To the central content area
Toggle Dark/Light Mode Dark Mode
:::

Cybersecurity Monthly Report (April 2026)

Cybersecurity Monthly Report (April 2026)

1. Introduction of Cybersecurity

The AI-Driven Automated Vulnerability Discovery Storm
Current cybersecurity threats have entered an asymmetric war of "AI versus humans." Emerging AI models, led by Anthropic Claude Mythos and OpenAI GPT-5.5, have demonstrated deep logical reasoning capabilities that surpass traditional vulnerability scanning tools.

(1) Full Platform Coverage: Thousands of high-severity vulnerabilities were discovered in mainstream operating systems and browsers in a short period, with an exploit success rate as high as 72%.

(2) Unprecedented Depth of Discovery: System-level vulnerabilities hidden for up to 27 years were found (such as the OpenBSD case), meaning that previously considered "stable and secure" old core systems are now vulnerable to AI.

(3) Accelerated Weaponization of Attacks: Complex code logic is transformed into immediately executable attack instructions, significantly shortening the development cycle from "vulnerability discovery" to "launching an attack." 

When Vulnerability Exploitation Exceeds Disclosure: 
All agencies must face a harsh reality: traditional patching cycles are no longer sufficient to keep up with the speed of AI. According to the "Zero Day Clock," the median time from vulnerability disclosure to exploitation has shrunk from 771 days in 2018 to just 4 hours in 2024. Entering 2026, we face the even more severe challenge of "vulnerability exploitation preceding disclosure," meaning that by the time you receive an update notification, the attack may have already occurred. Furthermore, previously low-priority vulnerabilities or "idle systems" due to their high exploitability can now be automatically recombined and exploited by AI.

Strategic Thinking Shifts from "Preventing Attacks" to "Rapid Recovery"
Faced with AI-driven, automated, large-scale, and low-cost attacks, the core logic of cybersecurity must undergo a paradigm shift. The past belief of "absolutely no chance of being hacked" is an unrealistic illusion. True security lies in "resilience." The allocation of cybersecurity resources should shift from simply "preventing external attacks" to detection, response, and recovery.

Synchronous Evolution of Strategy, Management, and Technology
In response to the various threat trends mentioned above, it is recommended that all agencies re-examine their cybersecurity systems based on the following three dimensions:

(1) Strategy—Upgrading Vulnerability Management Level: This should be personally supervised by management or the head of the government agency, clearly defining cybersecurity governance responsibilities. Cybersecurity resources should be shifted from solely preventative investment to a comprehensive resilience investment encompassing prevention, detection, response, and recovery. 

(2) Management Aspect—Regular Drills on Recoverability and the Principle of Least Privilege: Enterprises and government agencies should ensure that business data has offline, reversible backups at all times, strengthen Business Continuity Planning (BCP) drills, and implement the principle of least privilege.

(3) Technical Aspect—Shortening Detection and Response Time with Defense-in-Depth: Prioritize patching public vulnerabilities and exposures (CVEs) in external systems. In terms of cybersecurity control, fully implement Multi-Factor Authentication (MFA) and adopt Passkey credential technology based on the FIDO2 standard, and disable unnecessary external services and testing interfaces.

Returning to the Basics, Speed Against Speed
Although emerging AI has changed the "speed" and "scale" of attacks, its essence remains the exploitation of system weaknesses and oversights in access control. It has not changed the fundamental principles of cybersecurity; defense-in-depth, vulnerability management, and rigorous identity verification remain the unchanging truths. All agencies must take immediate action to reassess their own cybersecurity risks and reorder their vulnerability patch lists, and use Mean Time To Repair (MTTR) as an important metric for measuring cybersecurity effectiveness, establishing a resilient system for rapid response and remediation.

2. Recent Cybersecurity Incident Sharing
In accordance with the relevant subsidiary laws of the Cybersecurity Management Act, the Ministry of Digital Development announced on April 7, 2026, the appointment of the Cybersecurity Administration to handle cybersecurity-related matters, including:

(1) Auditing the implementation of cybersecurity maintenance plans, submitting improvement reports, and other related matters.

(2) Sharing cybersecurity intelligence, providing rewards, and other related matters.

(3) Reporting, responding to, and conducting drills for cybersecurity incidents, and other related matters.

(4) Conducting suitability checks, cybersecurity skills training, dispatching support, reward and punishment procedures, and other related matters for personnel of government agencies handling cybersecurity matters. 

3. Recent Cybersecurity Incident Sharing
Outsourced Personnel Downloads Hacker Kit, Leading to Malware Implantation on Devices

An agency received an alert from the National Institute for Information and Communications Security (NIICS) that its IT equipment was connected to a suspicious malicious relay station, which was determined to be related to the recent Axios NPM supply chain attack. Investigation revealed that the incident occurred because an on-site staff member of an outsourced vendor downloaded and installed an affected third-party kit on their personal laptop for project development needs. Because the official release version of the kit had been infected with malware, the device was hacked after installation. Furthermore, since the on-site staff member was new and had not yet participated in the project development, there was no immediate concern about the leakage of project code, credentials, API keys, or other information.

