Executive Summary
Executive Summary: Weekly CTI Report
- Key developments
- Critical vulnerabilities affecting core infrastructure emerged, including an authentication bypass in cPanel/WHM and a privilege escalation flaw in the Linux kernel "Copy Fail." These enable unauthorized access or elevation on internet-facing servers and backend systems. Analyses cover the cPanel authentication bypass (CVE-2026-41940) and the Linux Kernel 'Copy Fail' root access vulnerability.
- A PyPI software package, with over one million monthly installations, was compromised to distribute data-stealing malware. This shows ongoing software supply chain risks, affecting development and dependent systems.
- Prompt injection techniques against large language model applications from providers like Claude, Gemini, and Copilot were publicly detailed. This reveals a new method for adversaries to manipulate AI systems, impacting organizations using these tools. Details on AI cybersecurity threats are available.
- A home security service provider disclosed a data breach affecting 5.5 million individuals. This indicates large data compromises across multiple sectors, exposing substantial volumes of records.
- Business impact
Operational risk from compromised software and user data exposure increased. Service availability, data confidentiality, and system integrity are under pressure due to mass exploitation and supply chain attacks. Customer trust and regulatory compliance aspects are also affected given recent large-scale data breaches affecting consumer services and sensitive personal information.
- Notable trends and changes vs last week
The past week maintained rapid weaponization of newly disclosed critical vulnerabilities in widely deployed infrastructure. Ransomware activity (181 victims) remained high. AI model manipulation, via prompt injection, shows an evolving adversarial approach. Geopolitical cyber activity, including hacktivist campaigns, maintained a steady presence.
- Outlook
The coming 7 days are likely to see continued exploitation of internet-facing cPanel installations and systems vulnerable to the Linux kernel 'Copy Fail' flaw. Ransomware operations are expected to sustain current pace, focusing on data exfiltration and public disclosure. Experimentation with AI-assisted offensive techniques, like prompt injection, is projected to remain active. Politically motivated cyber operations are also expected to persist.
Key Threat Intelligence Highlights
A critical authentication vulnerability has been identified in cPanel, allowing attackers to gain unauthorized access to hosting servers. This flaw could lead to server compromise, enabling data theft and complete control over hosted websites. cPanel administrators are advised to apply security updates immediately to protect their systems from exploitation.
A recently discovered nine-year-old Linux kernel vulnerability, named "Copy Fail" (CVE-2023-51785), allows unprivileged local users to achieve full root access. This flaw in the copy_file_range() system call permits overwriting arbitrary read-only kernel memory pages, leading to complete system compromise. Its widespread presence across numerous Linux kernel versions makes immediate patching important for all administrators to counter the significant risk of local privilege escalation.
Home security giant ADT reported a data breach impacting 5.5 million people after a third-party vendor's marketing database was accessed without authorization. This event exposed customer names, addresses, and contact information, potentially leading to increased phishing and spam risks for those affected. The incident shows the challenges companies face in protecting sensitive client information, even within the security sector.
A widely used PyPI package, downloaded over a million times monthly, was compromised to distribute an infostealer. This resulted in the potential theft of sensitive user data, including cryptocurrency wallet information and browser credentials. The incident shows the ongoing risks within software supply chains, often originating from compromised developer accounts.
Prompt injection attacks are compromising AI models such as Claude, Gemini, and Copilot by embedding malicious instructions within GitHub repository files. These hidden commands can trick AI systems into disclosing sensitive data or generating unintended, harmful outputs. This new attack vector reveals a critical vulnerability in how AI assistants process external information, affecting their trustworthiness and posing risks to user security.
Additional Threat Intelligence Context
CVE-2026-41940 | CVSS: NA (CRITICAL) - Mass exploitation of , a critical authentication bypass in cPanel/WHM, allowing unauthenticated root access to shared-hosting servers and deployment of Sorry ransomware.
