Skip to content
Marcus Reed | CISO Intel

Daily Threat Intelligence  ·  CVE & Zero-Day Tracking  ·  APT & Ransomware Analysis

Go back

CISO Intel Brief — Sunday, 05-04-2026

🛡️ CISO Intel — Sunday, 05-04-2026

Due to API rate limiting, here is today’s briefing:

Alright, let’s cut through the Sunday brunch haze. While most of you were offline, the bad guys weren’t. We’ve got some nasty stuff dropping, especially around supply chain and AI. Pay attention.

🔴 Critical Threats & Active Exploitation

Google ChromeCVE-2026-5281 (High) — Use-after-free in Dawn (WebGPU) actively exploited. This allows remote code execution. Fourth Chrome zero-day this year. Patch now. Don’t wait for auto-updates. Fortinet FortiClient EMSCVE-2026-35616 (Critical) — Improper access control, API authentication bypass. Unauthenticated RCE. Actively exploited in the wild. Get the hotfixes on 7.4.5 and 7.4.6 immediately. Stop putting management interfaces on the internet, folks. Microsoft SharePoint Servers (on-premise)CVE-2025-53770, CVE-2025-53771 (Critical) — These are evolutions of older flaws, still leading to unauthenticated RCE via deserialization and ViewState abuse. Actively exploited across finance, education, energy, healthcare. If you’re running old SharePoint, you’re a sitting duck.

🛡️ CVEs Worth Your Attention

CVE-2026-3184 | util-linux | (No CVSS yet, but unauthorized access) | Improper hostname canonicalization in login(1) can bypass PAM host-based access controls. Patch available. CVE-2026-0737 | WP Shortcodes Plugin - Shortcodes Ultimate v7.4.7 | (No CVSS yet, Stored XSS) | Stored Cross-Site Scripting via su_lightbox shortcode. Authenticated attackers (contributor+) can inject web scripts. Not great, not terrible for a WordPress plugin. CVE-2018-25251 | Snes9K 0.0.9z | CVSS 4.0: 8.6 (High) | Buffer overflow in Netplay Socket Port Number. Local attackers can get code execution. Old software, but high impact if present.

⚡ New TTPs & Attack Research

Slopsquatting (AI Hallucination Exploitation) ⚡: Attackers are weaponizing AI’s tendency to “hallucinate” non-existent package names. They register these names on public registries. When developers or autonomous AI agents try to install these, they get malware. This is a new, scalable supply chain vector, distinct from typosquatting. T1195.002 variant. AI-enabled Autonomous Cyberattacks 🧪: Reports indicate Anthropic has a model capable of independent, sophisticated cyberattacks. Government officials are getting briefed. This isn’t theoretical anymore; it’s a new era for offensive capabilities. AI Agent Hacking FreeBSD ⚡: An AI agent successfully exploited a FreeBSD vulnerability from an advisory in four hours. This accelerates the OODA loop for attackers significantly. ChatGPT Silent Data Exfiltration via DNS 🧪: Check Point Research found a way to exfiltrate sensitive data from ChatGPT via DNS tunneling. Bypasses prompt injection risks. Another reminder that AI systems have a hidden attack surface. T1071.004. Active Directory Attack Chains ⚡: New deep dives on exploiting AD, including AS-REP Roasting and Pass-the-Hash. Standard stuff, but a good refresher on T1558.003 and T1003.003 for red teams and blue teams alike.

