
Daily Cybersecurity News - April 14, 2026
Adobe Patches Critical PDF Zero-Day
HighExecutive Summary
Adobe has released emergency updates to address CVE-2026-34621, a high-severity zero-day vulnerability in Acrobat and Reader that allows arbitrary code execution. The flaw is currently actively exploited in the wild, enabling attackers to silently steal data and potentially compromise systems via maliciously crafted PDF files.
Vulnerability Details
- Affected Product: Adobe Acrobat and Reader DC versions 26.001.21367 and earlier, and 2024 versions 24.001.30356 and earlier
- Identifier: CVE-2026-34621
- CVSS Score: 8.6 (High)
- Exploitation Status: Actively Exploited
Risk & Impact
- Triage: Critical urgency; patch immediately due to active, targeted exploitation and inclusion in CISA’s KEV catalog.
- Attack Vector: Opening a maliciously crafted PDF triggers a prototype pollution flaw, abusing privileged APIs to leak data and execute arbitrary code.
- Ease of Exploit: High; requires no user interaction beyond simply opening the booby-trapped PDF file.
Action Plan
- Immediate Action: Upgrade to Version 26.001.21411 (DC) or 24.001.30362/24.001.30360 (2024).
- Workaround: Disable JavaScript in Adobe Reader preferences (Edit > Preferences > JavaScript > Uncheck ‘Enable Acrobat JavaScript’) and avoid opening untrusted PDFs.
- Detection: Monitor HTTP/HTTPS traffic for the “Adobe Synchronizer” string in the User Agent field and scan endpoints for known malicious PDF hashes associated with the exploit.
Relevant professional terms
- Zero-Day
- A software vulnerability that is exploited by attackers before the vendor has released a patch, giving defenders “zero days” to prepare or mitigate the flaw.
- Prototype Pollution
- A JavaScript vulnerability where an attacker modifies the base object prototype, causing other objects to inherit malicious properties, which can lead to arbitrary code execution or application compromise.
ShowDoc Suffers Active RCE Exploitation
CriticalExecutive Summary
A critical unrestricted file upload vulnerability (CVE-2025-0520) in the ShowDoc collaboration platform is currently being actively exploited in the wild. Threat actors are leveraging this flaw to deploy web shells and achieve remote code execution on unpatched servers.
Vulnerability Details
- Affected Product: ShowDoc (versions prior to 2.8.7)
- Identifier: CVE-2025-0520
- CVSS Score: 9.4 (Critical)
- Exploitation Status: Actively Exploited
Risk & Impact
- Triage: Immediate patching is required as active exploitation is ongoing, particularly targeting internet-facing instances.
- Attack Vector: Improper validation of file extensions allows unauthenticated attackers to upload arbitrary PHP files, which are then executed by the server.
- Ease of Exploit: Trivial to exploit; requires no authentication and can be executed remotely over the network.
Action Plan
- Immediate Action: Upgrade immediately to ShowDoc Version 2.8.7 or later (version 3.8.1 is currently available).
- Workaround: Restrict file upload capabilities, enforce strict file extension allowlists, and disable PHP execution within upload directories.
- Detection: Monitor upload directories for unauthorized
.phpfiles, hunt for web shell signatures, and analyze web server logs for anomalous upload requests.
Relevant professional terms
- Remote Code Execution (RCE)
- A severe vulnerability that allows an attacker to run arbitrary malicious commands or code on a target machine over a network.
- Web Shell
- A malicious script deployed on a web server to grant an attacker persistent remote administrative access to the compromised system.
Fortinet SQL Flaw Triggers CISA Alert
CriticalExecutive Summary
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added six vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, prominently featuring CVE-2026-21643, a critical SQL injection flaw in Fortinet FortiClient EMS. This vulnerability is currently under active exploitation, allowing unauthenticated attackers to execute unauthorized code and extract sensitive data.
Vulnerability Details
- Affected Product: Fortinet FortiClient EMS version 7.4.4 (multi-tenant mode)
- Identifier: CVE-2026-21643
- CVSS Score: 9.1 (Critical)
- Exploitation Status: Actively Exploited
Risk & Impact
- Triage: Immediate patching required for internet-exposed instances.
- Attack Vector: Unauthenticated remote attackers send specially crafted HTTP requests to the EMS administrative interface.
