ALERT

ACTIVE THREATS: CISA: Hackers now exploit max severity GitLab flaw in attacks  •  How a hole in Lenovos login system let hackers walk into 5,000 Dropbox accounts  •  The US military just turned off ad tracking on its phones. Maybe you should too  •  Hackers exploit Tencent app flaw to deploy GrayRabbit malware  •  CRPx0 ransomware: what you need to know      ACTIVE THREATS: CISA: Hackers now exploit max severity GitLab flaw in attacks  •  How a hole in Lenovos login system let hackers walk into 5,000 Dropbox accounts  •  The US military just turned off ad tracking on its phones. Maybe you should too  •  Hackers exploit Tencent app flaw to deploy GrayRabbit malware  •  CRPx0 ransomware: what you need to know

Home/The Wire/2026-04-14
▶The Wire — Daily Briefing

The Wire — Tuesday, April 14, 2026

The Detection Gap Widens: Months-Long Zero-Days, Supply Chain Collapse, and the Credential Harvest

28 stories analyzed

The Detection Gap Widens: Months-Long Zero-Days, Supply Chain Collapse, and the Credential Harvest

We're watching the security industry's central contradiction play out in real time—our ability to detect threats has improved dramatically, but our ability to respond before attackers extract maximum value has not. Today's story tells us exactly why that matters.

The headline-grabbing moment arrived when Adobe rolled out emergency fixes for a zero-day in Acrobat Reader that attackers had been actively exploiting since at least December. Four months. That's not a vulnerability that slipped through the cracks—that's a vulnerability that weaponized attackers were already using while Adobe and security teams remained in the dark. The fact that it required emergency patching tells us Adobe didn't catch it through their own processes, and neither did the security vendors whose job it is to hunt this stuff. By the time the world knew about it, the damage was already done. Multiple organizations faced warnings about exploited Windows and Adobe flaws, and CISA's Known Exploited Vulnerabilities list swelled again, with another batch of six flaws already in active use. This isn't vulnerability management anymore—it's triage.

A critical zero-day in wolfSSL that weakens ECDSA signature verification shows us that the infrastructure we've spent decades building to authenticate and encrypt traffic has fundamental cracks. A library used everywhere for cryptographic operations can't correctly verify signatures. That's not a minor flaw—that's a foundation problem. Meanwhile, organizations are apparently not ready for the cryptographic transition ahead; a report on operational technology's lack of tools for cryptographic readiness suggests that when post-quantum crypto becomes mandatory, many environments won't even know where to start.

But vulnerabilities are only half the battle. The real damage today is coming from attackers who don't need zero-days when they can compromise the supply chain itself. OpenAI discovered that a GitHub Actions workflow used to sign its macOS app had downloaded a malicious Axios package, a supply chain attack we covered separately when the Axios package injection hit the broader JavaScript ecosystem. The attack worked not because macOS security failed, but because attackers knew that developers trust the package ecosystem. Similarly, CPUID's download infrastructure was compromised to distribute the STX RAT trojan—attackers are now owning distribution channels for widely-trusted system utilities. A fake Claude website is currently serving PlugX RAT, banking on users' trust in the Anthropic name. When supply chain attacks start targeting commodity tools that millions of security professionals rely on, we've entered a different threat landscape.

The credential harvest is equally alarming. A new infostealer called Storm is decrypting browser data server-side, meaning compromised machines don't just leak passwords—they leak live sessions and cookies that bypass MFA entirely. APT41 is targeting cloud environments with a "zero-detection" backdoor designed to extract credentials from AWS, Google, Azure, and Alibaba cloud—targeting the identities that unlock the entire infrastructure stack. JanelaRAT has been used in over 14,700 attacks against Latin American banks, harvesting credentials at scale. These aren't targeted nation-state operations—they're industrialized credential theft at commodity scale.

The scale of data loss deserves its own moment. Basic-Fit's breach affected a million gym members. Booking.com customers had reservations and sensitive booking data exposed. Rockstar Games' analytics data was stolen and leaked when a third-party vendor was compromised—a reminder that your security posture depends on vendors you can't directly control. These aren't small incidents being negotiated quietly with law enforcement. These are major services with millions of users losing control of customer data to extortion gangs.

The one bright spot comes from law enforcement. The FBI and Indonesian police dismantled the W3LL phishing infrastructure that had been behind $20 million in fraud attempts, arresting the developer in what officials called the first coordinated U.S.-Indonesia enforcement action against a phishing kit. An international operation froze $12 million and identified $45 million in cryptocurrency from theft schemes. These wins matter—they show that patient investigation and international cooperation can disrupt organized criminal infrastructure. But they're also tactical. Meanwhile, APT37 is running fresh social engineering campaigns on Facebook, approaching targets to build trust before delivering RokRAT malware. Nation-states are still operating in the open.

The most sobering moment comes from an observation on detection itself. Anthropic restricted its Mythos Preview model after it autonomously found and exploited zero-day vulnerabilities in every major operating system and browser—and the article's author notes that similar AI-powered vulnerability hunting capabilities are weeks or months from widespread use. Our MTTD (mean time to detection) looks great on a spreadsheet. Our post-alert gap—the time between detection and response—does not. And now we're entering an era where attackers will have AI tools to find zero-days faster than we can patch them.

The pattern is unmistakable: attackers are winning in the gaps. They're exploiting vulnerabilities for months before we notice. They're compromising supply chains because we trust the ecosystem. They're harvesting credentials server-side to bypass security controls. They're stealing from millions of users at once. And we're responding with emergency patches and breach notifications after the fact.

What we need to watch next is whether this accelerates changes to fundamental assumptions. Can we move faster than a four-month exploitation window? Should we be treating browser extension ecosystems as untrusted? What does credential security look like when session tokens can be decrypted server-side? The answers to these questions will define security architecture for the next era.

Key Takeaways

  • The detection gap is real: Zero-days remain exploited for months before discovery. Patch velocity hasn't kept pace with attacker speed. Expect more emergency updates.
  • Supply chain is the new perimeter: Compromised package managers, trojanized downloads from trusted vendors, and fake distribution sites are now primary attack vectors. Trust in the ecosystem is a liability.
  • Credentials unlock everything: Session theft, cloud account harvesting, and bank targeting via malware are converging around a single goal—obtaining valid authentication. MFA is no longer a complete answer.
  • Law enforcement can disrupt but can't deter: W3LL's takedown matters tactically, but APT37 and APT41 continue operating openly. Nation-state threats remain unaffected by enforcement actions.

The Wire is HackWire's daily editorial briefing, published every morning.