2026 Week 17 Privacy Threat Report
docThis week (April 14-20, 2026) saw major security incidents including Microsoft's record-breaking 163-CVE Patch Tuesday with an actively exploited SharePoint zero-day, the McGraw-Hill breach exposing 45M+ records via Salesforce misconfiguration, a critical Vercel-Context.ai OAuth supply-chain attack, Chrome's fourth zero-day of 2026, and the LAPD 7.7TB data leak.
2026 Week 17 Privacy Threat Report
Report Period: April 14–20, 2026
Microsoft's April Patch Tuesday: 163 CVEs, Two Zero-Days
Microsoft released its April 2026 security update on April 14, addressing 163 vulnerabilities across the Windows ecosystem — one of the largest Patch Tuesday releases on record. Eight vulnerabilities were rated Critical, and two were zero-days.
The most urgent is CVE-2026-32201, a spoofing vulnerability in Microsoft Office SharePoint Server that has been confirmed under active exploitation. CISA added it to the Known Exploited Vulnerabilities (KEV) catalog and has mandated federal agencies apply patches by April 28, 2026. CVE-2026-20945, another SharePoint spoofing flaw, was also patched this month.
The second zero-day, CVE-2026-33825, is an elevation-of-privilege vulnerability in Microsoft Defender with a CVSS score of 7.8. It was publicly disclosed and is linked to the "BlueHammer" exploit, with code posted to GitHub on April 3 by a researcher who criticized Microsoft's handling of the disclosure process.
Other critical fixes include:
- CVE-2026-33826 — Remote code execution in Windows Active Directory (CVSS 8.0)
- CVE-2026-32157 — Use-after-free RCE in Remote Desktop Client
- CVE-2026-33827 — Race condition RCE in Windows TCP/IP via specially crafted IPv6 packets
- CVE-2026-23666 — Denial of service in .NET Framework
Additionally, 80 Edge (Chromium-based) vulnerabilities were patched separately earlier in April.
McGraw-Hill Data Breach: 45M+ Records Exposed via Salesforce Misconfiguration
Education publishing giant McGraw-Hill confirmed a significant data breach in April 2026 after the ShinyHunters ransomware group issued an extortion threat. The attack vector was a misconfigured Salesforce environment — a cloud misconfiguration that allowed unauthorized access to internal data hosted on Salesforce web resources.
The breach reportedly exposed approximately 45 million Salesforce records, including personally identifiable information (PII) such as email addresses. Over 100 GB of data was later publicly distributed by the attackers, containing 13.5 million unique email addresses across multiple files. The ShinyHunters group, known for high-profile breaches including AT&T and Nissan, claimed responsibility.
This incident underscores the growing risk of cloud misconfiguration as an attack surface, particularly in enterprise SaaS environments where sensitive data is routinely stored.
Vercel-Context.ai OAuth Supply-Chain Attack
On April 19, 2026, Vercel disclosed a security breach originating from a compromised third-party AI tool. The attack chain began when Context.ai — a conversational analytics platform used by a Vercel employee — was infected with Lumma Stealer malware. This malware harvested credentials that granted access to the employee's Google Workspace OAuth application.
Through the OAuth token, attackers pivoted into Vercel's internal systems and a limited subset of customer environment variables (those not marked as sensitive). The breach also exposed:
- NPM and GitHub access tokens
- 580 employee records
- Partial source code
A threat actor subsequently claimed to possess additional stolen data and demanded $2 million for its return.
The incident highlights the OAuth-based supply-chain risk introduced by third-party SaaS tools integrated into enterprise developer workflows.
Chrome's Fourth Zero-Day of 2026: WebGPU Dawn Vulnerability
Google confirmed its fourth Chrome zero-day vulnerability of 2026 this week, residing in the WebGPU Dawn layer. The flaw was identified in Chrome's April 15 desktop update, which bundled 31 security fixes.
WebGPU provides native GPU-accelerated computing capabilities in the browser — functionality that now rivals the attack surface of native applications. With 3.5 billion Chrome users worldwide, the exposure is significant. Google has begun rolling out Chrome 147 with patches; users are advised to manually trigger updates via the three-dot menu → Help → About Google Chrome.
