Security News

Cybersecurity news aggregator

📰
INFO News

Security Morning Briefing - April 21, 2026

  • ## Útskýringarútgáfa Þjóðarhættleikastarfsemi á 21. apríl 2026 er stjórað af **breidduðu nýtingu á kritískum veikleikum** sem CISA hefur nýlega beðið um að bæta, og sérstaklega **aðfangakeðjuháttir** sem ákveðnar forritunarmenn og skygginguþjónustu. Þarf að bæta **Apache ActiveMQ**, **Microsoft Defender** og **Adobe Acrobat** á meðal annars, allar undir nýtingu. Þar á eftir er **npm aðfangakeðjuháttur** (Axios) og **þriðja hlutverk í Vercel** sýnileg á aukinni aðfangakeðjuhættleika. Þar að auki er **nýr ICS-áhrifandi gíslatökuhugbúnaður (ZionSiphon)** og nýr **gíslatökuhugbúnaður sem notar QEMU til að hægja sig** sýnilegur sem kritískar, breytilegar hættur. ## ⚠️ Þarf að gera á meðan
  • *Apache ActiveMQ RCE er í virkri nýtingu** Kritísk fjarkeyrsla kóða í Apache ActiveMQ Classic, sem er nýtt af auðkennistjóra, er í virkri nýtingu í heimilum.
  • *CVE:** CVE-2026-34197 (CVSS: 8.8)
  • *Staða:** Í virkri nýtingu
  • *Veikar útgáfur:** ActiveMQ Classic fyrir 5.19.4; útgáfur 6.0.0 til 6.2.2
  • *Lagfært í:** Útgáfur 5.19.4, 6.2.3 og síðar
  • *Tímabundin lausn:** Slökktu á Jolokia HTTP API ef ekki þörf; takmarka netvinnu að ActiveMQ útgáfum.
  • *Heimild:** [The Register Security](https://go.theregister.com/feed/www.theregister.com/2026/04/17/cisa_tells_feds_to_patch/)
  • *Microsoft Defender núll-daga veikleikar nýttir fyrir réttindaaukning** Þrjár núll-daga veikleikar í Microsoft Defender eru í virkri nýtingu, sem leyfir réttindaaukning og þjónustuneitun. Aðeins einn hefur verið bættur.
  • *CVE:** CVE-2026-33825 (BlueHammer, bættur), CVE-2026-34040 (RedSun, ekki bættur), CVE-2026-35616 (UnDefend, ekki bættur)
  • *Staða:** Í virkri nýtingu
  • *Veikar útgáfur:** Windows kerfi með Microsoft Defender
  • *Lagfært í:** CVE-2026-33825 bættur; önnur ekki tilgreind í heimildum — skoðið tilkynningu framleiðanda
  • *Tímabundin lausn:** Notaðu tilgengilegar uppfærslur fyrir CVE-2026-33825; skoðið uppfærslur um ekki bættar vandamál.
  • *Heimild:** [The Hacker News](https://thehackernews.com/2026/04/three-microsoft-defender-zero-days.html)
  • *Adobe Acrobat & Reader RCE með óþægilegum PDFs** Kritískar veikleikar í Adobe Acrobat og Reader, með Prototype Pollution, eru nýttir til að ná fjarkeyrslu kóða með óþægilegum PDFs.
  • *CVE:** CVE-2026-34621 (CVSS: Ekki tilgreint)
  • *Staða:** Í virkri nýtingu
  • *Veikar útgáfur:** Acrobat DC og Reader DC upp í 26.001.21431; Acrobat 2024 fyrir 24.001.30362
  • *Lagfært í:** Uppfærslur útgáfur útgefnar; ekki tilgreind í heimildum — skoðið tilkynningu framleiðanda
  • *Tímabundin lausn:** Notaðu nákvæm áætlunartíðni uppfærslur frá Adobe á meðan.
