🛡️ CISO Intel — Monday, 13-04-2026
Due to API rate limiting, here is today’s briefing:
Alright, let’s see what kind of Monday morning garbage the threat actors shipped. Had all weekend to brew something nasty, didn’t they? Here’s the intel, cut the fluff.
🔴 Critical Threats & Active Exploitation
Adobe Acrobat/Reader — CVE-2026-34621 (CVSS 8.6) — This is a zero-day, prototype pollution leading to arbitrary code execution. Actively exploited since at least November 2025, likely by an APT, using Russian-language lures. Adobe patched it, but if you’re running older versions, you’re exposed. Get the patch NOW.
Marimo — CVE-2026-39987 (CVSS 9.3) — Critical pre-authentication RCE in the open-source Python notebook environment. Exploited within 10 hours of public disclosure. Attackers are targeting .env credentials and SSH keys. If you’re using Marimo as an editable notebook and exposed it, you need to patch to v0.23.0 immediately and rotate keys. This is a fast-moving target.
APT28 (Fancy Bear) — These Russian state-sponsored clowns are still at it. FBI disrupted a long-running DNS hijacking operation, compromising US-based routers to redirect traffic. Good on the FBI for the proactive “unplugging,” but this group is relentless and will find another way. T1595.002, T1071.004.
🛡️ CVEs Worth Your Attention
CVE-2026-31829 | Flowise | CVSS Medium (implied, SSRF) | Server-Side Request Forgery in HTTP Node, internal network access possible. PoC: Yes (implied by research).
CVE-2026-31818 | Budibase | CVSS Critical (implied, SSRF) | SSRF via REST Connector, unauthorized internal resource access. PoC: Yes (implied by research).
CVE-2026-35459 | pyLoad | CVSS Critical (implied, SSRF) | SSRF filter bypass, incomplete fix for CVE-2026-33992. Cloud metadata exfiltration risk. PoC: Yes (implied by research).
CVE-2026-33752 | curl_cffi | CVSS Medium (implied, SSRF) | Redirect-based SSRF, internal network access with TLS impersonation bypass. PoC: Yes (implied by research).
CVE-2026-40395 | Varnish Enterprise < 6.0.16r12 | CVSS 4.0 (Medium) | Workspace overflow leading to daemon panic (DoS) for shared VCL. Remotely exploitable. PoC: Yes (implied by details).
CVE-2026-40385 | libexif < 0.6.25 | CVSS 4.0 (Medium) | Unsigned 32-bit integer overflow in Nikon MakerNote handling, local attacker can crash or leak info (32bit systems only). PoC: No (not explicitly stated, but commit reference available).
CVE-2026-0628 | Google Chrome (Gemini AI feature) | CVSS High (implied) | Insufficient policy enforcement in WebView tag, allowing malicious extensions to inject scripts/HTML into privileged pages. Can hijack Gemini panel for system resource access. Patch: Yes (Chrome 143.0.7499.192 and later).
CVE-2026-34078 | Flatpak 1.16.4 | CVSS Critical (implied) | Complete sandbox escape leading to host file access and code execution. Patch: Yes (Flatpak 1.16.4).
CVE-2026-31790, CVE-2026-2673 | OpenSSL 3.6.2 | CVSS Moderate (implied) | Various fixes including incorrect failure handling in RSA KEM and loss of key agreement group structure. Patch: Yes (OpenSSL 3.6.2).
⚡ New TTPs & Attack Research
AI-Powered Zero-Day Discovery: Anthropic’s Claude Mythos is reportedly finding “thousands” of zero-days. This is a game-changer. While currently used by defenders, the implications for offensive capabilities are massive. Expect more sophisticated and rapid vulnerability discovery from all sides. T1589.002, T1589.003.
Stealthy Credential Theft via Marimo RCE: Attackers exploiting CVE-2026-39987 are focused on quickly exfiltrating .env files and SSH keys, without installing persistence or cryptominers. This indicates a targeted, hands-on operator seeking high-value access, not just opportunistic defacement. T1552.001, T1552.004.