🏗️ DevSecOps & Cloud Security

European Commission Data Breach (Trivy Supply Chain) 🏗️: Hackers (TeamPCP, ShinyHunters) stole 300GB from the EC’s AWS environment. Initial access was an API key compromised via the Trivy vulnerability scanner. They used TruffleHog for secret discovery and tried lateral movement. This is a direct hit on our CI/CD trust. LiteLLM Supply Chain Compromise 🏗️: AI recruiting firm Mercor hit by malicious LiteLLM packages containing credential-stealing malware (API keys, cloud secrets). Exploiting central AI integration points is a high-leverage move. UNC1069 Targeting Open-Source Maintainers 🏗️: North Korean nation-state actors are social engineering Node.js and npm package maintainers. Fake recruiters, spoofed meeting sites, delivering malware. They’re patient and can bypass MFA with tools like WAVESHAPER. T1195.002, T1566.001. Anthropic Claude Code Leak Exploitation 🏗️: Accidental source code leak led to malware-laced GitHub repos and sponsored Google search results. Infostealers distributed. Confusion is an attacker’s best friend. Open-Source AI Security Debt 🏗️: Rapid adoption of open-source AI components is creating massive, hidden security debt. We’re building on shaky ground without proper oversight. New Tool: CTWall (ChainThreatWall) 🏗️: Open-source CLI for detecting malicious packages in SBOMs, integrating with OSV and DepAlert. Good initiative, but still reactive.

🔧 Patches & Vendor Releases

Google Chrome: Emergency update out for CVE-2026-5281. 🟢 solid fix Fortinet FortiClient EMS: Emergency hotfixes available for CVE-2026-35616. 🟢 solid fix SUSE Linux: Updates for CVE-2026-3184 in util-linux. 🟢 solid fix

🧪 Threat Intel & Malware

Agenda Ransomware 🧪: New Golang ransomware hitting healthcare and education in Asia/Africa. Customized per victim, reboots in safe mode, stops services. Linked to “Qilin” on the dark web. Looks like a professional operation. Ransomware as a Service (RaaS) Evolution 🧪: RaaS is lowering the bar for entry into cybercrime. Multi-extortion is the norm now – data theft, leaks, operational disruption, DDoS. It’s about leverage, not just encryption. LummaStealer/Malgent Warning 🧪: Users reporting potential LummaStealer/Malgent after downloading from Anna’s Archive. Could be false positives, could be new variants. Stay vigilant on unofficial download sources.

🌐 Industry, Brand & Internet Security

Vivaticket Ransomware Attack: RansomHouse hit ticketing provider Vivaticket, disrupting major European museums (Louvre included). Stolen reservation data (names, emails, purchase history). Another third-party vendor, another massive blast radius. DocketWise Data Breach: Immigration case management software exposed ~116k individuals. PII, SSNs, financial, health info. Compromised via valid credentials cloning partner repositories. Identity is the new perimeter, again. Hims & Hers Data Breach: Telehealth company had support tickets stolen from Zendesk by ShinyHunters, via a compromised Okta SSO account. Names, contact, support details exposed. Medical records safe, but still a mess. LinkedIn “Browsergate” Allegations: Reports of massive corporate espionage/data harvesting by LinkedIn itself, blurring analytics and surveillance. Expect regulatory heat and user backlash. Qilin Ransomware claims Die Linke hack: Ransomware group claims to have hit German political party Die Linke. Party confirmed incident, not breach. Standard comms dance.

📋 Compliance & Regulatory

AI Security Compliance Services: The market is maturing for AI security compliance, with frameworks like CSA STAR for AI and OWASP Top 10 for LLM Apps emerging. Good, because “Shadow AI” is a real problem. Cybersecurity Reporting in Education: Education sector is a soft target. Reports need to speak the board’s language, not just technical jargon. Use frameworks like CIS Controls to bridge the gap. AI Cybersecurity Certifications: The market is full of fluff. Focus on certifications that align with real roles (SOC, cloud, GRC) and build on foundational cybersecurity knowledge. Don’t waste time on a “fast track” that leads nowhere.

💡 Marcus’s Take

This weekend highlights a clear and present danger: the AI supply chain is the new wild west. From “slopsquatting” leveraging LLM hallucinations to nation-state actors targeting open-source maintainers, and even AI models capable of autonomous attacks, we’re seeing an explosion of new attack vectors that exploit trust in our development ecosystem. Coupled with critical zero-days in widely used software and continued third-party breaches, defenders need to shift their focus. Assume every dependency, every AI integration, and every vendor is compromised. Verify everything. Your SBOMs need to be more than a checklist; they need to be an active threat detection tool.


Share this post on:

Previous Post
CISO Intel Brief — Monday, 06-04-2026
Next Post
CISO Intel Brief — Saturday, 04-04-2026