Available Exploits:
- CVE-2026-41940 Exploit
- CVE-2026-41940 Exploit
- CVE-2026-41940 Exploit
- CVE-2026-41940 Exploit
- CVE-2026-41940 Exploit
Analysis: # CVE Analysis Report: CVE-2026-41940
GitHub Link:
- Title: cpanel-0day defensive posture scanner
- CVE: CVE-2026-41940 (CRITICAL)
- CVSS Score: NA
- CVSS Severity: CRITICAL
- Complexity Score: Easy
- Remote/Local: Remote
- Authenticated/Unauthenticated: Authenticated
- Privilege Required: System
Risk Score: 100/100
_Based on ease of use, potential impact, how widely it...
CVE-2026-31431 | CVSS: None (CRITICAL) - Active exploitation of (Linux Copy Fail), a local privilege escalation in the Linux kernel, providing root access on major distributions and container platforms.
Available Exploits:
- CVE-2026-31431 Exploit
- CVE-2026-31431 Exploit
- CVE-2026-31431 Exploit
- CVE-2026-31431 Exploit
- CVE-2026-31431 Exploit
Analysis: # CVE Analysis Report: CVE-2026-31431
GitHub Link:
- Title: 732 Bytes to Root PoC
- CVE: CVE-2026-31431 (CVSS: None, CRITICAL)
- CVSS Score: None
- CVSS Severity: CRITICAL
- Complexity Score: Easy
- Remote/Local: Local
- Authenticated/Unauthenticated: Unauthenticated
- Privilege Required: User
Risk Score: 95/100
_Based on ease of use, potential impact, how widely it could spread, and ...
Supply-chain attacks, such as the 'Mini Shai-Hulud' campaign, backdooring SAP npm packages and PyTorch Lightning wheels to steal GitHub, cloud, and CI/CD credentials.
CVE-2024-1708 | CVSS: 8.4 (HIGH) - Widespread exploitation of ConnectWise ScreenConnect RCE ( / CVE-2024-1709) for unauthenticated remote code execution, used for ransomware staging and network persistence.
Available Exploits:
- CVE-2024-1708 Exploit
- CVE-2024-1708 Exploit
Analysis: # CVE Analysis Report: CVE-2024-1708
GitHub Link:
- Title: Acronis Cyber Protect/Backup unauth RCE CVE-2022-3405
- CVE: CVE-2022-3405 (CVSS: 8.4, HIGH)
- CVSS Score: 8.4
- CVSS Severity: HIGH
- Complexity Score: Medium
- Remote/Local: Remote
- Authenticated/Unauthenticated: Unauthenticated
- Privileg...
CVE-2026-42208 - Rapid exploitation of LiteLLM , a SQL injection flaw in AI proxy stacks, allowing credential theft from OpenAI, Anthropic, and AWS Bedrock.
The ongoing Instructure / Canvas environment breach, claimed by ShinyHunters and SLSH, impacting data from roughly 9,000 schools and 275 million individuals.
Sustained, politically motivated DDoS campaigns by '313 Team' disrupting critical Ubuntu/Canonical services, affecting the open-source community.
CVE-2024-4577 | CVSS: 9.8 (CRITICAL) - Active exploitation of PHP CGI Argument Injection () for arbitrary command execution via crafted HTTP requests, deploying cross-architecture cryptominers.
Available Exploits:
- CVE-2024-4577 Exploit
- CVE-2024-4577 Exploit
- CVE-2024-4577 Exploit
- CVE-2024-4577 Exploit
- CVE-2024-4577 Exploit
Analysis: # CVE Analysis Report: CVE-2024-4577
GitHub Link:
- Title: CVE-2024-4577 PHP CGI Arg Injection PoC
- CVE: CVE-2024-4577 (CVSS: 9.8, CRITICAL)
- CVSS Score: 9.8
- CVSS Severity: CRITICAL
- Complexity Score: Easy
- Remote/Local: Remote
- Authenticated/Unauthenticated: Unauthenticated
- Privilege Required: None
Risk Score: 100/100
_Based on ease of use, potential impact, how widely ...
