Skip to content
Marcus Reed | CISO Intel

Daily Threat Intelligence  ·  CVE & Zero-Day Tracking  ·  APT & Ransomware Analysis

Go back

CISO Intel Brief — Thursday, 02-04-2026

🛡️ CISO Intel — Thursday, 02-04-2026

Due to API rate limiting, here is today’s briefing:

Alright, team. Thursday. Weekend’s close enough that orgs start getting sloppy. Perfect timing for a threat actor to move laterally. Let’s get to it.

🔴 Critical Threats & Active Exploitation

Google ChromeCVE-2026-5281 (CVSS 8.8) — Use-after-free in Dawn WebGPU component. This is being actively exploited in the wild. Attackers can execute arbitrary code via a crafted HTML page, potentially leading to sandbox escape and system compromise. Google pushed an emergency update. Patch your damn browsers. Fortinet FortiClient EMSCVE-2026-21643 (CVSS 9.1-9.8) — Pre-authentication SQL injection. Unauthenticated remote code execution via crafted HTTP requests. Thousands of instances are exposed online, and there’s active chatter about in-the-wild exploitation. You need to verify if you’re running this and patch immediately.

🛡️ CVEs Worth Your Attention

CVE-2026-5289 | Google Chrome v146.0.7680.178 | CVSS 9.6 | Sandbox escape via crafted HTML page after renderer process compromise. This is a high-severity use-after-free in the Navigation component. PoC: No (but the impact is clear). CVE-2026-34204 | MinIO (prior to RELEASE.2026-03-26T21-24-40Z) | CVSS not specified yet, but likely high | Authenticated users with s3:PutObject permission can inject internal server-side encryption metadata via crafted X-Minio-Replication-* headers, leading to potential privilege escalation or data manipulation. PoC: No (but the method is described).

⚡ New TTPs & Attack Research

Axios Supply Chain Attack: North Korea-linked APT group UNC1069 compromised an Axios npm maintainer account, distributing malicious versions (v1.14.1 and v0.30.4) with a hidden dependency plain-crypto-js. This injected a cross-platform RAT (Waveshaper v2) capable of reconnaissance, persistence, and remote command execution on Windows, macOS, and Linux. T1195.002 (Supply Chain Compromise: Compromise Software Supply Chain) and T1558.003 (Steal or Forge Kerberos Tickets: Kerberoasting) if they move to AD. The malware also had a self-destruct feature. Clever. ⚡ LiteLLM and Telnyx PyPI Backdoors: Malicious versions of LiteLLM (1.82.7, 1.82.8) and Telnyx (4.87.1, 4.87.2) Python packages were compromised in a broader campaign dubbed TeamPCP. The LiteLLM backdoor used a malicious .pth file for automatic execution on Python interpreter start, while Telnyx downloaded a hidden second-stage payload from a WAV file. T1195.002 (Supply Chain Compromise: Compromise Software Supply Chain). ⚡ CrystalX RAT: New Malware-as-a-Service (MaaS) discovered, offering data stealing (credentials from Telegram, Discord, Steam, browsers), spyware, keylogging, and clipboard modification. It also includes “prankware” capabilities. T1059.003 (Command and Scripting Interpreter: Windows Command Shell) for execution, T1558.003 (Credential Access: Kerberoasting) for potential lateral movement. ⚡ WhatsApp Malware Campaign: Microsoft Defender Experts reported a new campaign using malicious VBS files distributed via WhatsApp. It uses social engineering, delayed execution, and living-off-the-land (LOTL) techniques with renamed legitimate Windows utilities (curl.exe, bitsadmin.exe) to maintain persistence and establish remote access. T1204.002 (User Execution: Malicious File), T1059.005 (Command and Scripting Interpreter: Visual Basic), T1036.003 (Masquerading: Rename System Utilities). 🧪 Infostealer to Ransomware Pipeline: New research highlights that credentials from infostealer infections are often sold on dark web marketplaces within 24-48 hours. Ransomware deployment can follow within 48 hours of credential exposure. This is a critical window for defenders. T1078 (Valid Accounts), T1550 (Use Alternate Authentication Material).

