Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks
Daily Cybersecurity Briefing (4 May 2026)
Published: Loading…
At a Glance
- CISA added Linux kernel flaw CVE-2026-31431 to the KEV catalogue following evidence of active exploitation enabling local privilege escalation on affected systems.
- Attackers abuse Telegram Mini Apps via FEMITBOT infrastructure to deliver phishing dashboards, impersonate brands, run crypto scams, and distribute malicious Android APK files.
- Instructure confirmed a breach exposing Canvas user data including emails, student IDs, and messages, while ShinyHunters claimed theft affecting hundreds of millions of records.
- ConsentFix v3 automates Azure OAuth phishing by capturing authorisation codes via phishing pages and exchanging them for tokens to access Microsoft services.
- Critical cPanel vulnerability CVE-2026-41940 is being mass-exploited to breach websites and deploy 'Sorry' ransomware encrypting compromised server data.
- Microsoft Defender falsely detected DigiCert root certificates as malware, triggering widespread certificate removal and security alert disruptions across Windows systems.
Summary
CVE-2026-31431 affecting the Linux kernel has been added to the KEV catalogue following confirmed active exploitation enabling local privilege escalation across impacted systems. A separate cPanel vulnerability CVE-2026-41940 is being mass-exploited to breach websites and deploy “Sorry” ransomware encrypting compromised server environments.
Large-scale phishing and fraud activity is leveraging Telegram Mini Apps through FEMITBOT infrastructure to impersonate major brands and deliver crypto investment scams. The campaigns use embedded WebView phishing dashboards, shared backend APIs, and malicious Android APK distribution to capture funds and deploy malware.
The ConsentFix v3 technique automates OAuth phishing attacks against Microsoft Azure by harvesting authorisation codes through phishing workflows and exchanging them for access tokens. Attackers use cloud-hosted phishing pages and automation platforms to collect tokens in real time and access Microsoft services tied to compromised accounts.
Instructure confirmed a cyberattack exposing Canvas platform data including names, email addresses, student identifiers, and user messages across affected institutions. The ShinyHunters extortion group claimed responsibility and alleged theft of hundreds of millions of records spanning global educational organisations.
A breach at Trellix exposed part of its internal source code repository following unauthorised access, with investigation ongoing and law enforcement notified. Separately, Microsoft Defender generated false positives identifying DigiCert root certificates as malware, resulting in certificate removals and operational disruptions on Windows systems.
The UK’s National Cyber Security Centre warned that AI-driven vulnerability discovery is accelerating exposure of longstanding software weaknesses across ecosystems. The expected surge in disclosed vulnerabilities is driving a significant increase in required patches across open source, commercial, and SaaS platforms.
Highlights of the Day
Instructure Confirms Data Breach as ShinyHunters Claims Theft
Instructure confirmed a cyberattack exposing user data from its Canvas learning platform, including names, email addresses, student ID numbers, and user messages, while passwords and financial data were not affected. The company is investigating with external experts and law enforcement, and has applied patches, increased monitoring, and rotated application keys requiring customers to re-authorise API access. The ShinyHunters extortion group claimed responsibility, alleging theft of hundreds of millions of records and data spanning thousands of educational institutions globally.
CISA Flags Actively Exploited Linux Kernel Vulnerability
CISA added CVE-2026-31431, an incorrect resource transfer between spheres flaw in the Linux kernel, to its Known Exploited Vulnerabilities catalogue based on evidence of active exploitation. The vulnerability class is commonly used by threat actors as an attack vector and poses risks to federal enterprise systems. Under Binding Operational Directive 22-01, US federal civilian agencies are required to remediate listed vulnerabilities by specified deadlines to protect networks from ongoing threats.
ConsentFix v3 Automates OAuth Phishing Attacks on Azure
ConsentFix v3 is a newly promoted attack technique that automates OAuth2 abuse against Microsoft Azure by exploiting pre-trusted first-party applications and harvesting authorisation codes through phishing workflows. Attackers use personalised emails, Cloudflare-hosted phishing pages, and Pipedream automation to capture OAuth codes, exchange them for refresh tokens via Microsoft APIs, and collect them centrally in real time. The stolen tokens are then imported into Specter Portal, enabling access to Microsoft services such as email and files based on the compromised account’s permissions.
NCSC Warns AI Will Trigger Surge in Vulnerability Patches
The UK National Cyber Security Centre warns that AI-assisted bug discovery is exposing longstanding technical debt across software ecosystems, accelerating identification of vulnerabilities at scale and pace. The agency expects a surge of software updates across open source, commercial, proprietary and SaaS platforms, including numerous critical flaws requiring rapid remediation. Attackers and defenders alike are leveraging AI tools to uncover weaknesses, increasing the volume of disclosed vulnerabilities and driving a large-scale influx of required patches.
Trellix Confirms Breach of Internal Source Code Repository
Trellix disclosed unauthorised access to a portion of its internal source code repository, prompting an investigation with external forensic experts and notification to law enforcement authorities. The company stated it has found no evidence that its source code release or distribution processes were compromised or that accessed code has been exploited by attackers. Trellix did not identify the threat actor, duration of access, or specific data involved, and said further details will follow after the investigation concludes.
Telegram Mini Apps Exploited for Crypto Scams and Malware
Researchers identified a fraud platform called FEMITBOT that abuses Telegram Mini Apps and bots to deliver phishing pages, impersonate major brands, and run cryptocurrency investment scams. The operation uses shared backend infrastructure, phishing domains, and in-app WebView pages to display fake dashboards, prompting victims to deposit funds or complete tasks to withdraw earnings. Some campaigns also distribute malicious Android APKs disguised as legitimate apps, hosted on attacker-controlled domains and delivered through Telegram Mini Apps and embedded links.
Daily Coverage