CyberSecBrief

Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks


Daily Cybersecurity Briefing (28 April 2026)

Published: Loading…

At a Glance

  • Checkmarx confirmed GitHub repository exposure linked to March 23 supply chain attack involving compromised Trivy scanner CI/CD secrets.
  • A phishing campaign impersonating Meta verification collects credentials and live two-factor authentication tokens via Google Forms and fake pages.
  • BlueNoroff deployed fake Zoom meeting lures with ClickFix injection stealing crypto wallet credentials, browser sessions, and Telegram authentication data.
  • Akamai reported Windows zero-click authentication flaw CVE-2026-32202 enabling SMB hash leakage via shortcut parsing exploited by APT28 campaigns.
  • OpenSSH CVE-2026-35414 allows certificate principal comma parsing bypass resulting in root access without authentication failure logging on affected servers.
  • ShinyHunters breached ADT via Okta single sign-on compromise, exposing data from 5.5 million customers including names, addresses, and partial identifiers.

Summary

Compromised CI/CD tooling linked to Checkmarx and the Trivy scanner exposed GitHub repositories and developer pipelines across multiple software supply-chain environments. Lapsus$ claims and related intrusions impacted GitHub Actions workflows, OpenVSX extensions, and Bitwarden CLI secrets within developer infrastructure systems.

Meta verification-themed phishing campaigns harvested passwords and live two-factor authentication tokens through Google Forms and spoofed verification pages. ShinyHunters breached ADT systems via voice phishing targeting Okta single sign-on, exposing customer data including names, addresses, and partial identifiers.

Windows shortcut parsing flaw CVE-2026-32202 enabled zero-click SMB authentication coercion, while OpenSSH CVE-2026-35414 allowed certificate-based root access bypass affecting SSH authentication systems. PackageKit race condition vulnerability Pack2TheRoot enabled privilege escalation, while Firefox CVE-2026-6770 enabled Tor user fingerprinting via browser behaviour tracking.

BlueNoroff campaigns used fake Zoom meetings and ClickFix injection to steal cryptocurrency wallet credentials, browser sessions, and authentication tokens. GlassWorm malicious VS Code extensions, UNC6692 Snow malware variants, and BlackFile vishing campaigns enabled credential theft and persistent access operations.

Itron and Medtronic reported network intrusions affecting industrial systems and medical environments, with attackers accessing corporate IT infrastructure. Fake CAPTCHA SMS fraud campaigns, PyPI package compromises, and FTC-reported social media scams contributed to large-scale credential theft and financial losses.

Fast16 malware identified as pre-Stuxnet era sabotage tooling suggests early targeting of industrial systems linked to Iranian nuclear infrastructure operations. United States authorities launched a crackdown on Southeast Asian cyberscam networks and sanctioned Cambodian officials linked to large-scale crypto fraud operations.

Highlights of the Day

Checkmarx Breach Linked to Trivy Supply Chain Attack

Checkmarx confirmed that data exposed on the dark web originated from its GitHub repository, accessed through a March 23, 2026 supply chain attack involving compromised CI/CD secrets from the Trivy scanner. The TeamPCP group injected credential-stealing malware into KICS Docker images and related developer tools, enabling exfiltration of scan reports, credentials, and configuration data to external endpoints. The incident also impacted GitHub Actions, Open VSX plugins, and Bitwarden CLI, while Lapsus$ claimed to have leaked source code, API keys, database credentials, and employee information.

Phishing Campaign Steals Meta Credentials and Live 2FA Tokens

A phishing campaign impersonating Meta’s verification process uses emails and Google Forms to collect user credentials and two-factor authentication tokens through multi-step spoofed workflows. The attack redirects victims to a fraudulent “Meta Verified” page hosted on vercel.app, where personal details, passwords, and 2FA tokens are submitted in real time. Captured credentials and tokens are immediately used by attackers to access and take over accounts, targeting both individual users and businesses.

Source: Cofense

BlueNoroff Uses Fake Zoom Meetings to Steal Crypto Credentials

Arctic Wolf identified a targeted intrusion by BlueNoroff, a Lazarus Group subgroup, using spear-phishing Calendly invites with typo-squatted Zoom links to compromise a North American Web3 company. The attack deployed a fake meeting interface that captured webcam footage, executed a ClickFix clipboard injection, and launched a multi-stage PowerShell-based infection chain stealing browser data, Telegram sessions, and cryptocurrency wallet credentials. Analysis revealed over 100 global targets, 80 spoofed conferencing domains, and attacker infrastructure hosting more than 950 stolen media files used to generate AI-enhanced deepfake meeting lures.

Incomplete Windows Patch Enables Zero-Click Credential Theft Attacks

Akamai identified CVE-2026-32202, a zero-click authentication coercion flaw caused by an incomplete patch for CVE-2026-21510, originally exploited by APT28 using malicious LNK files. The vulnerability triggers automatic SMB connections when Windows Explorer parses shortcut icons, leaking Net-NTLMv2 hashes without user interaction and enabling credential theft. APT28 previously chained CVE-2026-21510 and CVE-2026-21513 to achieve remote code execution via spoofed Control Panel paths loading attacker-controlled DLLs from UNC locations.