  • *Heimild:** [Help Net Security](https://www.helpnetsecurity.com/2026/04/13/adobe-acrobat-reader-cve-2026-34621-emergency-fix/)
  • *Langflow kritískar RCE veikleikar nýttir** Fjöldi kritískra veikleika í open-source Langflow LLM plattform, með CVSS 10.0 RCE veikleika, eru nýttir innan klukkustundar eftir útgefinni til að taka yfir AI vinnusvið.
  • *CVE:** CVE-2026-33017, CVE-2025-3248 (CVSS: Allt að 10.0)
  • *Staða:** Í virkri nýtingu
  • *Veikar útgáfur:** Útgáfur fyrir 1.9.0
  • *Lagfært í:** Útgáfur 1.9.0 og síðar
  • *Tímabundin lausn:** Uppfæra á meðan í nýjasta uppfærslu.
  • *Heimild:** [CSO Online](https://www.csoonline.com/article/4151203/attackers-exploit-critical-langflow-rce-within-hours-as-cisa-sounds-alarm.html) ## 🔍 Hættuleg aðgerð
  • *🏢 Axios npm pakki varð í aðfangakeðjuhátt:** Þýðandi Axios npm hóp varð í aðfangakeðjuhátt með hækkun á stjórnandi aðgangi. Óþægilegar útgáfur (1.14.1, 0.30.4) setja framhjáhlaup á öll plattform sem fjarlægja umhverfis breytur. Þessi hættla er tengd norðurkóreska grúpu UNC1069 og býr til alvarlega hættu fyrir forritunarmenn og forrit sem nota þessar útgáfur.
  • *Payouts King gíslatökuhugbúnað notar QEMU til að hægja sig:** Payouts King gíslatökuhugbúnaður notar skjáðar Alpine Linux virtuella kerfi með QEMU til að búa til öfugan SSH tilgangsþjón. Þetta leyfir að hægja sig úr endapunkta upplýsingar. Þessi kampanj notar CVE-2025-26399 (CVSS 9.8) í SolarWinds Web Help Desk fyrir fyrstu aðgang.
  • *ZionSiphon gíslatökuhugbúnað áhrifir vatnshandtektar ICS:** Nýr gíslatökuhugbúnaður, ZionSiphon, er designedur til að skemmta vatnshandtektar og sýrðarvinnslu með breyttum klórum og vökvaþrýstum. Það breytist með USB og notar vinnsluþjónustu (ICS) aðferðir, sem býr til alvarlega líkamsáhrif á aðgengilegar kerfi.
  • *PowMix botnet áhrifir íslenskar stofnanir:** Nýrðu botnet, PowMix, áhrifir íslenskar stofnanir með netveiðar með óþægilegum ZIP viðaukum. Það notar multi-stage PowerShell loader og notar tilfáðar stjórn- og boðmiðlun (C2) með dulsýndum vefslóðum til að hægja sig úr netvinnu upplýsingar. ## 📋 Uppfærslur og uppfærslur
  • *Google Chrome núll-daga uppfærð:** CVE-2026-2441, kritísk use-after-free veikleiki í Chrome, er uppfærður. Notendur verða að uppfæra í Chrome útgáfu 145 eða hærra á meðan. **Heimild:** [SecurityWeek](https://www.securityweek.com/exploited-zero-day-among-21-vulnerabilities-patched-in-chrome/)
  • *Fjöldi kritískra veikleika í SAP uppfærð:** SAP's apríl 2026 uppfærslur aðgreina fjölda kritískra vandamála, með fjarkeyrslu kóða og SQL injection veikleika í forritum eins og S/4HANA og NetWeaver, með CVSS stig allt að 9.9. **Heimild:** [The Hacker News](https://thehackernews.com/2026/04/april-patch-tuesday-fixes-critical.html)
