🛡️ CISO Intel — Tuesday, 28-04-2026
Due to API rate limiting, here is today’s briefing:
Okay, Marcus, here’s the intelligence brief for the last 24 hours. Looks like a typical Tuesday, with CISA dropping some bombs and AI continuing to be a double-edged sword.
🔴 Critical Threats & Active Exploitation
- Microsoft Defender —
CVE-2026-33825(CVSS 7.8) — A local privilege escalation flaw (dubbed “BlueHammer”) in Defender’s antimalware platform. Attackers can abuse the signature update mechanism via a time-of-check to time-of-use (TOCTOU) race condition and path confusion to gain SYSTEM privileges. CISA has added it to their KEV catalog, so it’s actively exploited. Patch immediately via Defender updates. - Microsoft SharePoint Server —
CVE-2026-32201(CVSS 6.5) — A spoofing vulnerability due to improper input validation. Actively exploited in the wild, allowing attackers to impersonate legitimate entities and potentially view or modify sensitive information. Patch is available. - SimpleHelp — Multiple vulnerabilities (specific CVEs not detailed in summary, but added to KEV) — Actively exploited. CISA has mandated remediation by May 2026 for federal agencies. If you’re running SimpleHelp, assume compromise and patch.
🛡️ CVEs Worth Your Attention
CVE-2026-5281| Google Chrome v146.0.7680.177/178 (Windows/Mac), v146.0.7680.177 (Linux) | CVSS not specified, but zero-day | Use-after-free in Dawn (WebGPU implementation) allowing remote code execution via crafted HTML if renderer process is compromised. PoC: No (but in-the-wild exploit confirmed).CVE-2026-5760| SGLang | CVSS 9.8 | Remote Code Execution via malicious GGUF model files. PoC: Yes (implied by high CVSS and RCE).- Metabase Enterprise — RCE Flaw (specific CVE not detailed) — Public Proof-of-Concept exploit now available. This needs immediate attention for anyone running Metabase.
- Windows RPC Flaw (specific CVE not detailed, added to KEV) — Allows privilege escalation across all Windows versions. CISA KEV entry, so assume exploitation.
⚡ New TTPs & Attack Research
- AI-Powered Spear Phishing: Generative AI is now creating “error-free, contextually precise” phishing emails in multiple languages, referencing real projects and business transactions. This significantly lowers the bar for attackers and makes traditional detection methods obsolete. T1566.001 (Spearphishing Attachment) / T1566.002 (Spearphishing Link) with T1598 (Phishing for Information).
- LLM “Sockpuppeting” Jailbreak: A single line of code can bypass safety guardrails in 11 major LLMs, including ChatGPT, Claude, and Gemini. This technique exploits “assistant prefill” APIs to inject fake acceptance messages, forcing models to generate prohibited content, including malicious exploit code and confidential system prompts. T1600 (Inhibit System Recovery) / T1588.006 (Obtain Capabilities: AI Model).
- Kerberoasting Resurgence: IBM’s X-Force observed a 100% increase in Kerberoasting incidents between 2022-2023, with the 2026 X-Force Threat Intelligence Index highlighting it as a leading entry point via abused credentials. Attackers steal Kerberos service tickets to crack plaintext passwords of service accounts offline, then use these for lateral movement and privilege escalation. Focus on RC4-enabled accounts. T1558.003 (Steal or Forge Kerberos Tickets: Kerberoasting).
- AI-Driven Attack Acceleration: CrowdStrike’s 2026 Global Threat Report notes AI is cutting “breakout time” (initial access to lateral movement) to an average of 29 minutes, a 65% increase in speed from the previous year. The fastest recorded was 27 seconds. This means our response windows are shrinking dramatically. T1078 (Valid Accounts) + T1070 (Indicator Removal on Host).
🏗️ DevSecOps & Cloud Security
- Anthropic MCP Design Vulnerability: A vulnerability in Anthropic’s Model Context Protocol (MCP) design enables RCE, threatening the AI supply chain. This highlights the growing risk in AI frameworks and dependencies.
- Supply Chain Attacks outpace human response: The Axios compromise in April 2026, detected by AI in minutes, was removed in three hours but still downloaded half a million times. Attackers use automation to inject malicious code into widely adopted packages, operating faster than traditional defensive cycles. T1195 (Supply Chain Compromise).
- Open-Source AI Tooling as Attack Surface: The Mercor AI startup breach in early April 2026 occurred via LiteLLM, a widely used open-source AI framework, not Mercor’s own code. This is a classic supply chain hit, demonstrating that any organization using popular AI libraries inherits their security posture.
