Cybersecurity News | Daily Recap [22 Apr 2026]

Cybersecurity News | Daily Recap [22 Apr 2026]

Daily Recap, UK cyber officials report they are handling four major incidents per week amid rising nation-state activity from Russia, Iran and China, while the EU imposes sanctions on Russian propaganda networks and Ukraine exposes a bot farm supplying thousands of fake Telegram accounts to Russian spies. Ransomware cases surface in legal actions around BlackCat/ALPHV and insider-leakage details, while GoGra Linux backdoor abusing Microsoft Graph API and an npm supply-chain attack on Namastex Labs highlight evolving threats, alongside the Vercel breach via Context.ai.
#BlackCat #GoGra

State & Geopolitics

  • UK cyber officials say they are handling four major incidents a week amid a surge in nation-state activity from Russia, Iran and ChinaUK Incidents, UK Threats
  • The EU imposed new sanctions on two Russian propaganda networks, while Ukraine said it busted a bot farm supplying thousands of fake Telegram accounts to Russian spies – EU Sanctions, Ukraine Bot Farm
  • China-linked Mustang Panda shifted to targeting Indian banks with spear-phishing and LotusLite, showing espionage groups are broadening into financial-sector collection – Mustang Panda
  • French government agencies confirmed a breach as data was offered for sale online, adding to a week of public-sector incident disclosures – French Breach

Ransomware & Crime

  • Former ransomware negotiators including Angelo Martino pleaded guilty to helping BlackCat/ALPHV extort victims, exposing how insiders leaked negotiation details and contributed to roughly $75.3 million in extorted payments – Martino Guilty, BlackCat Scheme, Scattered Spider, Ransomware Insider, BlackCat Plea
  • Scattered Spider figure Tyler Robert Buchanan admitted to phishing and SIM-swap attacks that stole more than $8 million in cryptocurrency and thousands of credentials – Buchanan Plea
  • The Gentlemen ransomware operation used SystemBC infrastructure tied to more than 1,570 compromised corporate networks, while lawmakers continue debating harsher responses to hospital ransomware attacks – SystemBC C2, Hospital Ransomware

Microsoft & Enterprise Security

  • Microsoft issued emergency patches for CVE-2026-40372, a critical ASP.NET Core flaw that could let attackers gain SYSTEM privileges, and warned customers to rotate DataProtection keys – ASP.NET Fix, Emergency Patch
  • Microsoft SharePoint admins are still exposed to active spoofing attacks via CVE-2026-32201, with more than 1,300 servers vulnerable and fewer than 200 reportedly patched – SharePoint Spoofing
  • Microsoft also traced Universal Print failures to a Graph API code change, while rolling out Teams efficiency features and expanded OneDrive AI/compliance updates – Universal Print, Teams Update, OneDrive Update
  • A new GoGra Linux backdoor used Microsoft Graph API and hardcoded Azure AD credentials for covert command-and-control, highlighting abuse of cloud identity services – GoGra Backdoor

Supply Chain & Vulnerabilities

  • A malicious npm supply-chain attack compromised Namastex Labs packages, stole auth tokens and secrets, and tried to self-propagate across ecosystems including PyPInpm Attack
  • Oracle shipped 481 patches in its April 2026 CPU, covering about 450 CVEs with more than 300 remotely exploitable bugs across major product families – Oracle CPU
  • CISA added multiple actively exploited flaws to its KEV catalog, including Cisco Catalyst SD-WAN Manager bugs such as CVE-2026-20133, along with issues in PaperCut NG/MF, JetBrains TeamCity, Quest KACE and ZimbraCISA KEV, SD-WAN Flaw
  • More than 20,000 Lantronix and Silex serial-to-IP converters are exposed by 22 BRIDGE:BREAK flaws, widening attack surface for industrial and remote-access environments – Bridge Flaws
  • VirtualBox 7.2.8 landed with crash fixes, graphics, clipboard and UEFI repairs, plus support for newer Linux kernels – VirtualBox 7.2.8

Cloud, AI & Platform Abuse

  • Vercel said it was breached through a compromised third-party AI tool, Context.ai, leading to access of an employee Google Workspace account and prompting customer credential resets – Vercel Breach
  • Google Antigravity was patched for a sandbox-escape flaw, while criminals also used a fake site to distribute a trojanized installer that stole browser data and walletsAntigravity Attack
  • OpenAI is testing Chronicle for Codex, a screen-memory feature that raises privacy and prompt-injection concerns because it stores recent screen captures locally – Chronicle
  • Tencent launched QClaw, an AI agent app for Windows and macOS, as the enterprise AI assistant race continues – QClaw AI

Threats, Botnets & DDoS

  • Mastodon suffered a major DDoS attack that hit Mastodon.social shortly after a similar disruption to Bluesky, underscoring ongoing pressure on decentralized platforms – Mastodon DDoS
  • ProxySmart-powered SIM farms were found across 17 countries and 94 locations, using mobile proxies, IP rotation and fingerprint spoofing for likely fraud and account abuse – SIM Farm
  • Ofcom opened probes into Telegram and teen chat sites over alleged child safety and grooming failures under the UK Online Safety Act – Telegram Probe

Malware & Mobile/Endpoint Intrusions

  • Lotus, a previously undocumented data wiper, was used against Venezuelan energy and utility firms to disable defenses and make systems unrecoverable – Lotus Wiper
  • Cisco Talos reported that phishing reclaimed the top initial-access spot, while attackers also abused the AI builder Softr, exposed GitHub tokens, and weak MFA and logging to reach cloud environments – Talos Phishing

Cybersecurity News | Daily Recap – hendryadrian.com