  • *Microsoft Office veikleikar aðgreind:** Microsoft hefur útgefið uppfærslur fyrir fjölda hástig veikleika í Office forritum (Excel, Word, SharePoint) sem geta leitt til fjarkeyrslu kóða og réttindaaukning. **Heimild:** [NCSC Netherlands](https://advisories.ncsc.nl/advisory?id=NCSC-2026-0116) ## 📰 Þjónustu og reglur
  • *CISA breiddir KEV kataloginn:** CISA hefur bætt við fjölda veikleika sem eru í virkri nýtingu í sinni Þekktum Nýtingarveikleika (KEV) katalog, með bindandi uppfærslu tíma fyrir stjórnarskála. Þetta hefur verið í veikleikum í Zimbra (CVE-2025-66376, nýtt af APT28), TP-Link rúttar (CVE-2023-33538) og öðrum, sem sýnir breidduða nýtingu.
  • *Heimspeki á DDoS fyrir aðgerð:** Operation PowerOFF, með 21 landum, leiddi til að taka 53 booter tækifæri og fjóra átök, sem breytti plattform sem notuðu yfir 75.000 netþjónsmenn.
  • *Tycoon2FA netveiðarþjónusta er að halda:** Þó að nýlega hefur verið gerð heimspeki, er Tycoon2FA netveiðarþjónusta, sem sérhæfir sig í framhjáhlaup á multi-factor authentication (MFA), að halda, sem sýnir sterkni á kriminála náttúrunni. ## Þessar dagar árangur 1. **Bættu á meðan:** Fyrirsjá að bæta **Apache ActiveMQ** (CVE-2026-34197), **Microsoft Defender** (CVE-2026-33825) og **Adobe Acrobat/Reader** (CVE-2026-34621), þar sem þessar eru undir nýtingu. 2. **Athugaðu forritaflokkana:** Leitaðu og fjarlægðu öll tilfelli af óþægilegum **Axios npm útgáfum 1.14.1 og 0.30.4**. Skoðið byggingarferli og umhverfis breytur fyrir tekin. 3. **Athugaðu þriðja hlutverk:** Þjóða hvaða notkun er á óþægilegum **Context.ai** tæki og skoðið áhrif, með Vercel breiðslu sem dæmi um aðfangakeðju OAuth breytu. 4. **Uppfæra CISA KEV samkomulag:** Athugaðu að allar kerfi eru uppfærð með veikleikum sem nýlega bættar í CISA KEV katalog, sérstaklega þar sem það áhrifir **Zimbra** og enda-áætlaða **TP-Link rúttar** (sem geta þörf á netvinnu aðskilni). ## 🔗 Heimildir - [The Hacker News: Three Microsoft Defender Zero-Days Actively Exploited; Two Still Unpatched](https://thehackernews.com/2026/04/three-microsoft-defender-zero-days.html) - [The Register Security: CISA tells feds to patch 13-year-old Apache ActiveMQ bug under active attack](https://go.theregister.com/feed/www.theregister.com/2026/04/17/cisa_tells_feds_to_patch/) - [The Hacker News: UNC1069 Social Engineering of Axios Maintainer Led to npm Supply Chain Attack](https://thehackernews.com/2026/04/unc1069-social-engineering-of-axios.html) - [The Hacker News: Vercel Breach Tied to Context AI Hack Exposes Limited Customer Credentials](https://thehackernews.com/2026/04/vercel-breach-tied-to-context-ai-hack.html) - [The Hacker News: Researchers Detect ZionSiphon Malware Targeting Israeli Water, Desalination OT S](https://thehackernews.com/2026/04/researchers-detect-zionsiphon-malware.html)
Read Full Article →