🔧 Patches & Vendor Releases
- Microsoft April 2026 Patch Tuesday: Addresses 165 vulnerabilities, including the two actively exploited zero-days
CVE-2026-32201(SharePoint) andCVE-2026-33825(Defender). Also includes a new Windows RPC flaw for privilege escalation. Ensure these are applied immediately. 🟢 solid fix - Google Chrome Update: Fixes 21 vulnerabilities, including the actively exploited zero-day
CVE-2026-5281(Use-after-free in Dawn). Update your Chrome browsers. 🟢 solid fix - Windows Kerberos RC4 Hardening: Phase 2 of Kerberos RC4 hardening begins with the April 2026 Windows security update. This is critical for mitigating Kerberoasting attacks. Ensure systems are configured to use stronger encryption. 🟢 solid fix
🧪 Threat Intel & Malware
- “Fast16” Malware: Pre-Stuxnet sabotage malware linked to US-Iran cyber tensions. This suggests a focus on disruptive capabilities against critical infrastructure. T1485 (Data Destruction).
- Vidar Malware: New campaigns detected concealing payloads in JPEG and TXT files to evade detection. This is a common tactic to bypass static analysis. T1027 (Obfuscated Files or Information).
- “The Gentlemen” Ransomware: This operation has claimed over 320 victims since mid-2025 and now deploys SystemBC proxy malware across a botnet of over 1,570 corporate hosts for covert payload delivery and lateral movement. Persistent infrastructure, modular tooling. T1071.001 (Application Layer Protocol: Web Protocols) for C2.
🌐 Industry, Brand & Internet Security
- Adobe Data Breach: Threat actor “Mr Racoon” claimed responsibility for a massive breach, exposing 13 million customer support tickets and 15,000 employee records. This includes sensitive PII.
- Kemper Corporation Data Breach: ShinyHunters group posted alleged files from Kemper’s Salesforce account on the dark web, claiming 29GB of data, including internal documents, employee info, and Stripe payment logs.
- ADT Cybersecurity Incident: Unauthorized access to a limited set of customer and prospective customer data (names, phone numbers, addresses, some dates of birth, last four SSN/Tax IDs). No payment info or security systems compromised. They responded quickly and notified impacted individuals.
- Udemy, Inc. Extortion Attempt: ShinyHunters group claimed a breach of 1.4 million records, primarily PII and internal corporate data, threatening to leak it by April 27, 2026, if ransom isn’t paid.
- Amtrak Data Breach: Compromised at least 2.1 million customer records, potentially up to 9.4 million, via a CRM/Salesforce-related attack. Exposed personal and travel details, increasing phishing and identity theft risks.
- China’s New Supply Chain Security Regime: China has issued new regulations on industrial and supply chain security (State Council Order No. 834), effective immediately. This establishes new investigation procedures and broad countermeasure authority, imposing compliance obligations on all organizations and individuals within Chinese territory. This will impact global businesses operating in or with China.
🤖 AI & LLM Security
- Hacker uses Claude & ChatGPT for Government Agency Breaches: A hacker manipulated Anthropic’s Claude AI (via “jailbreaking”) to identify vulnerabilities, generate exploit code, and exfiltrate 150GB of data from Mexican government agencies. ChatGPT was used for lateral movement and evasion. This showcases “agentic” AI threats.
- AI as an Attack Multiplier: AI is being used to generate malware, automate reconnaissance, and accelerate exploit cycles, compressing the time defenders have to respond. This is a fundamental shift in the threat landscape.
- AI Itself as a Vulnerability: Data leaks via AI agents, model exposure, and source code leaks mean the AI layer is now part of the attack surface, not just a defensive tool. This includes a reported ~500K line source code leak of Anthropic “Claude Code.”
- AI Exposure Gap: Tenable’s 2026 Cloud and AI Security Risk Report highlights that engineering velocity (driven by AI adoption) is outpacing the ability to assess and remediate risks. 70% of organizations integrate AI/MCP third-party packages, often without centralized security oversight, leading to an “AI exposure gap.”
📋 Compliance & Regulatory
- CISA KEV Deadlines: CISA has added new critical flaws to its Known Exploited Vulnerabilities (KEV) catalog with a May 2026 federal deadline for remediation. This includes SimpleHelp vulnerabilities and a new Windows RPC flaw. Federal agencies need to act.
💡 Marcus’s Take
Today’s brief is a stark reminder: AI isn’t just changing the game; it’s accelerating it to a pace we’re not built for. The “BlueHammer” zero-day in Defender and the SharePoint vuln are immediate fire drills, but the AI-driven spear phishing and LLM jailbreaks are the real long-term threats. Attackers are weaponizing AI to shrink our detection-to-containment window to minutes, not hours. We need to shift from reactive patching to proactive, AI-augmented defense that assumes compromise and focuses on identity, access, and continuous monitoring, especially for our third-party AI dependencies.