🛡️ CISO Intel — Thursday, 07-05-2026
Due to API rate limiting, here is today’s briefing:
🔴 Critical Threats & Active Exploitation
Instructure (Canvas LMS) — ShinyHunters ransomware group claims a massive data breach affecting 275 million records of students, teachers, and staff. They’ve shared a list of 8,809 institutions. This is a supply chain ripple effect, hitting education hard. Assume data is compromised.
Vimeo, Udemy, Medtronic — The ShinyHunters ransomware campaign is expanding. Vimeo confirmed user/customer data access, Udemy claims 1.4 million records stolen, and Medtronic confirmed IT system compromise. This group is moving fast.
cPanel & WHM — CVE-2026-41940 (CVSS 8.8) — Authentication bypass vulnerability being actively exploited in the wild. Attackers are targeting government and military entities in Southeast Asia, MSPs, and hosting providers. PoC is public. Patch immediately, or attackers get full control of your hosting.
Microsoft Windows Shell — CVE-2026-32202 (Medium Severity) — CISA added this to the KEV catalog. It’s a protection mechanism failure, allowing attackers to impersonate legitimate users. This is an incomplete patch for a previous flaw, CVE-2026-21510, which APT28 used. Typical.
🛡️ CVEs Worth Your Attention
CVE-2026-31431 | Linux Kernel | CVSS 9.8 (High) | “Copy Fail” vulnerability enables root privilege escalation across cloud environments and Kubernetes workloads. Microsoft Defender Research discovered this. Expect weaponization soon. PoC: No (but exploitability is high)
CVE-2026-23918 | Apache HTTP Server (http2 module) | CVSS 8.8 | Double-free vulnerability leading to RCE or DoS via crafted HTTP/2 requests. This is a big one given Apache’s widespread use. Patch. PoC: No (but detailed description available, increasing likelihood)
CVE-2026-24072 | Apache HTTP Server (mod_rewrite) | CVSS 8.8 | Local privilege escalation for local attackers or compromised users via .htaccess files, allowing sensitive file reads. PoC: No
CVE-2026-0073 | Android System | CVSS 9.8 | Remote Code Execution without user interaction, affecting the adbd daemon. Patch available. No evidence of in-the-wild exploitation yet, but critical. PoC: No
CVE-2026-4670 | Progress MOVEit Automation | CVSS 9.8 | Critical authentication bypass. Attackers could gain unauthorized administrative control and data exposure. Patch immediately. PoC: No (but exploitation is trivial for this type of bug)
CVE-2026-5174 | Progress MOVEit Automation | CVSS 8.8 | Privilege escalation vulnerability. Complements CVE-2026-4670. Patch immediately. PoC: No
⚡ New TTPs & Attack Research
Kerberoasting Persistence — New research highlights Kerberoasting (T1558.003) remains a primary path to Domain Admin in Active Directory. Modern OPSEC-aware techniques are evading EDR by carefully requesting TGS tickets to avoid event log spikes. Defenders need behavioral monitoring for anomalous TGS requests, not just volume.
AI-Assisted Web Honeypot Analysis — SANS ISC published a guest diary on using LLMs to create bespoke UIs for web honeypot log analysis. It simplifies recognizing web attacks, lowering the bar for less experienced analysts. Good for defenders, but expect attackers to weaponize similar AI for faster recon.
🏗️ DevSecOps & Cloud Security
DAEMON Tools Supply Chain Attack — Kaspersky reports official DAEMON Tools installers were compromised since April 8, 2026, serving malicious payloads. These are signed with legitimate certs. If you use DAEMON Tools, verify your versions immediately. This is a classic supply chain hit. npm/PyPI Supply Chain Threats — Reminder that malicious packages continue to plague public registries. Recent incidents include backdoored PyTorch Lightning and compromised official SAP npm packages to steal credentials. Keep your build environments locked down and use package integrity checks. Microsoft Defender for Cloud enhancements — New capabilities in preview for detecting, blocking, and investigating threats to AI agents within Microsoft 365 environments. Leveraging webhooks for near real-time protection. Good to see the cloud providers stepping up on AI agent security.
