TechLogHub Blog — Page 14 of 22
Insights, guides, and product strategy for builders and product teams.

Over 1,300 Microsoft SharePoint servers vulnerable to spoofing attacks
More than 1,300 Microsoft SharePoint servers remain online and unpatched against CVE-2026-32201, a spoofing vulnerability affecting SharePoint Server 2016, 2019, and Subscription Edition. Exploitation could allow attackers to view or modify sensitive data with a low-complexity, no-interaction attack, though it cannot disable access to the resource. Microsoft released patches in April 2026, but Shadowserver reports only a small number of systems have been updated. CISA added CVE-2026-32201 to its Known Exploited Vulnerabilities catalog and ordered Federal Civilian Executive Branch agencies to patch by April 28 under BOD 22-01. The April Patch Tuesday also fixed 167 vulnerabilities, including two zero-days.

French govt agency confirms breach as hacker offers to sell data
France’s ANTS agency confirms a data breach after a threat actor claimed access to the ants.gouv.fr portal, potentially exposing up to 19 million records. Exposed data include login IDs, full names, emails, dates of birth, unique account IDs, and some postal addresses, places of birth, and phone numbers, with the breach not granting portal access but enabling phishing risks. Authorities CNIL, the Paris Public Prosecutor, and ANSSI are involved, and the attacker has offered the data for sale; users are advised to stay vigilant for suspicious messages, with no action required at this time.

KelpDAO Hit by $290 Million Heist Linked to Lazarus Hackers
North Korea’s Lazarus Group is suspected to have stolen about $290 million from KelpDAO by exploiting a compromised cross-chain verification layer to drain roughly 116,500 rsETH (around $293 million) and move funds through Tornado Cash. The attack also affected Compound and Euler, with Aave freezing rsETH deposits/borrowing. LayerZero and partners are investigating, with attribution pointing to Lazarus TraderTraitor. The breach appears isolated to rsETH with no broader contagion.

China's Apple App Store infiltrated by crypto-stealing wallet apps
Security researchers have uncovered 26 fake crypto-wallet apps on Apple's App Store in China that impersonate wallets like MetaMask, Coinbase, Trust Wallet, and OneKey to steal seed phrases. The FakeWallet campaign, linked to SparkKitty, used typosquatting and spoofed branding and was disguised as games or calculator apps to evade bans. These trojanized apps harvest mnemonic phrases during setup, encrypt them, and transmit them to attackers, enabling funds to be drained from wallets—even via phishing prompts on cold-storage devices. Although China-focused, the malware has no geographic limit. Apple removed all 26 apps after the disclosure; users should verify publishers and use official sources only.

The Gentlemen ransomware now uses SystemBC for bot-powered attacks
Check Point reveals that The Gentlemen ransomware affiliate network has begun using SystemBC proxy malware, forming a botnet of over 1,570 hosts to covertly deliver payloads and support post‑exploitation operations, signaling a shift toward a broader, more mature toolchain targeting corporate environments across the US, UK, Germany, Australia, and Romania.

NIST to stop rating non-priority flaws due to volume increase
NIST’s National Vulnerability Database will stop assigning severity scores to lower-priority vulnerabilities due to a surge in submissions. Beginning April 15, 2026, CVEs will be enriched only if they meet risk-based criteria: they appear in CISA’s Known Exploited Vulnerabilities catalog, affect U.S. federal software, or involve software deemed critical under Executive Order 14028. All submitted CVEs will still appear in the NVD, but those not meeting the criteria will be labeled Not Scheduled; enrichment requests for the lowest-priority CVEs can still be sent to [email protected]. The change aims to focus on vulnerabilities with the greatest potential for widespread impact amid a 263% rise in submissions and 42,000 CVEs enriched in 2025.

Vercel confirms breach as hackers claim to be selling stolen data
Vercel confirms a security incident after a third-party AI tool’s Google Workspace OAuth app was compromised, with attackers claiming to sell stolen data. The breach allegedly allowed access to non‑sensitive environment variables and, later, broader access; Vercel says core services remain unaffected and is working with investigators and law enforcement. Customers are advised to review environment variables, rotate secrets, and enable the sensitive-variable encryption feature; attribution to ShinyHunters remains unverified.

Microsoft releases emergency updates to fix Windows Server issues
Microsoft issued emergency out-of-band updates to fix issues caused by April 2026 security updates for Windows Server, including installation failures on Windows Server 2025, LSASS-related domain controller restart loops, and BitLocker recovery prompts after KB5082063, with fixes covering Windows Server 2025, 23H2, 2022, 2019, 2016, and Azure Datacenter editions.

Microsoft tests Windows Explorer speed, performance improvements
Microsoft is testing Windows 11 File Explorer speed and performance improvements for Insider users, including an optional background preloading feature to speed launches. The rollout also includes reliability fixes (stopping explorer.exe) and dark-mode white-flash fixes, building on the May 2025 Startup Boost for Office apps, plus a new Xbox mode for a full-screen gaming interface. The changes are rolling out to Release Preview Insiders on Windows 11 24H2/25H2 with builds 26100.8313 and 26200.8313 (KB5083631).

Microsoft Pulls Service Update Causing Teams Launch Failures
Microsoft has reverted a service update that caused Teams desktop launch failures due to a regression in the client build caching system; users experiencing the issue should fully quit and restart Teams for the fix to propagate, while Microsoft continues to monitor telemetry and seek confirmation that the incident is resolved.

Seiko USA website defaced as hacker claims customer data theft
Seiko USA’s website was defaced with a ransom note claiming the Shopify-backed customer database was breached and exfiltrated, threatening to publish sensitive data unless a 72-hour negotiation window is met. The attackers allege they obtained names, emails, phone numbers, order histories, shipping details, and account notes, and point to a specific Shopify account ID (8069776801871) for negotiations. The claim’s legitimacy is unconfirmed, Seiko has not publicly commented, and the defacement has since been removed.