Ransomware Activity Overview
Ransomware activity persists, with Sorry ransomware using the cPanel/WHM flaw for mass deployment. Other groups like Everest, M3RXDLS, INC_Ransom, Mnt6, and Fulcrum continue to list new victims across financial technology, legal, healthcare, and industrial supply sectors, often involving data theft and publication.
Data breaches are large. Beyond the Instructure/Canvas incident impacting 275 million individuals, other data sales include 55 GB of 'World Wide passports' from ezcloud.vn, 1.4 billion records related to Tencent.com, 20 million Ticketmaster databases, and 4.6 million Wells Fargo bank records. Additionally, a 10+ PB leak from China's NSCC supercomputing environment had military implications, and a Russia Pension Fund database with over 100 million records was exposed.
Geopolitical cyber activity includes claims by the 313 Team to disrupt Ubuntu infrastructure, Infrastructure Destruction Squad targeting Albanian government and diplomatic systems with exfiltration of 53 GB of sensitive archives, and OpIsrael-aligned actors attacking Israeli corporate services. BreachForums leadership declared a 'mobilization war' stance against law enforcement and rival actors, showing ongoing cohesion for illicit data activities. Politically motivated DDoS and defacement campaigns are observed against targets in Thailand, Venezuela, and Israel.
During the reporting period, 181 total victims were identified across 36 active ransomware groups. The top 5 most active groups accounted for 88 victims.
Top 5 Ransomware Groups
Qilin - 30 victim(s)
- Notable victims: Abazia spa, Accurate nursing services, Admins, Antica sartoria, Apothebeauty (and 25 more)
Fulcrum - 22 victim(s)
- Notable victims: analog-prospector, avnet-leaks, bookblock, crank-communications, credielite (and 17 more)
DragonForce - 13 victim(s)
- Notable victims: Andrewtjohnson.com, Aotco.com, Avalonflooring.com, Bela - pharm, Delonhampton.com (and 8 more)
The_Gentelman - 12 victim(s)
- Notable victims: Acfa regionale de calgary, Beaconhouse school system, Colegio notre dame campinas, Diviso grupo financiero, Fabritius (and 7 more)
INC_Ransom - 11 victim(s)
- Notable victims: Arban & Carosi, BELFOR, Iowa Spring Manufacturing & Sales, Selex - Gruppo Commerciale, (and 6 more)
Deep Web
Deep Web Observations for the Week
This week, deep web forums hosted many important data exposures, including state-level military secrets, large financial records, and highly sensitive government and critical infrastructure access. The observed activity shows a persistent and varied set of adversaries targeting a broad spectrum of sectors with broad consequences.
What major data leaks appeared on deep web forums this week?
Several major data leaks surfaced this week, including large amounts of classified military research, complete financial customer data, and credentials related to national security contractors. These disclosures show capabilities from advanced state-level intrusion to large-scale commercial data exfiltration.
National Supercomputing Center (NSCC) China Breach
A large data leak from China's National Supercomputing Center (NSCC) Tianjin and associated high-performance clusters (AVIC, COMAC, space programs) was advertised. This incident involves over 10 Petabytes of classified military and aerospace research. The exfiltrated data covers years of raw simulation data, design files, and satellite telemetry. Specific contents include full schematics for the Taiji-1 Gravitational Wave Detection Satellite, AVIC Aviation Industry helicopter designs with ANSYS/Abaqus simulations, bunker and explosive impact simulations, sonic boom prediction studies, and satellite radar/raw observation data from 2015-2022 Tibet atmospheric datasets. Employee personal data, including full scans of Chinese ID cards with names, addresses, and IDs, were also part of this compromise. This data set presents information about the computational backbone of China's advanced military-aerospace initiatives.