🔧 Patches & Vendor Releases
Apache HTTP Server — Emergency patches released for multiple high-severity vulnerabilities, including CVE-2026-23918 (RCE) and CVE-2026-24072 (EoP). Upgrade immediately. 🟢 solid fix
Progress MOVEit Automation — Urgent patches released for CVE-2026-4670 (Auth Bypass) and CVE-2026-5174 (PrivEsc). Full installer upgrade required, meaning downtime. 🟢 solid fix
Android — Google released an update patching CVE-2026-0073, a critical RCE. Deploy this. 🟢 solid fix
SSL.com Root Certificate Rotation — SSL.com is rotating its root certificate. If you have pinned trust anchors or custom trust stores, audit your configurations. This is standard but can cause outages if ignored. 🟢 business as usual, but check your systems
Microsoft Secure Boot Certificates — Microsoft is terminating critical Secure Boot certificates for over a billion Windows PCs. April’s updates included new status checks and refreshed certificates. Check your devices; a “red (critical)” warning will appear in 10 days if action is needed. 🟢 critical update, act now
🧪 Threat Intel & Malware
Manufacturing Sector Targeted by Ransomware — Ransomware attacks in 2026 are heavily targeting industrial manufacturing, ranking second only to technology in reported victims. Groups like SafePay, RansomHub, Akira, Qilin, and Cl0p are highly active. They’re going for operational disruption and strategic impact. PEAR Ransomware hits Monmouth University — PEAR ransomware group claims to have exfiltrated 16 TB of data from Monmouth University, posting samples as proof. Education is a soft target, and they know it. China-linked APT targeting governments — A sophisticated China-linked APT group has been observed targeting government entities in South America since late 2024 and in Southeastern Europe since 2025. Expect continued geopolitical cyber activity. Multi-stage ‘code of conduct’ phishing — Microsoft Defender Research observed a large-scale credential theft campaign using code-of-conduct themed lures, multi-step chains, and legitimate email services to bypass defenses. AiTM token compromise is the goal.
🌐 Industry, Brand & Internet Security
Education Sector Data Breaches — Instructure (Canvas LMS) breach, potentially affecting 275 million users, highlights the massive blast radius in the education sector. Expect downstream phishing from this data. US Army Contractor Data Leak — A US government contractor leaked military base photos and personnel information for over a year. The usual suspects, poor configuration, massive impact. Germany’s .de domains outage — Millions of German websites and apps went dark due to a DNS outage affecting the .de TLD. This is a critical infrastructure failure, not just a minor hiccup. CISA considering 3-day patch deadline — US cyber officials are reportedly considering shortening the deadline for federal agencies to fix critical vulnerabilities from 14 days to three days, spurred by concerns over AI-accelerated attacks (e.g., Claude Mythos, GPT-5.4-Cyber). This will set a new benchmark for private sector expectations.
🤖 AI & LLM Security
OpenAI Advanced Account Security — OpenAI introduces Advanced Account Security for ChatGPT, adding stronger phishing-resistant sign-in (passkeys/security keys), tighter recovery controls, shorter sessions, and login alerts. Good move for reducing ATO risk. OpenAI expands AI-powered cyber defense for governments — OpenAI is expanding its Trusted Access for Cyber (TAC) program to federal, state, and local governments, offering more capable models like GPT-5.4-Cyber for defensive work. This is a direct response to the accelerating pace of AI-driven attacks. AI-driven attack speed — Experts are warning that AI models like Anthropic’s Claude Mythos and OpenAI’s GPT-5.4-Cyber will accelerate attackers’ ability to find and exploit vulnerabilities. The time to exploit is shrinking, demanding faster defense.
📋 Compliance & Regulatory
[Clear — enjoy it]
💡 Marcus’s Take
Another Thursday, another flood of critical vulnerabilities and massive breaches. The ShinyHunters campaign hitting education and major platforms is a stark reminder: third-party risk is your risk. We’re seeing AI-driven attack speeds pushing CISA to consider a 72-hour patch window for critical flaws. This isn’t just government policy; it’s a preview of private sector expectations. Your patching cadence needs to accelerate, and your third-party risk management needs to be more than just a checkbox. Focus on those Apache and MOVEit patches. Assume your service accounts are already compromised, and hunt for Kerberoasting activity. The AI race is on, and it’s not just about offense anymore; it’s about AI-powered defense keeping pace.