- Ease of Exploit: High; requires no credentials and can be triggered via a single crafted HTTP header.
Action Plan
- Immediate Action: Upgrade to Version 7.4.5 immediately.
- Workaround: Restrict network access to the administrative interface to trusted IP ranges and block anomalous HTTP headers.
- Detection: Review EMS server logs for anomalous API requests and unexpected child process spawning.
Relevant professional terms
- SQL Injection
- A web vulnerability where attackers insert malicious SQL statements into application inputs, tricking the database into revealing data or executing unauthorized commands.
- Known Exploited Vulnerabilities (KEV)
- A CISA-maintained catalog of security flaws confirmed to be under active exploitation, used to prioritize urgent patching across federal agencies and industry.
Venice Flood Defenses Suffer Critical Breach
Executive Summary
Hackers breached Venice’s San Marco hydraulic pump system, gaining root access to critical flood defenses. The attackers claimed the ability to disable floodgates, threatening physical flooding.
Attack Overview
- Attack Path: Exploited internet-facing OT systems via credential stuffing and default passwords to manipulate HMI interfaces.
- Attacker: Infrastructure Destruction Squad
Impact Assessment
- Operational Impact: Attackers gained full root access to manipulate SCADA data, posing a severe physical threat before being locked out.
Detection & Hunting
- Detection Guidance: Monitor internet-facing OT assets for unauthorized access, enforce strong authentication, and segment HMI networks.
Strategic Takeaway
Exposing operational technology to the public internet without robust access controls transforms digital vulnerabilities into physical disasters.
Relevant professional terms
- Operational Technology (OT)
- Hardware and software used to monitor and control physical industrial processes and machinery.
- SCADA
- Supervisory Control and Data Acquisition systems used to control and monitor industrial infrastructure.
Mirax RAT Converts Androids into Proxy Nodes
Executive Summary
The Mirax Android RAT is actively targeting Spanish-speaking users via malicious Meta advertisements. Operating as a private MaaS, it steals credentials and transforms over 220,000 compromised devices into residential proxy nodes.
Key TTPs
- Initial Access: Malicious Meta ads lure victims into downloading dropper apps hosted on GitHub.
- Execution: Masquerades as a video utility, abuses Accessibility Services, and establishes WebSocket C2 channels.
- Defense Evasion: Employs GoldCrypt obfuscation, displays fake installation errors, and bypasses Google Play Protect.
Campaign Analysis
Mirax represents a significant evolution by combining traditional banking trojan capabilities with residential proxy botnet features. This allows threat actors to monetize infections while bypassing IP-based fraud detection systems.
Targeting & Infrastructure
- Target Profile: Spanish-speaking users and European regions; MaaS access is restricted to elite Russian-speaking affiliates.
- Infrastructure: Leverages GitHub for dropper hosting and uses SOCKS5 with Yamux multiplexing over WebSockets.
Relevant Terms
- SOCKS5: An internet protocol that routes network traffic through a proxy server, often used to mask a user’s real IP address.
- WebSocket: A communications protocol providing full-duplex, real-time data transfer over a single, long-held TCP connection.
Malicious Chrome Extensions Exfiltrate User Sessions
Executive Summary
A campaign of 108 malicious Chrome extensions compromised 20,000 users. They masquerade as legitimate tools to steal Google OAuth2 tokens and Telegram sessions via shared C2 infrastructure.
Key TTPs
- Initial Access: Users install malicious extensions disguised as legitimate tools from the Chrome Web Store.
- Execution: Extensions inject arbitrary JavaScript and utilize universal backdoors upon browser startup.
- Defense Evasion: Extensions strip security headers and use multiple fake publisher identities to bypass store reviews.
Campaign Analysis
This highlights a trend of supply chain attacks using shared infrastructure and decoy UIs. Exploiting OAuth2 allows persistent account takeover without passwords.
Targeting & Infrastructure
- Target Profile: General users of Google Workspace, Telegram Web, YouTube, and TikTok.
- Infrastructure: 108 extensions across 5 fake publishers routing data to a single C2 server.
Actionable Intelligence
- IPs:
144. 126. 135. 238 - Domains:
cloudapi. stream,mines. cloudapi. stream
Relevant Terms
- OAuth2: A framework allowing apps limited access to user accounts without exposing passwords.
- C2: A server used by attackers to control compromised systems and exfiltrate data.