## Executive Summary The threat landscape on April 21, 2026, is dominated by **widespread active exploitation of critical vulnerabilities** recently mandated for patching by CISA, and sophisticated **supply chain attacks** targeting developers and cloud infrastructure. Urgent patching is required for **Apache ActiveMQ**, **Microsoft Defender**, and **Adobe Acrobat**, all under active attack. A significant **npm supply chain compromise** (Axios) and a **third-party breach at Vercel** highlight escalating software supply chain risks. Additionally, a new **ICS-targeting malware (ZionSiphon)** and a novel **ransomware evasion technique using QEMU** represent critical, evolving threats.

## ⚠️ Immediate Action Required * **Apache ActiveMQ RCE Actively Exploited** A critical remote code execution vulnerability in Apache ActiveMQ Classic, exploitable via the Jolokia API by authenticated attackers, is being actively exploited in the wild. * **CVE:** CVE-2026-34197 (CVSS: 8.8) * **Status:** Active exploitation detected * **Vulnerable:** ActiveMQ Classic before 5.19.4; versions 6.0.0 through 6.2.2 * **Fixed:** Versions 5.19.4, 6.2.3, and later * **Workaround:** Disable the Jolokia HTTP API if not required; restrict network access to ActiveMQ instances. * **Reference:** [The Register Security](https://go.theregister.com/feed/www.theregister.com/2026/04/17/cisa_tells_feds_to_patch/)

* **Microsoft Defender Zero-Days Exploited for Privilege Escalation** Three zero-day vulnerabilities in Microsoft Defender are being actively exploited, enabling local privilege escalation and denial-of-service. Only one has been patched. * **CVE:** CVE-2026-33825 (BlueHammer, Patched), CVE-2026-34040 (RedSun, Unpatched), CVE-2026-35616 (UnDefend, Unpatched) * **Status:** Active exploitation detected * **Vulnerable:** Windows systems with Microsoft Defender * **Fixed:** CVE-2026-33825 patched; others not specified in source — check vendor advisory * **Workaround:** Apply available patches for CVE-2026-33825; monitor for updates on unpatched flaws. * **Reference:** [The Hacker News](https://thehackernews.com/2026/04/three-microsoft-defender-zero-days.html)

* **Adobe Acrobat & Reader RCE via Malicious PDFs** Critical vulnerabilities in Adobe Acrobat and Reader, including a Prototype Pollution flaw, are being exploited to achieve remote code execution via malicious PDF files. * **CVE:** CVE-2026-34621 (CVSS: Not specified) * **Status:** Active exploitation detected * **Vulnerable:** Acrobat DC and Reader DC up to 26.001.21431; Acrobat 2024 prior to 24.001.30362 * **Fixed:** Patched versions released; not specified in source — check vendor advisory * **Workaround:** Apply emergency patches from Adobe immediately. * **Reference:** [Help Net Security](https://www.helpnetsecurity.com/2026/04/13/adobe-acrobat-reader-cve-2026-34621-emergency-fix/)

* **Langflow Critical RCE Flaws Exploited** Multiple critical vulnerabilities in the open-source Langflow LLM platform, including a CVSS 10.0 RCE flaw, are being exploited within hours of disclosure to hijack AI workflows. * **CVE:** CVE-2026-33017, CVE-2025-3248 (CVSS: Up to 10.0) * **Status:** Active exploitation detected * **Vulnerable:** Versions prior to 1.9.0 * **Fixed:** Version 1.9.0 and later * **Workaround:** Update to the latest patched version immediately. * **Reference:** [CSO Online](https://www.csoonline.com/article/4151203/attackers-exploit-critical-langflow-rce-within-hours-as-cisa-sounds-alarm.html)

## 🔍 Threat Activity * **🏢 Axios npm Package Compromised in Supply Chain Attack:** The widely used Axios npm library was compromised via a hijacked maintainer account. Malicious versions (1.14.1, 0.30.4) deploy a cross-platform Remote Access Trojan (RAT) that exfiltrates environment variables. This attack, attributed to North Korean group UNC1069, poses a severe risk to development environments and applications using these versions. * **Payouts King Ransomware Abuses QEMU for Evasion:** The Payouts King ransomware group is deploying hidden Alpine Linux virtual machines via QEMU to establish reverse SSH backdoors, effectively bypassing endpoint detection. This campaign exploits CVE-2025-26399 (CVSS 9.8) in SolarWinds Web Help Desk for initial access. * **ZionSiphon Malware Targets Water Treatment ICS:** A new malware family, ZionSiphon, is designed to sabotage water treatment and desalination plants by altering chlorine levels and hydraulic pressures. It spreads via USB and exploits industrial control system (ICS) protocols, posing a direct physical risk to critical infrastructure. * **PowMix Botnet Targets Czech Organizations:** A newly identified botnet, PowMix, is targeting Czech entities via phishing emails with malicious ZIP attachments. It uses a multi-stage PowerShell loader and employs randomized command-and-control (C2) beaconing with encrypted URLs to evade network detection.

