- Cisco Secure Firewall Management Center maximum-severity RCE exploited by Interlock ransomware
- Cisco Smart Software Manager On-Prem unauthenticated remote code execution vulnerability
- Cisco IMC authentication bypass allowing unauthenticated Admin access via crafted HTTP requests
ThreatNoir Afternoon Brief — April 2
Afternoon Review in IT Security — April 2, 2026
The IT security landscape continues to face significant threats as critical vulnerabilities emerge across major infrastructure platforms and sophisticated supply chain attacks target AI companies. Today's briefing highlights urgent patching requirements, data breaches affecting recruiting technology, sophisticated state-sponsored malware, and widespread exposure of network appliances to active exploitation.
Critical Cisco IMC Authentication Bypass Gives Attackers Admin Access
Cisco has released patches for multiple critical and high-severity vulnerabilities affecting its Integrated Management Controller (IMC) infrastructure. Among these is a critical authentication bypass vulnerability that allows attackers to gain administrative access to affected systems. The vulnerability, tracked as CVE-2026-20093, represents a significant risk to organizations relying on Cisco IMC for infrastructure management. Two additional vulnerabilities, CVE-2026-20160 and CVE-2026-20131, were also patched in the same advisory. Source: Critical Cisco IMC auth bypass gives attackers Admin access
Mercor Hit by LiteLLM Supply Chain Attack
The AI recruiting firm Mercor is investigating a significant security incident involving a compromised PyPI package. The threat actor group Lapsus$ has claimed responsibility for stealing approximately 4TB of Mercor data through a supply chain attack targeting the LiteLLM library. The attack involved malicious versions of the LiteLLM PyPI package, specifically versions 1.82.7 and 1.82.8, which were distributed to downstream users. This incident demonstrates the continued risk posed by compromised dependencies in the software supply chain. Source: Mercor Hit by LiteLLM Supply Chain Attack
Possible US Government iPhone Hacking Tool Leaked
Security researchers at Google have documented a highly sophisticated iPhone hacking toolkit called Coruna that appears to have been leaked from a government source. The toolkit includes five complete hacking techniques capable of bypassing all iOS defenses to silently install malware on devices when users visit compromised websites. Coruna exploits 23 distinct vulnerabilities in iOS, an unusually large collection suggesting development by a well-resourced, state-sponsored group. The leak represents a significant breach of operational security and raises concerns about insider threats within government agencies. Source: Possible US Government iPhone Hacking Tool Leaked - Schneier on Security
Over 14,000 F5 BIG-IP APM Instances Still Exposed to RCE Attacks
Internet security watchdog Shadowserver has identified more than 14,000 F5 BIG-IP Access Policy Manager instances exposed online and vulnerable to active remote code execution attacks. These systems remain vulnerable to CVE-2025-53521, a critical-severity vulnerability that continues to be exploited by threat actors. The widespread exposure of these network appliances represents a significant risk to organizations that have not yet applied available patches. Source: Over 14,000 F5 BIG-IP APM instances still exposed to RCE attacks
Today's threat landscape underscores the critical importance of rapid patch deployment, supply chain security vigilance, and comprehensive vulnerability management. Organizations should prioritize patching the Cisco IMC authentication bypass and F5 BIG-IP RCE vulnerability while reviewing their PyPI dependencies for compromised packages.
Sources & IOCs
Source articles and extracted indicators (defanged where appropriate).
- LiteLLM PyPI package v1.82.7Malicious package published by TeamPCP via compromised maintainer credentials
- LiteLLM PyPI package v1.82.8Malicious package published by TeamPCP via compromised maintainer credentials
- CorunaSophisticated iPhone hacking toolkit exploiting 23 iOS vulnerabilities, allegedly developed by L3Harris for US government
- Critical RCE vulnerability in F5 BIG-IP APM, originally disclosed as DoS in October 2025, reclassified to RCE in March 2026 after active exploitation discovered