FIRESTARTER: Cisco ASA Backdoor

On April 23, 2026, CISA and the UK National Cyber Security Centre revealed FIRESTARTER, a persistent backdoor implant targeting Cisco Adaptive Security Appliance firmware via CVE-2025-20333 and CVE-2025-20362, enabling advanced persistent threat actor UAT-4356 (linked to the earlier ArcaneDoor campaign) to maintain long-term access even after patching and rebooting. The malware hooks into Cisco’s core LINA process to execute attacker shellcode triggered by specially crafted WebVPN requests, requiring a hard power cycle or full device reimaging to fully remove, highlighting a serious evolution in firmware-level threats that challenge conventional patch-and-monitor security models.

https://thecyberthrone.in/2026/04/28/firestarter-cisco-asa-backdoor/

Exploits Turn Windows Defender Into Attacker Tool

Threat actors are exploiting three publicly available proof-of-concept vulnerabilities—BlueHammer, RedSun, and UnDefend—to turn Microsoft Defender's built-in security functions against the systems it is meant to protect, enabling SYSTEM-level access and disrupting update mechanisms. While Microsoft has patched BlueHammer, the other two remain unpatched, and these exploits are actively used in targeted attacks that highlight systemic validation weaknesses in Defender’s privileged workflows, underscoring the need for updated defenses and multi-factor authentication for remote access.

https://www.darkreading.com/cyberattacks-data-breaches/exploits-turn-windows-defender-attacker-tool

Self-Propagating Supply Chain Worm Hijacks Npm Packages to Steal Developer Tokens

Cybersecurity researchers have identified a self-propagating supply chain worm named CanisterSprawl that compromises npm packages to steal developer tokens and credentials, spreading by injecting malicious postinstall hooks into affected packages. The worm exfiltrates sensitive data from developer environments, including npm configuration files, cloud credentials, SSH keys, and browser data, to push poisoned package versions and expand its reach, posing significant risks to open-source supply chains.

https://thehackernews.com/2026/04/self-propagating-supply-chain-worm.html

A Dozen Allied Agencies Say China Is Building Covert Hacker Networks Out of Everyday Routers

A coalition of U.S. and international government agencies has issued a warning about a significant shift in Chinese hacker tactics, highlighting the use of large-scale covert networks composed of compromised everyday routers and Internet of Things devices to conduct cyberattacks. These networks enable malicious activities such as reconnaissance, malware delivery, and espionage while disguising attackers' origins, prompting recommendations for organizations, especially large and critical infrastructure entities, to adopt enhanced cybersecurity measures and active threat hunting.

https://cyberscoop.com/china-nexus-covert-networks-advisory/

Phishing — Sometimes with AI’s Help — Topped Initial-Access Methods in Q1, Cisco Says

In the first quarter of 2026, phishing—sometimes aided by AI tools like the Softr platform—was the most common method hackers used to gain initial access, according to Cisco’s Talos threat intelligence report. Attackers leveraged AI to quickly create fake login pages for credential harvesting without coding, targeting mainly government and health-care sectors, with deficient multifactor authentication being the leading security weakness exploited.

https://www.cybersecuritydive.com/news/phishing-initial-access-ai-cisco/818185/

We Found a Stable Firefox Identifier Linking All Your Private Tor Identities

Researchers discovered a privacy vulnerability in Firefox-based browsers whereby the order of IndexedDB databases returned by the indexedDB.databases() API serves as a stable, process-scoped identifier. This allows unrelated websites to link user activity across origins and defeats privacy features in Firefox Private Browsing and Tor Browser, including Tor's “New Identity” function, by exposing a deterministic fingerprint until the browser process restarts. Mozilla has released a fix that canonicalizes the database order to eliminate this leakage and restore expected privacy guarantees.

https://fingerprint.com/blog/firefox-tor-indexeddb-privacy-vulnerability/

“Hackers Can Now Launch Massive 2Tbps Attacks”: Report Reveals Staggering 10x Growth in Botnet Size with Record-Breaking DDoS Incidents Peaking for 40 Minutes as Multi-Vector Attacks Grow in Complexity and Become Harder to Dismantle

Security researchers report a massive 10-fold growth in the size of the largest botnet, which expanded from 1.33 million to 13.5 million infected devices within a year, enabling hackers to launch unprecedented sustained DDoS attacks exceeding 2 Tbps and lasting over 40 minutes. These increasingly complex multi-vector attacks, often commanded via blockchain-based systems, pose greater challenges for mitigation as traffic now originates worldwide, rendering traditional defenses less effective.

https://www.techradar.com/pro/hackers-can-now-launch-massive-2tbps-attacks-report-reveals-staggering-10x-growth-in-botnet-size-with-record-breaking-ddos-incidents-peaking-for-40-minutes-as-multi-vector-attacks-grow-in-complexity-and-become-harder-to-dismantle