Lessons Learned
Supply chain attacks can exploit previously trusted official release and update channels. Attackers can embed malware into normal update or installation processes. Even users who obtain kits through official channels may still be affected, making it difficult for users to identify or prevent such attacks beforehand. Therefore, the focus of protection against such incidents, in addition to continuously monitoring the source of the attack packages and abnormal behavior, should be on damage control to prevent the spread of a single compromised device to internal networks, account credentials, or other system environments. It is recommended that organizations continuously strengthen their protective measures in the following aspects:

(1) Implement separation and control of development and testing environments: Development or testing environments should be separated from the production environment as much as possible, and the scope of systems, data, and credentials they can access should be limited to reduce the risk of spread after a single host is compromised.

(2) Manage outsourced equipment and connection environments: Network segments and areas should be properly planned according to business needs, and the usage environment, network access scope, and necessary security settings of outsourced equipment should be clearly defined to reduce the scope of impact.

(3) Strengthen the inventory of sensitive information in the development environment and the impact assessment of leaks: If a supply chain attack occurs in a development or testing environment, an assessment should be conducted simultaneously to determine whether there is a risk of leakage of project code, API keys, credentials, or environmental variables. Sensitive information inventory, access control, and necessary replacement procedures should be incorporated into the incident response to reduce the risk of subsequent misuse.

4. Cybersecurity Trends
4.1 National Government Cybersecurity Threat Trends

Ex ante joint defense and monitoring
This month, a total of 89,246 cybersecurity joint defense intelligence items were collected from government agencies, (an increase of 16,153 items). Among identifiable threat categories, information collection ranked first (61%), primarily involving the acquisition of information through techniques such as scanning, probing and social engineering. This was followed by intrusion attempts (18%), mainly involving attempts to access unauthorized hosts, and intrusion attacks (9%), most of which involved unauthorized system access or the acquisition of system or user privileges. The distribution of intelligence volume over the past year is shown in Figure 1.

Figure 1: Statistics of cybersecurity monitoring intelligence in joint defense

Hackers are abusing free image sharing space as a platform for distributing malicious files.
Further analysis of joint defense intelligence reveals that hackers have recently been abusing the free image hosting and sharing space PNGUP as a malicious file download site in social engineering phishing email attacks. This website is a free cloud sharing space that allows users to upload files and generate download links for file access or sharing. However, hackers are using its legitimate domain to distribute malicious programs, thus circumventing cybersecurity detection mechanisms. This intelligence has been provided to relevant organizations with joint defense monitoring and protection recommendations.rious organizations for joint defense monitoring and protection recommendations.

In-process reporting and responding
This month, a total of 67 reported cybersecurity incidents (including 18 cases of exercise) were recorded, representing 0.84 times of the volume from the same period last year. The majority of reported incidents were categorized as illegal intrusions, accounting for 65.67% of the total. This month, conducting network attack and defense exercises were started, and the majority of the vulnerabilities discovered were of the type of "insecure configuration settings" such as preset passwords. Statistics for cybersecurity incident reports over the past year are illustrated in Figure 2.

Figure 2: Statistics of cybersecurity incident reports

4.2 Important Vulnerability Alerts

Alert Type Category Description
Vulnerability Alert

Network storage system
QNAP operating system
Severity: 
(CVE-2025-66277: CVSS 9.8)

  • Researchers have discovered a link following vulnerability (CVE-2025-66277) in the QNAP operating system.
  • An unauthenticated remote attacker could exploit this vulnerability to access unauthorized file system paths.
  • QNAP has provided a security advisory and patch recommendations; please update to the patch version outlined in the QNAP advisory as soon as possible.
Software Licensing Management System
Cisco Smart Software Manager On-Prem
Severity: 
(CVE-2026-20160: CVSS 9.8)
  • Researchers have discovered a vulnerability (CVE-2026-20160) in Cisco Smart Software Manager On-Prem that allows arbitrary code execution (RCE).
  • An unauthenticated remote attacker could send specially crafted requests to APIs exposing internal services, enabling them to execute arbitrary commands with root privileges on the underlying operating system.
  • Cisco has provided a security advisory and patch recommendations; please update to the patch version provided in the Cisco advisory as soon as possible.
Router
Juniper JSI vLWC and Junos OS MX series routers 
Severity: 
(CVE-2026-33784: CVSS 9.8)
(CVE-2026-33785: CVSS 8.8)
  • Researchers have discovered high-risk security vulnerabilities (CVE-2026-33784 and CVE-2026-33785) in Juniper JSI vLWC and Junos OS MX series routers.
  • CVE-2026-33784 is a default password exploit vulnerability, allowing unauthenticated remote attackers to log in to the system and gain complete control of the device using the default username and password. CVE-2026-33785 could allow low-privilege local users to execute high-privilege CLI commands without authorization.
  • An official security advisory has been released for vLWC; please update to version 3.0.94 or later as soon as possible.
  • Junos OS MX series routers should also be updated to the patched version according to the official announcement.
Known Exploited Vulnerability

