CyberSecBrief

Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks


Daily Cybersecurity Briefing (29 April 2026)

Published: Loading…

At a Glance

  • GitHub CVE-2026-3854 enables remote code execution through malicious git push commands, impacting GitHub.com and Enterprise Server instances.
  • LiteLLM CVE-2026-42208 pre-auth SQL injection is exploited via Authorization headers exposing API keys and cloud provider credentials databases.
  • Microsoft confirms active exploitation of Windows Shell CVE-2026-32202 spoofing flaw enabling credential theft via crafted LNK files attacks.
  • Medtronic confirms corporate IT breach following ShinyHunters claims of nine million records exfiltrated from internal systems investigation ongoing.
  • VECT 2.0 ransomware permanently destroys files larger than 131KB due to ChaCha20 nonce handling flaw across Windows Linux ESXi.

Summary

GitHub CVE-2026-3854, LiteLLM CVE-2026-42208, and Windows Shell CVE-2026-32202 were actively exploited, enabling remote code execution, credential theft, and spoofing attacks across enterprise environments. Microsoft Entra ID Agent ID Administrator role flaw enabled privilege escalation and identity impact affecting AI agent identity management systems.

VECT 2.0 ransomware permanently destroys files over 131KB due to ChaCha20 nonce handling errors across Windows, Linux, and ESXi systems. Medtronic confirmed a corporate IT breach after ShinyHunters claimed nine million records, while Vimeo reported a third-party Anodot data exposure incident with investigation ongoing and no service disruption reported.

China-linked phishing campaigns targeted journalists and activists to steal credentials. North Korean groups were reported using AI-generated social engineering lures in cryptocurrency theft operations. Fake CAPTCHA-based fraud and SMS billing abuse campaigns were reported as part of broader fraud and account compromise activity.

Silk Typhoon-linked suspect Xu Zewei was extradited to the United States over cyberattacks, alongside reported long-term Chinese espionage involving impersonation and Signal phishing campaigns. Separate reporting described Chinese engineer impersonation operations targeting US institutions, while Germany investigated Russia-linked Signal phishing targeting senior government officials.

LofyGang malware campaign distributed Minecraft-themed LofyStealer to harvest credentials, while Open VSX cloned extensions delivered GlassWorm malware across developer ecosystems. US authorities charged a Scattered Spider member arrested in Finland, while LAPSUS$ data leaks and ransomware group disputes escalated across cybercriminal forums.

Highlights of the Day

GitHub RCE flaw allows push-based server compromise

GitHub CVE-2026-3854 is an injection flaw in git push handling where user-controlled push options were unsafely embedded into an internal header and later parsed with delimiter-based logic that allowed fields to be overwritten. This enabled attackers to modify security-critical configuration values in backend services, leading to remote code execution on GitHub.com and full server compromise on GitHub Enterprise Server. CVE-2026-3854 was assigned CVSS 8.7, with GitHub releasing patches for GitHub.com and GitHub Enterprise Server versions 3.14.24 through 3.19.3 after initial mitigation on GitHub.com.

VECT 2.0 ransomware destroys large files via flawed encryption design

VECT 2.0 ransomware targets Windows, Linux and ESXi systems, with a flawed encryption design that permanently destroys files larger than 131KB. Check Point Research reports the malware discards required ChaCha20 nonces during encryption, making large file recovery impossible even for operators or victims. The ransomware-as-a-service operation partners with BreachForums and TeamPCP, with limited reported victims and supply-chain distribution despite presenting itself as ransomware.

Windows Shell spoofing flaw actively exploited in the wild

CVE-2026-32202 is a Windows Shell spoofing vulnerability with CVSS 4.3 that requires user execution of a malicious file to trigger over a network. Microsoft confirmed exploitation in the wild after revising its advisory, noting the issue stems from an incomplete patch for a prior Windows Shell flaw CVE-2026-21510. Attack chains leverage specially crafted LNK files using UNC paths to trigger SMB connections that coerce NTLM authentication and expose Net-NTLMv2 hashes for relay or cracking.

LiteLLM SQL injection flaw actively exploited for secret theft

LiteLLM CVE-2026-42208 is a pre-auth SQL injection in proxy API key verification, triggered via crafted Authorization headers to /chat/completions endpoint. Exploitation began approximately 36 hours after public disclosure, with Sysdig observing targeted queries against database tables containing API keys, provider credentials and configuration data. Successful exploitation enables unauthenticated database read and modification of LiteLLM-managed secrets, with mitigation delivered in version 1.83.7 using parameterised queries replacing unsafe concatenation.

Medtronic confirms corporate IT data breach after ShinyHunters claims

Medtronic confirmed a data security incident affecting corporate IT systems after ShinyHunters claimed responsibility on its leak site in mid-April. The company stated unauthorised access to internal systems, no disruption to products, patient safety or operations, and hospital networks were not affected. ShinyHunters alleged over nine million records exfiltrated and internal corporate data, later removing Medtronic from leak site while investigation into scope continues.

Vimeo confirms third-party breach exposing user data via Anodot

Vimeo reported Anodot third-party breach leading to unauthorised access to Vimeo user and customer data, including technical data, video titles, metadata, and some email addresses. The accessed datasets excluded video content, login credentials and payment card information, while Vimeo confirmed no service disruption and disabled Anodot integration during investigation.

Daily Coverage

Developments
Github RceLitellm SqliWindows Shell ExploitMedtronic Breach
Vulnerabilities
CVE-2026-3854CVE-2026-42208CVE-2024-1708CVE-2026-32202Windows 10 Version 1607 10.0.14393.0 (Medium)CVE-2026-21510CVE-2026-41940Cpanel 11.110.0 (Critical)
Threat Groups
PlayPlay is a ransomware group that has been active since at least 2022 deploying Playcrypt ransomware against the business, government, critical infrastructure, healthcare, and media sectors in North America, South America, and Europe. Play actors employ a doubleextortion model, encrypting systems after exfiltrating data, and are presumed by security researchers to operate as a closed group.Silk TyphoonHAFNIUM is a likely statesponsored cyber espionage group operating out of China that has been active since at least January 2021. HAFNIUM primarily targets entities in the US across a number of industry sectors, including infectious disease researchers, law firms, higher education institutions, defense contractors, policy think tanks, and NGOs. HAFNIUM has targeted remote management tools and cloud software for intial access and has demonstrated an ability to quickly operationalize exploits for identified vulnerabilities in edge devices.LAPSUS$LAPSUS$ is cyber criminal threat group that has been active since at least mid2021. LAPSUS$ specializes in largescale social engineering and extortion operations, including destructive attacks without the use of ransomware. The group has targeted organizations globally, including in the government, manufacturing, higher education, energy, healthcare, technology, telecommunications, and media sectors.Scattered SpiderScattered Spider is a native Englishspeaking cybercriminal group active since at least 2022. The group initially targeted customer relationship management (CRM) providers, business process outsourcing (BPO) firms, and telecommunications and technology companies before expanding in 2023 to gaming, hospitality, retail, managed service provider (MSP), manufacturing, and financial sectors. Scattered Spider relies heavily on social engineering, including impersonating IT and helpdesk staff, to gain initial access, bypass multifactor authentication (MFA), and compromise enterprise networks. The group has adapted its tooling to evade endpoint detection and response (EDR) defenses and used ransomware for financial gain. Scattered Spider had expanded into hybrid cloud and identity environments, using helpdesk impersonation and MFA bypass to obtain administrator access in Okta, AWS, and Office 365.