Skip to content
All resources
Cybersecurity Intel · № 08 · 13 – 26 April 2026

Encryption is now optional: the fortnight extortion went pure-exfiltration

Three enterprises extorted through Salesforce in seven days, none of them encrypted. Microsoft's largest Patch Tuesday of 2026 lands with a SharePoint zero-day already being exploited. And CISA's Known Exploited Vulnerabilities catalog grows by eight entries in a week.

Published 27 April 2026 By Blacklight Threat Intelligence Classification TLP:CLEAR · Public
167
Flaws fixed in Microsoft's April Patch Tuesday, incl. one exploited zero-day
8
New CISA KEV entries in one week (Microsoft, Adobe, Fortinet)
13.5M
Records exposed in a single SaaS-misconfiguration breach
3
SaaS-centric extortion incidents in 7 days, all without encryption

Executive summary

  • SaaS misconfiguration is the enterprise attack surface of 2026. Three Salesforce-centric extortion incidents in one week share a root cause the legacy SIEM was never built to see: misconfigured trust, over-permissioned connected apps and anomalous API volumes.
  • Encryption is now optional for the attacker. Pure data-theft extortion bypasses encryptor-focused detection entirely; behavioural signals such as privileged access, bulk exfiltration and token abuse are the tell.
  • The patch-to-exploit window has collapsed. A SharePoint flaw went from patch release to the CISA KEV list on the same day. Waiting for the post-mortem means defending a week behind the threat.

Key findings

14 April 2026 CVE-2026-32201 · KEV

Microsoft patches 167 flaws; SharePoint zero-day under active exploitation

April's Patch Tuesday included a SharePoint Server spoofing flaw (CVE-2026-32201) already exploited in the wild and added to CISA KEV the same day, alongside a 9.8-CVSS Windows IKE remote-code-execution bug and a wormable TCP/IP flaw on IPv6+IPSec systems. Enterprise SharePoint estates in regulated sectors are the immediate priority.

12 – 15 April 2026 ATT&CK T1114 / T1567

Three SaaS extortion incidents in one week, no encryption used

An extortion crew exfiltrated 13.5 million records from one enterprise via a Salesforce environment misconfiguration and threatened 30 million records at a second; a third organisation was listed on an extortion leak site by an actor that operates without any encryption payload. The behavioural pattern: dormant OAuth tokens, over-scoped connected apps and anomalous bulk-export API volumes.

13 April 2026 Ransomware

Qilin ransomware compresses initial-access-to-encryption to minutes

SOC telemetry reporting flags Qilin among the fastest-moving crews this month, with encryption starting minutes after endpoint compromise. Vulnerable internet-facing endpoints remain the primary access vector. At this speed, containment has to happen at machine speed, before a human picks up the queue.

12 April 2026 Supply chain

Travel-sector breach exposes reservation data

A major booking platform confirmed compromise of customer reservation data including names, addresses and booking details. Travel-adjacent incidents carry elevated third-party risk for any enterprise with corporate-travel and supply-chain exposure.

The broader pattern

  • Legacy detection content does not fire on SaaS identity abuse. Rules built around Windows logs and network flow are blind to connected-app scope changes and Data Loader API anomalies.
  • If your detections key on encryptor signatures, the playbook is already outdated. Exfiltration-only extortion produces no encryption event to catch.
  • KEV additions are a same-day operational trigger, not a monthly review item: patch, hunt retroactively, and confirm detection coverage the day an entry lands.

Sector lens

Financial services
SaaS CRM estates hold regulated client data; misconfigured connected apps are a reportable-breach vector. Confirm your SIEM ingests Salesforce and M365 audit events, not just infrastructure logs.
Healthcare
Ransomware pressure continues to shift toward providers; Qilin-speed intrusions leave no time for manual triage on endpoint alerts.
Professional services & real estate
This fortnight's extortion targets show mid-market data-rich firms are in scope, not just global enterprises.
Hospitality & travel
Reservation-data exposure raises downstream phishing and fraud risk against your guests and your corporate travellers.

Suggested priorities to consider

Based on this fortnight's public reporting, these are the areas we would review first. Weigh each against your own environment and risk profile.

01

Patch CVE-2026-32201 on all SharePoint estates now. It is exploited and on KEV; treat exposure as presumed until hunted.

02

Audit Salesforce (and equivalent SaaS) connected-app scopes and dormant OAuth tokens. Revoke anything unused; alert on new scope grants as first-class events.

03

Baseline SaaS API volume per identity, per app, per hour. Bulk-export anomalies are the earliest reliable exfiltration signal.

04

Verify your detection content covers exfiltration-only extortion. If every ransomware detection assumes an encryptor, close that gap this week.

05

Wire KEV additions into a same-day patch-and-hunt workflow. Eight entries landed in one week; the window between patch and exploitation has collapsed.

These suggestions are general commentary based on publicly reported events, provided for information only. They are not tailored security advice and may not suit your environment; validate against your own risk assessment and change-control processes before acting.

How Blacklight handles this

Blacklight's agents baseline every identity and connected app across your SaaS, cloud and endpoint estate, so an over-scoped OAuth grant or an anomalous bulk export is investigated and contained in minutes, encryptor or not. KEV entries are correlated against your actual assets the day they land, with the reasoning trail shown for every verdict.

Book a Demo

Sources & methodology

Primary public sources this issue: Microsoft Security Response Center (April 2026 Patch Tuesday release notes) · CISA Known Exploited Vulnerabilities catalog (entries of 13–16 April 2026) · NVD (CVE-2026-32201 and related) · vendor SOC telemetry reporting (April 2026) · public breach disclosures and leak-site monitoring, 12–19 April 2026 · MITRE ATT&CK v15 for technique mapping.

Methodology. Findings are compiled from public reporting and Blacklight Threat Intelligence monitoring for the stated window, mapped to MITRE ATT&CK where applicable. Aggregate platform observations, where cited, are anonymised across the Blacklight customer base and never identify a customer environment. Corrections: intel@blacklightai.com.

Related reading

Blacklight AI · Cybersecurity Intel · № 08 TLP:CLEAR
Get started

See what truly predictive
security looks like.

Sixty minutes, under your control. See the platform run on a pre-loaded, anonymised environment, watch one real incident handled end to end, and map it to your sector, without connecting a single data source.

A typical demo
  • 01 A live tour on a pre-loaded, anonymised environment, running from minute one, not slides.
  • 02 One real incident, detected, investigated and contained, written up as a regulator-ready report.
  • 03 Mapped to your world: your sources, your sector's threats and your regulators.
  • 04 The questions your board will ask: deployment, residency, security, integrations and TCO.

No connectors or data required from you. A proof-of-value on your own telemetry is the next step, never the ask on a first call.