Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks
Daily Cybersecurity Briefing (30 April 2026)
Published: Loading…
At a Glance
- Attackers compromised SAP npm packages using preinstall scripts to steal CI/CD secrets, GitHub tokens, and cloud credentials, propagating through developer environments.
- Critical cPanel vulnerability CVE-2026-41940 enabled unauthenticated access to hosting control panels, allowing attackers to control websites, databases, and entire servers.
- Qinglong task scheduler flaws CVE-2026-3965 and CVE-2026-4047 enabled unauthenticated RCE, deploying .fullgc cryptominers that consumed up to 100 percent CPU.
- GitHub remote code execution vulnerability CVE-2026-3854 exposed millions of private repositories to unauthorised access before being patched in early March.
- CISA added ConnectWise ScreenConnect CVE-2024-1708 and Windows CVE-2026-32202 to KEV catalogue following confirmed active exploitation in the wild.
- Phoenix phishing-as-a-service platform used SMS campaigns, rogue BTS injection, and geofencing to target over 70 organisations and harvest financial credentials.
Summary
Supply chain attacks escalated across development ecosystems, with compromised SAP npm packages executing malicious preinstall scripts that harvested CI/CD secrets, GitHub tokens, and cloud credentials from developer systems. The campaign used automated propagation techniques to spread through repositories and environments by abusing stolen authentication tokens. Separate malicious npm activity included brand-squatted packages and dependencies exfiltrating environment variables and targeting crypto wallets.
Widespread vulnerabilities in internet-facing platforms exposed critical infrastructure to compromise, including a severe cPanel authentication bypass flaw allowing unauthorised access to hosting control panels and server environments. A separate GitHub remote code execution vulnerability enabled potential access to millions of private repositories before remediation. Additional exposure included dozens of vulnerabilities in OpenEMR systems and large numbers of internet-facing VNC servers linked to industrial control environments.
Active exploitation of high-severity flaws continued across multiple platforms, with Qinglong task scheduler vulnerabilities enabling unauthenticated remote code execution and deployment of persistent cryptominers consuming significant system resources. The LiteLLM SQL injection vulnerability was exploited within 36 hours of disclosure to access and modify database contents. Browser updates for Chrome and Firefox addressed critical flaws enabling arbitrary code execution, including hundreds of vulnerabilities identified in Firefox.
Phishing and social engineering operations expanded through scalable infrastructure, with the Phoenix System phishing-as-a-service platform delivering global smishing campaigns targeting financial, telecoms, and logistics sectors. The platform used rogue base transceiver stations, geofencing, and real-time victim interaction to harvest credentials and intercept one-time passwords. Additional campaigns abused legitimate platforms such as Kuse to host phishing content and impersonate trusted services.
Government and regulatory actions highlighted ongoing exploitation risks, with CISA adding actively exploited vulnerabilities in ConnectWise ScreenConnect and Microsoft Windows to the Known Exploited Vulnerabilities catalogue. A separate Windows flaw involving zero-click exploitation was also reported as actively targeted in attacks.
Highlights of the Day
Malicious SAP npm Packages Steal Credentials via Preinstall Scripts
Threat actors linked to TeamPCP compromised SAP CAP-related npm packages including @cap-js/sqlite, @cap-js/postgres, @cap-js/db-service, and mbt by injecting preinstall scripts that execute during dependency installation. The scripts download a Bun runtime and run an obfuscated payload that harvests credentials from developer systems and CI/CD environments, including GitHub tokens, cloud secrets, Kubernetes configs, and browser-stored passwords. Stolen data is encrypted and exfiltrated via attacker-controlled GitHub repositories, while the malware also propagates using compromised npm tokens and extracts secrets directly from CI runner memory.
WordPress Plugin Author Backdoored Sites via Hidden Update Channel
A WordPress plugin author inserted a hidden update mechanism into Quick Page/Post Redirect Plugin versions 5.2.1 and 5.2.2, directing sites to fetch updates from anadnet.com outside the official repository. The remote server distributed a tampered 5.2.3 version containing code that injected third-party content into public pages and silently contacted attacker infrastructure using request metadata. The malicious package also enabled remote code execution by delivering updates with full plugin permissions, affecting installations that polled the external update endpoint between March 10 and March 17, 2021.
Attackers Exploit CI/CD Pipelines to Steal Secrets at Scale
Threat actors increasingly target CI/CD pipelines by modifying workflow files using stolen developer credentials, enabling large-scale secret exfiltration from environments containing cloud tokens, registry credentials, and code signing keys. Campaigns including GhostAction compromised 327 GitHub users across 817 repositories and extracted 3,325 secrets, while HackerBot-Claw exploited pull_request_target misconfigurations to compromise repositories and expose 33,000 secrets across nearly 7,000 systems. Techniques include injecting malicious pipeline code, abusing privileged triggers, harvesting secrets from runner memory, and propagating through compromised tokens to infect additional repositories and packages.
Phoenix Smishing Platform Drives Global Phishing Campaigns via Telegram
Group-IB identified a phishing-as-a-service platform named Phoenix System used since January 2025 to run global smishing campaigns, with over 2,500 phishing domains targeting more than 70 organisations across finance, telecoms, and logistics sectors. The platform delivers SMS phishing messages, including via rogue base transceiver stations, and uses geofencing, IP filtering, and device checks to present credential-harvesting pages requesting personal and payment data. Its administrative panel enables real-time victim monitoring, OTP interception, and credential exfiltration, while being distributed through Telegram channels as a subscription service costing around $2,000 annually.
Qinglong RCE Flaws Exploited to Deploy Cryptominers
Attackers exploited two authentication bypass vulnerabilities in Qinglong task scheduler versions 2.20.1 and earlier, tracked as CVE-2026-3965 and CVE-2026-4047, enabling unauthorised remote code execution on exposed panels. The flaws allowed credential resets via URL rewriting and direct command execution through case-sensitive path mismatches, granting full administrative control without authentication. Since early February 2026, attackers have used these access paths to deploy a .fullgc cryptominer that downloads binaries, runs persistently in the background, and consumes up to 100% CPU on compromised systems.
Critical cPanel Auth Bypass Bug Grants Unauthorised Server Access
A critical authentication bypass vulnerability tracked as CVE-2026-41940 with a 9.8 severity score affected most supported cPanel and WHM versions, allowing attackers to access control panels without credentials. Hosting provider Namecheap temporarily blocked ports 2083 and 2087 to mitigate exposure while patches were released for multiple versions including 11.110.0.97 and 11.136.0.5. Successful exploitation could grant full control over hosted websites, databases and email accounts, or entire servers via WHM, enabling data theft, malware deployment, account manipulation and persistent access.
CISA Flags Actively Exploited ConnectWise and Windows Flaws
CISA has added CVE-2024-1708 affecting ConnectWise ScreenConnect and CVE-2026-32202 impacting Microsoft Windows to its Known Exploited Vulnerabilities catalogue, citing confirmed active exploitation in the wild. The ScreenConnect flaw is a path traversal vulnerability, while the Windows issue involves a protection mechanism failure that could be leveraged by attackers to bypass security controls. Both vulnerabilities are now classified as high-risk threats to federal systems under Binding Operational Directive 22-01.
Daily Coverage