Bissa Scanner, An AI-Assisted Credential Harvesting Factory

An exposed server revealed a criminal operation exploiting the React2Shell vulnerability (CVE-2025-55182) to harvest credentials. The “Bissa scanner” operation used AI tools like Claude Code and OpenClaw to automate target scanning, credential extraction, and victim triage. The operation targeted credentials from various cloud providers, payment platforms, and databases, highlighting the risks of storing secrets in .env files.

https://thecyberexpress.com/bissa-scanner-ai-assisted-credential-factory/

UK Government Says 100 Countries Have Spyware That Can Hack People’s Phones

According to U.K. intelligence, over 100 countries now have access to commercial spyware capable of hacking phones and computers to steal sensitive data, increasing from 80 countries in 2023. The U.K. National Cyber Security Centre warns this expanded access lowers barriers for foreign governments and hackers to target U.K. citizens, companies, and critical infrastructure, with victims now including bankers and wealthy businesspeople, and highlights ongoing threats from state-backed intrusions and leaked hacking tools.

https://techcrunch.com/2026/04/22/uk-government-says-100-countries-have-spyware-that-can-hack-peoples-phones/

How a Roblox Cheat and One AI Tool Brought Down Vercel’s Entire Platform

In early 2026, a security breach at Vercel was triggered by an employee at Context.ai downloading a Roblox cheat bundled with Lumma Stealer malware, which compromised internal systems and enabled attackers to access non-sensitive environment variables stored by Vercel. This incident exposed the risks posed by broad OAuth permissions granted to third-party AI tools and highlighted how non-sensitive environment variables were less protected, prompting Vercel to change its default encryption settings; the breach has led to widespread credential rotations and raised concerns over the security trade-offs in AI tooling and developer convenience.

https://webmatrices.com/post/how-a-roblox-cheat-and-one-ai-tool-brought-down-vercel-s-entire-platform

Mozilla: Anthropic’s Mythos Found 271 Zero-Day Vulnerabilities in Firefox 150

Mozilla reported that Anthropic’s AI model Mythos Preview identified 271 security vulnerabilities in the unreleased Firefox 150 source code, significantly more than previous AI models. Mozilla’s CTO stated that AI tools like Mythos could decisively shift cybersecurity defenses by making vulnerability detection faster and more efficient, potentially transforming how software security is maintained.

https://arstechnica.com/ai/2026/04/mozilla-anthropics-mythos-found-271-zero-day-vulnerabilities-in-firefox-150/

No Exploit Needed: How Attackers Walk Through the Front Door Via Identity-Based Attacks

The article highlights that despite advances in cybersecurity threats, stolen credentials remain the most common and effective method attackers use to gain unauthorized access. It emphasizes the growing role of AI in accelerating these identity-based attacks and advocates for a dynamic, iterative incident response approach—DAIR—to effectively detect, contain, and eradicate threats.

https://thehackernews.com/2026/04/no-exploit-needed-how-attackers-walk.html

All Vulnerabilities Are Exploitable: The New Reality of Software Risk

Javed Hasan, CEO and Cofounder of Lineaje, explains that rapid software evolution and AI-generated code have made all software vulnerabilities potentially exploitable, as automated tools can quickly create working exploits. He argues that traditional vulnerability management is outdated, urging organizations to adopt continuous security practices that assume every vulnerability can be weaponized, embedding security directly into development with automated governance to reduce risk in dynamic software environments.

https://www.cybersecurity-insiders.com/all-vulnerabilities-are-exploitable-the-new-reality-of-software-risk/

The Volunteer DDoS: Why AI Security Tools Are Breaking the Infrastructure They’re Meant to Protect

The article discusses how AI security tools, designed to identify vulnerabilities rapidly, are overwhelming open source software maintainers with excessive, low-quality reports, creating a “volunteer DDoS” effect that hinders real security work. It highlights the need for improved governance and trust frameworks—like those developed by the OpenSSF, including SAFE-MCP, OSS-CRS, and OMS—to filter AI findings, verify model provenance, enforce scoped permissions, and maintain human review, emphasizing that existing community-driven governance structures are crucial to managing AI-driven security challenges effectively.

https://hackernoon.com/the-volunteer-ddos-why-ai-security-tools-are-breaking-the-infrastructure-theyre-meant-to-protect

Fracturing Software Security With Frontier AI Models

Unit 42's research reveals that frontier AI models significantly enhance the ability to autonomously discover software vulnerabilities, accelerating the exploitation of zero-day and N-day flaws and enabling complex attack chains at unprecedented speed and scale. These advancements pose heightened risks to open-source software and software supply chains, as AI-driven attacks can rapidly identify and exploit vulnerabilities, necessitating stronger prevention, rapid patching, and automated incident response strategies for security teams.

https://unit42.paloaltonetworks.com/ai-software-security-risks/

Scroll to Top