Financial and Retail Sector Breaches
The actor "ShinyHunters" was active, presenting multiple large-scale breaches:
- Santander Groupo Bank: This leak comprises 1.6 billion lines of data, including information on 30 million customers, 64 million account numbers with balances, and 28 million credit card numbers. HR employee lists and consumer citizenship information are also exposed, affecting customers in Spain, Chile, and Uruguay. The depth of this financial data could enable significant fraud.
- Neiman Marcus: A retail data breach affecting Neiman Marcus exposed 182 million customer profiles, including 3 million plaintext credit card numbers. The data also contains names, addresses, phone numbers, dates of birth, email addresses, last four digits of SSNs, and 70 million transaction records. This also incorporated 50 million customer emails with IP tracking and 12 million gift card numbers. The disclosure indicates a direct financial compromise.
- Major Financial Company API Access: An offering for "critical API access" from a major financial transactions company was posted, priced at $1 million USD. This API reportedly facilitates transactions across more than 20 countries and multiple financial systems. The identified affected currencies and regions span Latin America, Asia, Africa, and the Middle East, including Brazil, Mexico, India, Nigeria, and the United Arab Emirates. This access represents a significant risk for supply chain attacks and broad financial manipulation.
- Odido NL & Ben.nl (Telecommunications): Over 15 million Salesforce records belonging to the Dutch telecommunications providers Odido NL and Ben.nl were made available. This data set, totaling over 88GB (uncompressed), contains full names, physical addresses, email addresses, phone numbers, plaintext passwords, IBANs, passport numbers, and driver's license numbers. The exposure of such complete PII and financial identifiers for a national telecommunications customer base is large.
Government and Defense-Related Data Exposures
Several breaches this week impacted governmental and national security entities:
- Space-Eyes.com (US National Security Contractor): ShinyHunters also disclosed the entire dataset from Space-eyes.com, a contractor serving various US government agencies including the Department of Justice, Department of Homeland Security, branches of the US military, US Space Force, and the National Geospatial-Intelligence Agency. The breach, dated April 2024, exposed confidential documents, including "denied person" lists and user credentials (some hashed, some with what appear to be encrypted passwords) for individuals associated with these defense and intelligence organizations.
- FBI Data: A forum post by "spider321" claimed to possess thousands of FBI records, providing a sample that included email addresses with plaintext passwords for "fbi.gov" and "ic.fbi.gov" domains. This type of credential exposure allows for potential unauthorized access to government systems and internal communications.
- Philippines National Police (PNP) Officer Data: A new actor, "FuckSpy," posted data pertaining to both active and retired officers of the Philippines National Police (PNP). This data includes sensitive employee information, personal details, family records, firearm details, promotion histories, and Statements of Assets, Liabilities, and Net Worth (SALN). Such complete personal and professional details create significant security risks for affected individuals.
- Law Enforcement/Government Email & Portal Sales: A user named "convince" offered for sale law enforcement and government emails, along with access to social media Law Enforcement Portals for platforms like Instagram, Facebook, TikTok, and WhatsApp. These tools enable Emergency Data Requests (EDRs) to obtain IP information, device details, emails, phone numbers, and sometimes message logs. Additionally, the vendor offers forged court orders and subpoenas for broader data access and domain suspension services. This provides direct means for malicious actors to impersonate law enforcement and conduct surveillance or account takeovers.
AstraZeneca Group Leak
A post by a forum moderator ("Tanaka") detailed a compromise of AstraZeneca Group data, attributed to "Lapsus Group." The breach, dated March 25, 2026, involves the theft of the company's source code, employee databases, API keys, and cloud infrastructure credentials (including AWS keys). Sample data analysis confirmed exposed GitHub user information and employee details from AstraZeneca clinical research entities. This exposure allows for industrial espionage, intellectual property theft, and further system exploitation.
What patterns and trends emerge from this week's deep web breach data?
This week's data reveals several patterns, including many target sectors, a persistent appearance of an active breach group, and a shift towards monetizing access tools in addition to raw data.