OpenSSH Comma Parsing Bug Grants Root Access via Certificates

OpenSSH before version 10.3 is affected by CVE-2026-35414, where a comma in CA-signed SSH certificate principals enables authentication bypass and root access on trusted servers. Code reuse error in list parsing splits comma-separated principals such as deploy,root, with one authentication path treating fragments as valid identities while another skips validation entirely. Exploitation generates no authentication failure logs, making detection unreliable; the flaw was fixed in OpenSSH 10.3 released in April, enabling root shell access affected servers.

ADT breach exposes data of 5.5 million customers via ShinyHunters

ShinyHunters breached ADT systems via voice phishing targeting an employee Okta single sign-on account accessing Salesforce data tied to customer records affecting 5.5 million individuals. Stolen data contained names, phone numbers and addresses, with limited dates of birth and partial Social Security or Tax ID numbers, without payment information accessed. ShinyHunters leaked an 11GB archive after failed extortion, with Have I Been Pwned estimating 5.5 million people affected across multiple data fields.

Daily Coverage

Developments
Supply Chain AttackMeta 2Fa PhishingBluenoroff Zoom LuresWindows Zero-Click Flaw
Vulnerabilities
CVE-2026-32202Windows 10 Version 1607 10.0.14393.0 (Medium)CVE-2026-3854CVE-2026-25874CVE-2026-42208CVE-2026-6770CVE-2026-35414CVE-2026-21513Windows 10 Version 1607 10.0.14393.0 (High)CVE-2026-21510CVE-2026-35230Oracle Vm Virtualbox 7.2.6 (High)
Threat Groups
Silk TyphoonHAFNIUM is a likely statesponsored cyber espionage group operating out of China that has been active since at least January 2021. HAFNIUM primarily targets entities in the US across a number of industry sectors, including infectious disease researchers, law firms, higher education institutions, defense contractors, policy think tanks, and NGOs. HAFNIUM has targeted remote management tools and cloud software for intial access and has demonstrated an ability to quickly operationalize exploits for identified vulnerabilities in edge devices.BluenoroffAPT38 is a North Korean statesponsored threat group that specializes in financial cyber operations; it has been attributed to the Reconnaissance General Bureau. Active since at least 2014, APT38 has targeted banks, financial institutions, casinos, cryptocurrency exchanges, SWIFT system endpoints, and ATMs in at least 38 countries worldwide. Significant operations include the 2016 Bank of Bangladesh heist, during which APT38 stole $81 million, as well as attacks against Bancomext and Banco de Chile; some of their attacks have been destructive. North Korean group definitions are known to have significant overlap, and some security researchers report all North Korean statesponsored cyber activity under the name Lazarus Group instead of tracking clusters or subgroups.LAPSUS$LAPSUS$ is cyber criminal threat group that has been active since at least mid2021. LAPSUS$ specializes in largescale social engineering and extortion operations, including destructive attacks without the use of ransomware. The group has targeted organizations globally, including in the government, manufacturing, higher education, energy, healthcare, technology, telecommunications, and media sectors.Lazarus GroupLazarus Group is a North Korean statesponsored cyber threat group attributed to the Reconnaissance General Bureau (RGB). Lazarus Group has been active since at least 2009 and is reportedly responsible for the November 2014 destructive wiper attack on Sony Pictures Entertainment, identified by Novetta as part of Operation Blockbuster. Malware used by Lazarus Group correlates to other reported campaigns, including Operation Flame, Operation 1Mission, Operation Troy, DarkSeoul, and Ten Days of Rain. North Korea’s cyber operations have shown a consistent pattern of adaptation, forming and reorganizing units as national priorities shift. These units frequently share personnel, infrastructure, malware, and tradecraft, making it difficult to attribute specific operations with high confidence. Public reporting often uses “Lazarus Group” as an umbrella term for multiple North Korean cyber operators conducting espionage, destructive attacks, and financially motivated campaigns.Scattered SpiderScattered Spider is a native Englishspeaking cybercriminal group active since at least 2022. The group initially targeted customer relationship management (CRM) providers, business process outsourcing (BPO) firms, and telecommunications and technology companies before expanding in 2023 to gaming, hospitality, retail, managed service provider (MSP), manufacturing, and financial sectors. Scattered Spider relies heavily on social engineering, including impersonating IT and helpdesk staff, to gain initial access, bypass multifactor authentication (MFA), and compromise enterprise networks. The group has adapted its tooling to evade endpoint detection and response (EDR) defenses and used ransomware for financial gain. Scattered Spider had expanded into hybrid cloud and identity environments, using helpdesk impersonation and MFA bypass to obtain administrator access in Okta, AWS, and Office 365.APT28APT28 is a threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) 85th Main Special Service Center (GTsSS) military unit 26165. This group has been active since at least 2004. APT28 reportedly compromised the Hillary Clinton campaign, the Democratic National Committee, and the Democratic Congressional Campaign Committee in 2016 in an attempt to interfere with the U. S. presidential election. In 2018, the US indicted five GRU Unit 26165 officers associated with APT28 for cyber operations (including closeaccess operations) conducted between 2014 and 2018 against the World AntiDoping Agency (WADA), the US AntiDoping Agency, a US nuclear facility, the Organization for the Prohibition of Chemical Weapons (OPCW), the Spiez Swiss Chemicals Laboratory, and other organizations. Some of these were conducted with the assistance of GRU Unit 74455, which is also referred to as Sandworm Team.