Web browser
Chromium-based browser
Severity: 
(CVE-2026-5281: CVSS 8.8)

  • CISA has added CVE-2026-5281 to its KEV list, and Google has also stated that the vulnerability has been exploited.
  • This vulnerability is a Use After Free vulnerability in Dawn components, allowing a remote attacker to execute arbitrary code under certain conditions using a specially crafted HTML page.
  • It is recommended to update your Google Chrome version as soon as possible, and also check the update status of other browsers such as Microsoft Edge, Brave, Vivaldi, and Opera.

Endpoint Management System
FortiClient EMS
Severity: 
(CVE-2026-21643: CVSS 9.8)
(CVE-2026-35616: CVSS 9.8)

  • CISA has added CVE-2026-21643 to its KEV list, and Fortinet has also indicated that CVE-2026-35616 has been exploited.
  • FortiClient EMS contains SQL injection and improper access control vulnerabilities. Unauthenticated remote attackers could execute unauthorized code or commands through specially crafted HTTP requests.
  • Official security advisories and patch recommendations have been provided. Please update to the patch version announced by Fortinet as soon as possible.

Communication Equipment
Cisco Catalyst SD-WAN Manager
Severity:
(CVE-2026-20122: CVSS 5.4)
(CVE-2026-20128: CVSS 7.5)
(CVE-2026-20133: CVSS 7.5)

  • CISA has added three vulnerabilities (CVE-2026-20122, CVE-2026-20128, and CVE-2026-20133) to its KEV list.
  • The vulnerabilities include improper use of privileged APIs, reversible password storage, and disclosure of sensitive information, potentially leading to arbitrary file overwriting, gaining DCA privileges, or reading sensitive information from underlying systems.
  • Official security advisories and patch recommendations have been provided; please update to the patch version provided in the Cisco advisory as soon as possible.

Alert Explanations:
Vulnerability Alert: This is a verified vulnerability that has not yet been widely exploited by attackers. It is recommended to update the vulnerability as soon as possible.
Known Exploited Vulnerability: Successful attacks using this vulnerability are known. It is recommended to immediately evaluate and patch it.

5. International Cybersecurity News 
OpenAI Impacted by North Korea-Linked Axios Supply
(Source: Security Week)
On April 10, OpenAI reported that it was impacted by a recent Axios supply chain attack on the widely used Axios JavaScript HTTP client library. The attack was attributed to North Korean hacking group UNC1069 and impacted numerous organizations including OpenAI. In late March, attackers compromised an Axios maintainer’s NPM account and published malicious packages that installed a cross-platform remote access trojan (RAT) on Windows, macOS and Linux systems. OpenAI discovered that its macOS app-signing workflow had executed the compromised Axios package, potentially exposing its software signing certificate and notarization materials. OpenAI found no evidence of the certificate being misused, but proactively revoked and rotated the certificate and stopped notarizations with the old certificate. While the malicious Axios packages were detected and removed within hours, cybersecurity firms estimate that at least 135 machines and 3% of affected environments were compromised.

CISA Adds 8 Exploited Flaws to KEV, Sets April-May 2026 Federal Deadlines
(Source: The Hacker News)

CISA added eight actively exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, including three flaws in Cisco Catalyst SD WAN Manager. CVE-2023-27351 (CVSS: 8.2) is an improper authentication flaw in PaperCut NG/MF, CVE-2024-27199 (CVSS: 7.3) is a path traversal bug in JetBrains TeamCity and CVE-2025-32975 (CVSS: 10) is an improper authentication bypass in Quest KACE SMA. CVE 2025-2749 (CVSS: 7.2) is a path traversal vulnerability in Kentico Xperience and CVE-2025-48700 (CVSS: 6.1) is a cross-site scripting flaw in Synacor Zimbra Collaboration Suite. The Cisco SD-WAN Manager vulnerabilities: CVE-2026-20122 (CVSS: 5.4), CVE-2026-20128 (CVSS: 7.5) and CVE-2026-20133 (CVSS: 6.5) allow for file uploads, privilege escalation and exposure of sensitive information. Cisco found that CVE 2026-20122 and CVE-2026-20128 have been exploited in-the-wild since March. Federal agencies must address the Cisco flaws by April 23 and the remaining vulnerabilities by May 4.

6. Laest Cybersecurity Conferences and Events

Date Events/Conferences Participants

16 June 2026

NISAC Technical Exchange Meeting

NISAC Members
Go Top