- Diverse Targeting with Serious Implications: Breaches affected sensitive sectors: national defense (China NSCC, Space-Eyes), critical financial infrastructure (Santander, global financial API), national law enforcement (FBI, Philippines PNP, EDR sales), and major corporations (Neiman Marcus, AstraZeneca, Odido). This indicates a varied set of motivations, from state-sponsored espionage and intellectual property theft to direct financial gain and tools for further illicit activity.
- Emergence of Capable Actors: The actor "ShinyHunters" shows a sustained and broad operational capability, appearing in five of the notable incidents, affecting financial, retail, telecommunications, and national security contractor targets. This group consistently obtains large amounts of sensitive data, often including plaintext credentials or critical access mechanisms.
- Shift to Access and Tool Monetization: Beyond the direct sale of compromised data, there's an observable trend toward offering access points and tools for subsequent exploitation. Examples include the sale of critical financial API access and the offerings of government emails/law enforcement portals for Emergency Data Requests. This allows buyers to conduct their own operations, extending the reach of the initial compromise.
- Volume and Granularity of PII: Several breaches, particularly Santander, Neiman Marcus, and Odido, exposed tens to hundreds of millions of individual records. The inclusion of plaintext passwords, credit card numbers, IBANs, passport numbers, and driver's license numbers provides much material for identity theft, financial fraud, and account takeovers.
- National Security as a Recurring Target: Three breaches (China NSCC, Space-Eyes, FBI) directly relate to national security, defense, or intelligence, along with the leak of Philippines police data. This suggests a continuous focus by adversaries on intelligence gathering, disruption, and using governmental information for various objectives.
What is the potential impact of these observed deep web breaches?
The potential impact of these deep web breaches is significant, affecting national security, individual privacy, financial systems, and corporate intellectual property.
- National Security Compromise: The compromise of 10+ petabytes of Chinese military and aerospace research poses a significant risk for national defense capabilities and could alter geopolitical balances. Similarly, the Space-Eyes.com breach, involving a US national security contractor, and the exposure of FBI employee credentials could jeopardize intelligence operations, personnel security, and access to classified systems. The PII of Philippines National Police officers also creates opportunities for targeting, blackmail, and coercion.
- Widespread Financial Fraud and Identity Theft: The large-scale leaks from Santander Groupo Bank, Neiman Marcus, and Odido NL & Ben.nl provide adversaries with millions of plaintext credit card numbers, account balances, IBANs, and complete PII. This enables immediate financial exploitation, sophisticated identity theft schemes, and long-term financial fraud against affected individuals and institutions. The sale of API access to a major financial company could allow for large-scale transaction manipulation across many countries, potentially disrupting financial markets.
- Governmental Process Exploitation: The sale of law enforcement emails and portal access for Emergency Data Requests provides a new avenue for criminals to bypass legal processes, conduct unauthorized surveillance, and manipulate or remove content on social media platforms. This undermines public trust in digital platforms and law enforcement agencies.
- Corporate Espionage and Competitive Disadvantage: The AstraZeneca leak of source code, employee databases, and cloud credentials presents a risk of industrial espionage, allowing competitors to gain insights into pharmaceutical research and development, or enabling further attacks on the company's infrastructure.
- Supply Chain Vulnerabilities: The sale of API access to a financial transactions company with global reach introduces a significant supply chain risk. Unauthorized access to such an API could have cascading effects across multiple financial systems and partners, leading to widespread disruption and financial losses.
Sources
- Critical cPanel Authentication Vulnerability Identified - Update Your Server Immediately
- 9-Year-Old Linux Kernel Vulnerability "Copy Fail" Enables Full Root Access
- Home security giant ADT data breach affects 5.5 million people
- PyPI package with 1.1M monthly downloads hacked to push infostealer
- Claude, Gemini, and Copilot Hit by GitHub Prompt Injection