2026 Week 18 Privacy Threat Report

doc

This week (April 21-27, 2026) saw critical security events including Microsoft's massive April Patch Tuesday addressing 167 CVEs with two zero-days, the Vercel breach via compromised Context.ai OAuth application affecting customer environment variables, Chrome's fourth zero-day vulnerability, ongoing Qilin ransomware operations with new BYOVD tactics, and significant Git NTLM hash leakage vulnerability.

2026 Week 18 Privacy Threat Report

Report Period: April 21–27, 2026


Microsoft's April Patch Tuesday: 167 CVEs, Two Zero-Days

Microsoft released its April 2026 security update on April 14, addressing 167 vulnerabilities across the Windows ecosystem. Eight vulnerabilities were rated Critical, including seven remote code execution flaws and one denial of service. Two zero-days were patched — one actively exploited and one publicly disclosed prior to the patch.

The most urgent is CVE-2026-32201, a spoofing vulnerability in Microsoft Office SharePoint Server caused by improper input validation. It has been confirmed under active exploitation and was added to CISA's Known Exploited Vulnerabilities (KEV) catalog. Federal agencies were mandated to apply patches by April 28, 2026.

The second zero-day, CVE-2026-33825, is an elevation-of-privilege vulnerability in Microsoft Defender with CVSS 7.8. It was publicly disclosed and linked to the "BlueHammer" exploit, with proof-of-concept code posted to GitHub on April 3.

Critical fixes include:

  • CVE-2026-33826 — Remote code execution in Windows Active Directory (CVSS 8.0)
  • CVE-2026-32157 — Use-after-free RCE in Remote Desktop Client
  • CVE-2026-33827 — Race condition RCE in Windows TCP/IP via IPv6 packets
  • CVE-2026-23666 — Denial of service in .NET Framework (Critical)

Additionally, 80 Edge (Chromium-based) vulnerabilities were patched separately earlier in April.


Vercel Security Breach: Context.ai OAuth Supply-Chain Compromise

On April 19, 2026, Vercel disclosed a security incident that exposed internal systems and customer data. The attack chain began when Context.ai — a conversational analytics platform integrated with Vercel's developer workflow — was compromised via Lumma Stealer malware, likely delivered through a Roblox game cheat.

The malware harvested credentials granting access to a Vercel employee's Google Workspace OAuth application. Through this OAuth token, attackers pivoted into Vercel's internal systems and accessed a limited subset of customer environment variables (those not marked as sensitive). The breach also exposed:

  • NPM and GitHub access tokens
  • 580 employee records
  • Partial source code

A threat actor subsequently claimed to possess additional stolen data and demanded $2 million for its return. Vercel confirmed the breach on April 19 and engaged external incident response experts.

This incident highlights growing OAuth-based supply-chain risks from third-party SaaS integrations in developer workflows.


Chrome's Fourth Zero-Day of 2026: WebGPU Dawn Vulnerability

Google confirmed its fourth Chrome zero-day vulnerability of 2026 this week. The flaw resides in the WebGPU Dawn layer, which provides native GPU-accelerated computing in the browser — an expanding attack surface.

Chrome 147 was released with patches. With 3.5 billion Chrome users worldwide, immediate updating is critical. Users should manually trigger updates via the three-dot menu → Help → About Google Chrome.

This follows Chrome's third zero-day (March 31), which was also under active exploitation.


Git NTLM Hash Leak: CVE-2026-32631 in Git for Windows

A critical vulnerability in Git for Windows was disclosed this week. CVE-2026-32631 allows an attacker to leak user NTLM hashes when a victim executes git clone from a manipulated repository.

NTLM hashes are valuable to attackers as they can be used for pass-the-hash attacks, enabling lateral movement without password cracking. This affects all Git for Windows users on Windows environments using NTLM authentication.


Qilin Ransomware Surge: New BYOVD Tactics Targeting Healthcare

The Qilin ransomware group continues to dominate the threat landscape in April 2026. Recent attacks have introduced new Bring Your Own Vulnerable Driver (BYOVD) tactics, leveraging vulnerable kernel drivers such as rwdrv.sys (ThrottleStop) and hlpdrv.sys to disable security monitoring callbacks.

Check Point Research confirms ransomware rose to 672 incidents in March 2026, with Qilin, Akira, and DragonForce as the dominant threat actors. Qilin has been particularly aggressive in targeting healthcare and critical infrastructure.

Barracuda's April 2026 SOC Threat Radar also notes a spike in brute-force attacks on network devices and the emergence of ClickFix phishing — where victims are tricked into pasting malicious commands into browser developer tools.


Browser & Platform Security Updates

Chrome 147 and Firefox 147

  • Chrome 147: 31 security fixes including WebGPU Dawn zero-day
  • Firefox 147: Patches for V8 vulnerabilities including CVE-2026-0899 (out-of-bounds memory access)

DigiCert G1 Root Certificate Distrust

On April 15, 2026, both Chrome and Firefox officially revoked trust in DigiCert's G1 root certificates. Any TLS certificates chaining to these roots now trigger browser security warnings. Organizations must migrate immediately.


Summary Table

Event Category Impact
Microsoft April Patch Tuesday (167 CVEs, 2 zero-days) Vulnerability Critical — patch by April 28
Vercel-Context.ai OAuth breach Supply Chain Developer platform, customer env vars
Chrome 4th zero-day (WebGPU Dawn) Vulnerability 3.5B Chrome users
Git NTLM hash leak (CVE-2026-32631) Vulnerability Windows Git users
Qilin ransomware + BYOVD tactics Ransomware Healthcare, critical infrastructure
ClickFix phishing campaigns Phishing Global enterprises

Report generated: April 22, 2026 | Data period: April 21–27, 2026

2026 Week 18 Privacy Threat Report