🏗️ DevSecOps & Cloud Security

Axios npm Supply Chain Attack: This is a major hit to the JavaScript ecosystem. If you use Axios in your web apps, Node.js services, or CI/CD pipelines, you need to audit for malicious versions 1.14.1 and 0.30.4 and the injected plain-crypto-js package. This impacts Windows, macOS, and Linux. LiteLLM & Telnyx PyPI Compromise: Another supply chain hit, this time on Python packages. If your projects depend on LiteLLM or Telnyx, check for compromised versions and scan for credential exfiltration.

🔧 Patches & Vendor Releases

Google Chrome — Version 146.0.7680.177/178 (Windows/macOS) and 146.0.7680.177 (Linux) released to fix CVE-2026-5281 and other high-severity flaws. 🟢 solid fix. Update immediately. MinIO — Version RELEASE.2026-03-26T21-24-40Z patches CVE-2026-34204. 🟢 solid fix. Apply if you’re running MinIO.

🧪 Threat Intel & Malware

Pay2Key Ransomware Resurfaces: Iran-linked Pay2Key ransomware group is back with upgraded tactics. They used self-extracting 7zip archives for rapid encryption and a “No Defender” evasion toolkit. No data exfiltration was observed, suggesting deliberate evidence destruction. Geopolitical tensions are accelerating their activity. BASANAI Ransomware: A new variant from the MedusaLocker family, encrypting files and appending .BASANAI extension. Ransom note read_to_decrypt_files.html. Standard ransomware TTPs, but always good to know the new players. APT Iran Targeting Lockheed Martin: Alleged pro-Iranian hacktivist group APT Iran claims to have exfiltrated 375TB of sensitive data, including F-35 blueprints, from Lockheed Martin. Claims are unverified, but it’s a significant geopolitical cyber activity to watch. This group often uses “hacktivist” personas to obscure state-aligned objectives. T1020 (Automated Exfiltration).

🌐 Industry, Brand & Internet Security

Mercor AI Data Breach: Mercor AI confirmed a 4TB data breach linked to the LiteLLM supply chain attack. Lapsus$ claimed responsibility, stealing source code, internal databases, and user-verification data via a Tailscale VPN breach. This highlights the cascading risk of supply chain compromises. Marquis Fintech Ransomware Attack: A ransomware attack at fintech firm Marquis exposed data of 672,075 people, including names, SSNs, and financial details. Hackers reportedly accessed firewall configuration files, possibly from SonicWall, to map the network. Third-party risk is a killer. Aura Data Breach: Hacking group ShinyHunters used phone phishing to breach Aura, gaining access to an employee’s account for an hour and exfiltrating 900,000 records (names, emails, addresses, phone numbers) of 35,000 customers. Simple phishing, massive impact. Hightower Holding Cyberattack: Hightower Holding suffered a cyberattack in January 2026, leading to the exfiltration of sensitive personal information like names, SSNs, and driver’s license numbers. Advantage Media Services Data Breach: An unauthorized actor accessed AMS servers in September 2025, copying data including full names, SSNs, dates of birth, and government IDs. Disclosed to multiple state attorneys general in late March 2026. CareCloud Healthcare Data Breach: Healthcare tech firm CareCloud confirmed a breach where hackers accessed one of its electronic medical record storage environments for about 8 hours. Affects potentially millions of Americans. Drift Protocol Hacked for $270M-$285M: A major DeFi platform on Solana suffered a massive exploit, with assets rapidly moved to a single wallet. Preliminary assessment points to compromised administrator private keys. This is the second-largest exploit in Solana history. FBI Warns of China-Made Mobile App Risks: FBI issued a warning about data security risks associated with mobile apps made in China. This follows recent bans on foreign-made consumer routers.

📋 Compliance & Regulatory

[Clear — enjoy it]

💡 Marcus’s Take

Another day, another pile of supply chain hits and zero-days. The Axios and LiteLLM compromises are a stark reminder that your software dependencies are now your perimeter. Defenders need to pivot from just securing their own code to actively monitoring their entire software supply chain for malicious injections. The speed at which infostealers lead to ransomware (48 hours!) means detection and response times are utterly critical. If you’re not patching Chrome and your dev tools within hours, you’re already losing. And for the love of god, enforce MFA everywhere and review admin privileges. The weekend’s coming, don’t be the low-hanging fruit.


Share this post on:

Previous Post
CISO Intel Brief — Friday, 03-04-2026
Next Post
CISO Intel Brief — Wednesday, 01-04-2026