This follows Chrome's third zero-day (March 31), which was also under active exploitation before patching.
LAPD Data Breach: 7.7TB of Police Documents Leaked
The Los Angeles Police Department confirmed a data breach affecting a digital storage system belonging to the city's Attorney's Office. The World Leaks extortion gang was attributed as the responsible party.
The leaked data totals approximately 7.7 terabytes across 337,000 files, including:
- Police officer personnel files
- Internal affairs investigation records
- Discovery documents containing unredacted criminal complaints
- Witness names and medical information
The data was initially published on the World Leaks dark-web extortion site before being taken down for unknown reasons. The Distributed Denial of Secrets (DDoSecrets) organization reviewed the data before its removal.
Die Linke Qilin Ransomware Attack
Germany's Die Linke ("The Left"), the country's second-largest opposition party with 64 seats in the Bundestag and approximately 123,000 registered members, confirmed a ransomware attack by the Qilin ransomware group.
The attack forced an IT systems outage at the party's headquarters. Qilin claimed to have stolen employee information from party headquarters — though Die Linke stated the membership database was not accessed. Qilin operates on a Ransomware-as-a-Service (RaaS) model and is among the most active threat groups targeting healthcare, education, and critical infrastructure globally.
Booking.com Customer Reservation Data Breach
Booking.com notified affected customers in mid-April 2026 that their reservation details had been compromised. The breach stemmed from a third-party supplier attack, with exposed data including:
- Full names and home addresses
- Booking dates and accommodation details
- Email addresses and phone numbers
- Special requests submitted to hotels
Travelers who received notifications are advised to be alert for phishing and social engineering attacks leveraging the exposed reservation details.
Ransomware Landscape: Qilin, Akira, and DragonForce Lead
Check Point Research's March 2026 threat intelligence report confirms organizations averaged 1,995 weekly cyberattacks in March. Ransomware rose to 672 incidents, with Qilin, Akira, and DragonForce as the dominant threat actors.
Barracuda's SOC Threat Radar for April 2026 highlights a spike in brute-force attacks on network devices and the emergence of ClickFix phishing tactics — where victims are tricked into pasting malicious commands into their browser developer tools.
The Qilin ransomware group has additionally been leveraging BYOVD (Bring Your Own Vulnerable Driver) attacks using vulnerable kernel drivers (rwdrv.sys, hlpdrv.sys) to disable security monitoring callbacks.
Browser & Platform Security Updates
Chrome 147 and Firefox 147
Google's Chrome 147 and Mozilla's Firefox 147 both shipped high-severity patches in April:
- Chrome 147: 31 security fixes, including the fourth zero-day (WebGPU Dawn, CVE-2026 related)
- Firefox 147: Patches for V8 vulnerabilities including CVE-2026-0899 (out-of-bounds memory access)
DigiCert G1 Root Certificate Distrust
On April 15, 2026, both Chrome and Firefox officially revoked trust in DigiCert's G1 root certificates. Any TLS certificates chaining to these roots now trigger browser security warnings. Organizations still using affected certificates must migrate immediately.
Summary Table
| Event | Category | Impact |
|---|---|---|
| Microsoft April Patch Tuesday (163 CVEs, 2 zero-days) | Vulnerability | Critical — patch by April 28 |
| McGraw-Hill breach (45M+ records) | Data Breach | Education sector |
| Vercel-Context.ai OAuth attack | Supply Chain | Developer platform |
| Chrome 4th zero-day (WebGPU Dawn) | Vulnerability | 3.5B Chrome users |
| LAPD 7.7TB data leak | Data Breach | Law enforcement |
| Die Linke Qilin ransomware | Ransomware | German political party |
| Booking.com reservation leak | Data Breach | Hospitality |
| Qilin/Akira/DragonForce ransomware surge | Ransomware | Global |
Report generated: April 21, 2026 | Data period: April 14–20, 2026