- GNU Emacs vc-git RCE via .git/config core.fsmonitorArbitrary command execution through version control integration
ThreatNoir Morning Brief — April 1
Morning Review in IT Security — April 1, 2026
April 1st brings critical security developments across multiple threat vectors, from newly discovered zero-day vulnerabilities in widely-used development tools to sophisticated supply chain attacks targeting the security infrastructure itself. Today's landscape underscores the urgent need for proactive vulnerability management and heightened scrutiny of software dependencies.
Claude AI finds Vim, Emacs RCE bugs that trigger on file open
Remote code execution vulnerabilities have been identified in two of the most widely deployed text editors in the software development community. The Vim and GNU Emacs editors contain flaws that allow arbitrary code execution simply through the act of opening a specially crafted file. These vulnerabilities were discovered using straightforward prompts with the Claude AI assistant, demonstrating how modern language models can be leveraged to identify security weaknesses in legacy and contemporary tools alike. The GNU Emacs vulnerability specifically involves the vc-git module and exploitation through malicious .git/config core.fsmonitor settings. Source: Claude AI finds Vim, Emacs RCE bugs that trigger on file open
Weaponizing the Protectors: TeamPCP's Multi-Stage Supply Chain Attack on Security Infrastructure
The threat actor group TeamPCP continues its aggressive campaign targeting the software supply chain, with a particular focus on security tools and infrastructure. The group has announced a strategic partnership with the Vect ransomware operation, expanding its operational capabilities and threat surface. This multi-stage supply chain attack involves several malware families including CanisterWorm and CipherForce, alongside the exploitation of CVE-2025-55182. The coordination between TeamPCP and Vect represents a significant escalation in the sophistication and scope of supply chain threats targeting organizations that rely on open-source security solutions. Source: Weaponizing the Protectors: TeamPCP's Multi-Stage Supply Chain Attack on Security Infrastructure
A massive breach allegedly from BlackLine, a major financial automation platform
BlackLine, a critical financial automation platform serving enterprise organizations, has reportedly suffered a major data breach. Approximately 1.5 million sensitive documents totaling 354.4 gigabytes have been compromised and are currently being marketed on cybercrime forums. The exfiltrated data includes bills, licenses, certificates, and other confidential documents that were processed through the platform for high-profile clients. This breach exposes the vulnerability of financial infrastructure to sophisticated threat actors and highlights the risks associated with centralized document processing systems. Source: ‼️🇺🇸 A massive breach allegedly from BlackLine, a major financial automation platform, is being...
Cisco source code stolen in Trivy-linked dev environment breach
Cisco has disclosed a significant cyberattack on its internal development infrastructure resulting in the theft of proprietary source code belonging to both the company and its customers. Threat actors leveraged credentials stolen during the recent Trivy supply chain compromise to gain unauthorized access to Cisco's development environment. The TeamPCP Cloud Stealer malware was instrumental in facilitating the breach, demonstrating how initial compromises in upstream dependencies can cascade into attacks against major technology vendors. This incident underscores the interconnected nature of modern software supply chains and the critical importance of credential hygiene across development platforms. Source: Cisco source code stolen in Trivy-linked dev environment breach
The convergence of zero-day vulnerabilities in development tools, coordinated supply chain attacks on security infrastructure, and breaches of major financial and technology platforms signals an intensifying threat environment. Organizations must prioritize rapid vulnerability patching, comprehensive supply chain risk assessment, and enhanced monitoring of development environments to mitigate these evolving risks.
Sources & IOCs
Source articles and extracted indicators (defanged where appropriate).
- React2Shell RCE vulnerability exploited by TeamPCP in cloud environments
- CipherForceRansomware group collaborating with TeamPCP for breach data publication
- CanisterWormTeamPCP malware with decentralized C2 and wiper components
- TeamPCPAlso known as PCPcat, ShellForce, DeadCatx3; active since September 2025
- VectRansomware group partnering with TeamPCP
- BlackLine breach dataAlleged breach data from BlackLine financial automation platform being sold on cybercrime forum
- TeamPCP Cloud StealerInfostealer malware used in Trivy and downstream supply chain attacks to steal CI/CD credentials