Recently leaked Windows zero-days now exploited in attacks
Threat actors are actively exploiting three newly disclosed Windows zero-days—BlueHammer, RedSun, and UnDefend—to gain SYSTEM or elevated privileges and to block Defender updates. BlueHammer has been patched in the April 2026 updates (CVE-2026-33825), but RedSun and UnDefend remain unpatched, enabling attacks on Windows 10/11 and Windows Server 2019+ even with Defender enabled. Security researchers have observed all three exploits in the wild since early April, including an instance via a compromised SSLVPN session, indicating hands-on-keyboard activity and foreshadowing a wave of further exploits.

CISA flags Apache ActiveMQ flaw as actively exploited in attacks
CISA warns that the high-severity CVE-2026-34197 flaw in Apache ActiveMQ is now actively exploited in attacks. The vulnerability enables remote code execution through improper input validation and was patched on March 30 for ActiveMQ Classic 6.2.3 and 5.19.4; ShadowServer reports over 7,500 exposed servers. CISA added CVE-2026-34197 to the Known Exploited Vulnerabilities catalog and ordered federal agencies to patch by April 30 under BOD 22-01, while PRIVATE sector defenders are urged to apply mitigations for CVE-2026-35616 and monitor logs for suspicious broker activity; this follows prior ActiveMQ exploits CVE-2023-46604 and CVE-2016-3088.

Webinar: From phishing to fallout — Why MSPs must rethink both security and recovery
BleepingComputer is hosting a live webinar on May 14, 2026 at 2:00 PM ET with Kaseya to explain why MSPs must rethink both security and recovery, highlighting how AI-powered phishing, BEC, and ransomware challenge traditional defenses and how integrating SaaS backups and disaster recovery with prevention and detection can minimize downtime and strengthen cyber resilience.

Inside an Underground Guide: How Threat Actors Vet Stolen Credit Card Shops
Flare’s analysis reveals an underground guide that treats vetting stolen credit card shops as the core skill, showing threat actors moving from opportunistic fraud to structured supplier verification. Survival and data freshness define legitimacy, with emphasis on fresh BIN data and low decline rates, multiple data sources, and controlled forums for validation. The guide covers technical checks (domain age, SSL, mirror domains) and operational security (proxying, crypto choices, multi-point access). It also notes potential bias and highlights defensive value by monitoring these markets for early fraud indicators.

Grinex Exchange Blames Western Intelligence for $13.7M Crypto Hack
Grinex, a Kyrgyzstan-based exchange with Russian ties, suspended operations after a $13.7 million hack targeting Russian user wallets. The exchange claims Western intelligence orchestrated the attack to undermine Russia’s financial sovereignty, but no public evidence supports this attribution. Security researchers traced the theft to transfers through TRON and Ethereum addresses and noted a second hack at TokenSpot; US authorities have linked Grinex to the sanctioned Garantex network in 2025. The incident underscores ongoing risks around sanctioned, Russia-linked crypto activity.

NAKIVO v11.2: Ransomware Defense, Faster Replication, vSphere 9, and Proxmox VE 9.0 Support
NAKIVO announces the general availability of Backup & Replication v11.2, featuring automated real-time replication, full VMware vSphere 9 support, Proxmox VE 9.0/9.1 compatibility, OAuth 2.0 for secure notifications, and expanded ransomware defenses with immutable backups and air-gapped options, plus an enhanced MSP Direct Connect for multi-tenant management. Available now with a 15-day free trial.

Microsoft Teams right-click paste broken by Edge update bug
Microsoft warns that a recent Edge browser update breaks the right-click paste function in Microsoft Teams desktop chats; users should use keyboard shortcuts (Ctrl/C/V on Windows, Cmd/C/V on macOS) while Microsoft rolls out a staged fix with no exact ETA as of April 16, 2026.

AgingFly Malware Used in Attacks on Ukraine's Government and Hospitals
Ukraine’s CERT-UA has identified a new malware family, AgingFly, used in attacks against local governments and hospitals to steal Chromium-based browser data and WhatsApp messages, with potential targeting of Defense Forces. The campaign, attributed to cluster UAC-0247, begins with a phishing email offering humanitarian aid, leading to a LNK that launches an HTA to fetch and execute a staged payload and establish a C2-enabled TCP reverse shell. AgingFly is notable for compiling command handlers on the host from code received from the C2 at runtime, enabling on‑demand capabilities but increasing complexity and detection risk. It exfiltrates browser data via ChromElevator and WhatsApp data via ZAPiDESK, conducts reconnaissance and lateral movement, and communicates with its C2 over WebSockets with AES-CBC encryption; CERT-UA recommends blocking LNK, HTA, and JS files to disrupt the attack chain.

Critical Nginx UI Authentication Bypass Flaw Now Actively Exploited in the Wild
Researchers warn of a critical Nginx UI vulnerability (CVE-2026-33032) in MCP mode that leaves the /mcp_message endpoint unprotected, allowing unauthenticated attackers to perform privileged MCP actions—including writing and reloading nginx configuration and taking over the server. The flaw is under active exploitation, with roughly 2,600 publicly exposed instances identified (US, China, Indonesia, Germany, Hong Kong). Exploitation uses an SSE connection to establish an MCP session, then uses the returned sessionID to call /mcp_message to access 12 MCP tools (7 destructive), enabling config exfiltration, injection of malicious blocks, and forced reloads. Nginx released a fix in version 2.3.4 on March 15; the recommended safe version is 2.3.6—patch immediately.
Showing 20 of 423 articles