AI Agent Data Exposure: Research highlights that AI agents, if granted excessive network access without runtime validation, can make accidental data exposure more likely. This is due to the AI’s ability to access sensitive content a user technically has permission to, even if they shouldn’t. A new attack surface. T1589.003.
🏗️ DevSecOps & Cloud Security
OpenAI Supply Chain Hit: A North Korea-linked group compromised Axios, a developer tool, impacting OpenAI’s macOS app-signing workflow. No user data compromised, but it forced OpenAI to rotate certificates. Highlights the persistent risk of supply chain attacks, especially for critical infrastructure like signing processes. T1195.002.
Marimo RCE Impact: The active exploitation of CVE-2026-39987 in Marimo (a Python notebook environment) is a stark reminder for data scientists and ML/AI practitioners. If exposed to a shared network in edit mode, it’s a direct path to RCE and credential theft. Secure your dev environments!
🔧 Patches & Vendor Releases
Adobe Acrobat/Reader — Patches released for CVE-2026-34621. 🟢 solid fix, but the CVSS score was adjusted from 9.6 to 8.6 by changing the attack vector from Network to Local. Still, it’s a zero-day, patch it.
Marimo — Version 0.23.0 released to address CVE-2026-39987. 🟢 solid fix. Update immediately.
Varnish Enterprise — Update to 6.0.16r12 or later for CVE-2026-40395 (DoS). 🟢 solid fix.
OpenSSL — Version 3.6.2 released with fixes for eight CVEs, including CVE-2026-31790 and CVE-2026-2673. 🟢 solid fix.
Flatpak — Version 1.16.4 released, patching CVE-2026-34078 (sandbox escape). 🟢 solid fix.
Google Chrome — Version 143.0.7499.192 fixes CVE-2026-0628 affecting the Gemini AI feature. 🟢 solid fix.
🧪 Threat Intel & Malware
Payload Ransomware Group: A new, technically sophisticated ransomware group, “Payload,” has emerged since February 2026. They’re doing double extortion, hitting 26 victims across 7 countries. They use ESXi-specific encryption, ETW patching (T1562.001) for EDR evasion, and their Windows variant is derived from Babuk. Their mutex MakeAmericaGreatAgain is a clear operator fingerprint. T1486, T1070.004.
Blackwater Ransomware: This group claimed “medical-park” as a victim on April 12, 2026, with an estimated attack date of March 20, 2026. Standard leak site activity.
Qilin Ransomware: Claimed responsibility for an attack against the German political party “Die Linke,” causing IT outages and threatening data leaks.
🌐 Industry, Brand & Internet Security
Spring Lake Park Schools Ransomware: A school district in Minnesota had to cancel classes due to a suspected ransomware attack, forcing them to shut down systems. This is a direct operational impact.
Mercor Data Breach: This $10 billion AI startup (provides training data to OpenAI, Anthropic, Meta) confirmed a major data breach, possibly linked to the LiteLLM supply chain attack. Attackers claim source code and database records.
AI in Cybersecurity Landscape Shift: The discussion around AI finding zero-days and increasing accidental data exposure means boards are going to be asking about your AI security strategy. Not just how you use AI, but how you secure against AI-driven threats and how your data is protected from AI agents.
📋 Compliance & Regulatory
[Clear — enjoy it]
💡 Marcus’s Take
This weekend just proved what I’ve been screaming about: the adversary doesn’t rest. Two critical RCEs, actively exploited, one within hours of disclosure, the other for months. This is a wake-up call for everyone still relying on “eventual patching.” Your time to patch is now measured in hours, not days or weeks. And don’t get me started on AI. It’s a double-edged sword: great for finding bugs, terrifying for creating new attack surfaces and accelerating exploitation. If your incident response plan doesn’t account for AI-driven threats and zero-day compression, you’re already behind. Prioritize patching, secure your dev environments, and assume compromise. The fundamentals still matter, but the speed of the game has changed.