## 📋 Patches & Updates * **Google Chrome Zero-Day Patched:** CVE-2026-2441, a critical use-after-free vulnerability in Chrome exploited in the wild, has been patched. Users must update to Chrome version 145 or later immediately. **Reference:** [SecurityWeek](https://www.securityweek.com/exploited-zero-day-among-21-vulnerabilities-patched-in-chrome/) * **Multiple SAP Critical Vulnerabilities Patched:** SAP's April 2026 patches address multiple critical flaws, including remote code execution and SQL injection vulnerabilities in products like S/4HANA and NetWeaver, with CVSS scores up to 9.9. **Reference:** [The Hacker News](https://thehackernews.com/2026/04/april-patch-tuesday-fixes-critical.html) * **Microsoft Office Vulnerabilities Addressed:** Microsoft has released patches for multiple high-severity vulnerabilities in Office products (Excel, Word, SharePoint) that could lead to remote code execution and privilege escalation. **Reference:** [NCSC Netherlands](https://advisories.ncsc.nl/advisory?id=NCSC-2026-0116)

## 📰 Industry & Policy * **CISA Aggressively Expands KEV Catalog:** CISA has added multiple batches of actively exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog over the past week, setting binding patching deadlines for federal agencies. This includes flaws in Zimbra (CVE-2025-66376, exploited by APT28), TP-Link routers (CVE-2023-33538), and others, signaling widespread ongoing exploitation. * **Global Takedown of DDoS-for-Hire Services:** Operation PowerOFF, involving 21 countries, resulted in the seizure of 53 booter service domains and four arrests, disrupting a platform used by over 75,000 cybercriminals. * **Tycoon2FA Phishing Service Persists:** Despite a recent global law enforcement takedown, the Tycoon2FA phishing-as-a-service platform, which specializes in bypassing multi-factor authentication (MFA), has quickly resumed operations, highlighting the resilience of criminal infrastructure.

## Today's Priorities 1. **Patch Immediately:** Prioritize deploying patches for **Apache ActiveMQ** (CVE-2026-34197), **Microsoft Defender** (CVE-2026-33825), and **Adobe Acrobat/Reader** (CVE-2026-34621), as these are under active exploitation. 2. **Audit Development Dependencies:** Scan for and remove any instances of the compromised **Axios npm package versions 1.14.1 and 0.30.4**. Review build pipelines and environment variables for signs of compromise. 3. **Review Third-Party Integrations:** Investigate any use of the compromised **Context.ai** tool and assess potential impact, following Vercel's breach as a case study in third-party OAuth token risk. 4. **Update CISA KEV Compliance Status:** Verify that all systems are patched against the vulnerabilities newly added to the CISA KEV catalog, especially those affecting **Zimbra** and end-of-life **TP-Link routers** (which may require network isolation).

## 🔗 References

  • [The Hacker News: Three Microsoft Defender Zero-Days Actively Exploited; Two Still Unpatched](https://thehackernews.com/2026/04/three-microsoft-defender-zero-days.html)
  • [The Register Security: CISA tells feds to patch 13-year-old Apache ActiveMQ bug under active attack](https://go.theregister.com/feed/www.theregister.com/2026/04/17/cisa_tells_feds_to_patch/)
  • [The Hacker News: UNC1069 Social Engineering of Axios Maintainer Led to npm Supply Chain Attack](https://thehackernews.com/2026/04/unc1069-social-engineering-of-axios.html)
  • [The Hacker News: Vercel Breach Tied to Context AI Hack Exposes Limited Customer Credentials](https://thehackernews.com/2026/04/vercel-breach-tied-to-context-ai-hack.html)
  • [The Hacker News: Researchers Detect ZionSiphon Malware Targeting Israeli Water, Desalination OT S](https://thehackernews.com/2026/04/researchers-detect-zionsiphon-malware.html)

Share this article