Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks
Daily Cybersecurity Briefing (29 April 2026)
Published: Loading…
At a Glance
- GitHub CVE-2026-3854 enables remote code execution through malicious git push commands, impacting GitHub.com and Enterprise Server instances.
- LiteLLM CVE-2026-42208 pre-auth SQL injection is exploited via Authorization headers exposing API keys and cloud provider credentials databases.
- Microsoft confirms active exploitation of Windows Shell CVE-2026-32202 spoofing flaw enabling credential theft via crafted LNK files attacks.
- Medtronic confirms corporate IT breach following ShinyHunters claims of nine million records exfiltrated from internal systems investigation ongoing.
- VECT 2.0 ransomware permanently destroys files larger than 131KB due to ChaCha20 nonce handling flaw across Windows Linux ESXi.
Summary
GitHub CVE-2026-3854, LiteLLM CVE-2026-42208, and Windows Shell CVE-2026-32202 were actively exploited, enabling remote code execution, credential theft, and spoofing attacks across enterprise environments. Microsoft Entra ID Agent ID Administrator role flaw enabled privilege escalation and identity impact affecting AI agent identity management systems.
VECT 2.0 ransomware permanently destroys files over 131KB due to ChaCha20 nonce handling errors across Windows, Linux, and ESXi systems. Medtronic confirmed a corporate IT breach after ShinyHunters claimed nine million records, while Vimeo reported a third-party Anodot data exposure incident with investigation ongoing and no service disruption reported.
China-linked phishing campaigns targeted journalists and activists to steal credentials. North Korean groups were reported using AI-generated social engineering lures in cryptocurrency theft operations. Fake CAPTCHA-based fraud and SMS billing abuse campaigns were reported as part of broader fraud and account compromise activity.
Silk Typhoon-linked suspect Xu Zewei was extradited to the United States over cyberattacks, alongside reported long-term Chinese espionage involving impersonation and Signal phishing campaigns. Separate reporting described Chinese engineer impersonation operations targeting US institutions, while Germany investigated Russia-linked Signal phishing targeting senior government officials.
LofyGang malware campaign distributed Minecraft-themed LofyStealer to harvest credentials, while Open VSX cloned extensions delivered GlassWorm malware across developer ecosystems. US authorities charged a Scattered Spider member arrested in Finland, while LAPSUS$ data leaks and ransomware group disputes escalated across cybercriminal forums.
Highlights of the Day
GitHub RCE flaw allows push-based server compromise
GitHub CVE-2026-3854 is an injection flaw in git push handling where user-controlled push options were unsafely embedded into an internal header and later parsed with delimiter-based logic that allowed fields to be overwritten. This enabled attackers to modify security-critical configuration values in backend services, leading to remote code execution on GitHub.com and full server compromise on GitHub Enterprise Server. CVE-2026-3854 was assigned CVSS 8.7, with GitHub releasing patches for GitHub.com and GitHub Enterprise Server versions 3.14.24 through 3.19.3 after initial mitigation on GitHub.com.
VECT 2.0 ransomware destroys large files via flawed encryption design
VECT 2.0 ransomware targets Windows, Linux and ESXi systems, with a flawed encryption design that permanently destroys files larger than 131KB. Check Point Research reports the malware discards required ChaCha20 nonces during encryption, making large file recovery impossible even for operators or victims. The ransomware-as-a-service operation partners with BreachForums and TeamPCP, with limited reported victims and supply-chain distribution despite presenting itself as ransomware.
Windows Shell spoofing flaw actively exploited in the wild
CVE-2026-32202 is a Windows Shell spoofing vulnerability with CVSS 4.3 that requires user execution of a malicious file to trigger over a network. Microsoft confirmed exploitation in the wild after revising its advisory, noting the issue stems from an incomplete patch for a prior Windows Shell flaw CVE-2026-21510. Attack chains leverage specially crafted LNK files using UNC paths to trigger SMB connections that coerce NTLM authentication and expose Net-NTLMv2 hashes for relay or cracking.
LiteLLM SQL injection flaw actively exploited for secret theft
LiteLLM CVE-2026-42208 is a pre-auth SQL injection in proxy API key verification, triggered via crafted Authorization headers to /chat/completions endpoint. Exploitation began approximately 36 hours after public disclosure, with Sysdig observing targeted queries against database tables containing API keys, provider credentials and configuration data. Successful exploitation enables unauthenticated database read and modification of LiteLLM-managed secrets, with mitigation delivered in version 1.83.7 using parameterised queries replacing unsafe concatenation.
Medtronic confirms corporate IT data breach after ShinyHunters claims
Medtronic confirmed a data security incident affecting corporate IT systems after ShinyHunters claimed responsibility on its leak site in mid-April. The company stated unauthorised access to internal systems, no disruption to products, patient safety or operations, and hospital networks were not affected. ShinyHunters alleged over nine million records exfiltrated and internal corporate data, later removing Medtronic from leak site while investigation into scope continues.
Vimeo confirms third-party breach exposing user data via Anodot
Vimeo reported Anodot third-party breach leading to unauthorised access to Vimeo user and customer data, including technical data, video titles, metadata, and some email addresses. The accessed datasets excluded video content, login credentials and payment card information, while Vimeo confirmed no service disruption and disabled Anodot integration during investigation.
Daily Coverage