial systems and medical environments, with attackers accessing corporate IT infrastructure. Fake CAPTCHA SMS fraud campaigns, PyPI package compromises, and FTC-reported social media scams contributed to large-scale credential theft and financial losses.
Fast16 malware identified as pre-Stuxnet era sabotage tooling suggests early targeting of industrial systems linked to Iranian nuclear infrastructure operations. United States authorities launched a crackdown on Southeast Asian cyberscam networks and sanctioned Cambodian officials linked to large-scale crypto fraud operations.
Highlights of the Day
Checkmarx Breach Linked to Trivy Supply Chain Attack
Checkmarx confirmed that data exposed on the dark web originated from its GitHub repository, accessed through a March 23, 2026 supply chain attack involving compromised CI/CD secrets from the Trivy scanner. The TeamPCP group injected credential-stealing malware into KICS Docker images and related developer tools, enabling exfiltration of scan reports, credentials, and configuration data to external endpoints. The incident also impacted GitHub Actions, Open VSX plugins, and Bitwarden CLI, while Lapsus$ claimed to have leaked source code, API keys, database credentials, and employee information.
Phishing Campaign Steals Meta Credentials and Live 2FA Tokens
A phishing campaign impersonating Meta’s verification process uses emails and Google Forms to collect user credentials and two-factor authentication tokens through multi-step spoofed workflows. The attack redirects victims to a fraudulent “Meta Verified” page hosted on vercel.app, where personal details, passwords, and 2FA tokens are submitted in real time. Captured credentials and tokens are immediately used by attackers to access and take over accounts, targeting both individual users and businesses.
BlueNoroff Uses Fake Zoom Meetings to Steal Crypto Credentials
Arctic Wolf identified a targeted intrusion by BlueNoroff, a Lazarus Group subgroup, using spear-phishing Calendly invites with typo-squatted Zoom links to compromise a North American Web3 company. The attack deployed a fake meeting interface that captured webcam footage, executed a ClickFix clipboard injection, and launched a multi-stage PowerShell-based infection chain stealing browser data, Telegram sessions, and cryptocurrency wallet credentials. Analysis revealed over 100 global targets, 80 spoofed conferencing domains, and attacker infrastructure hosting more than 950 stolen media files used to generate AI-enhanced deepfake meeting lures.
Incomplete Windows Patch Enables Zero-Click Credential Theft Attacks
Akamai identified CVE-2026-32202, a zero-click authentication coercion flaw caused by an incomplete patch for CVE-2026-21510, originally exploited by APT28 using malicious LNK files. The vulnerability triggers automatic SMB connections when Windows Explorer parses shortcut icons, leaking Net-NTLMv2 hashes without user interaction and enabling credential theft. APT28 previously chained CVE-2026-21510 and CVE-2026-21513 to achieve remote code execution via spoofed Control Panel paths loading attacker-controlled DLLs from UNC locations.
OpenSSH Comma Parsing Bug Grants Root Access via Certificates
OpenSSH before version 10.3 is affected by CVE-2026-35414, where a comma in CA-signed SSH certificate principals enables authentication bypass and root access on trusted servers. Code reuse error in list parsing splits comma-separated principals such as deploy,root, with one authentication path treating fragments as valid identities while another skips validation entirely. Exploitation generates no authentication failure logs, making detection unreliable; the flaw was fixed in OpenSSH 10.3 released in April, enabling root shell access affected servers.
ADT breach exposes data of 5.5 million customers via ShinyHunters
ShinyHunters breached ADT systems via voice phishing targeting an employee Okta single sign-on account accessing Salesforce data tied to customer records affecting 5.5 million individuals. Stolen data contained names, phone numbers and addresses, with limited dates of birth and partial Social Security or Tax ID numbers, without payment information accessed. ShinyHunters leaked an 11GB archive after failed extortion, with Have I Been Pwned estimating 5.5 million people affected across multiple data fields.
Daily Coverage