Weekly review

ThreatNoir Afternoon Brief — April 2

2026-04-02Afternoon4 articles
Audio
Listen to the episode

Afternoon Review in IT Security — April 2, 2026

The IT security landscape continues to face significant threats as critical vulnerabilities emerge across major infrastructure platforms and sophisticated supply chain attacks target AI companies. Today's briefing highlights urgent patching requirements, data breaches affecting recruiting technology, sophisticated state-sponsored malware, and widespread exposure of network appliances to active exploitation.

Critical Cisco IMC Authentication Bypass Gives Attackers Admin Access

Cisco has released patches for multiple critical and high-severity vulnerabilities affecting its Integrated Management Controller (IMC) infrastructure. Among these is a critical authentication bypass vulnerability that allows attackers to gain administrative access to affected systems. The vulnerability, tracked as CVE-2026-20093, represents a significant risk to organizations relying on Cisco IMC for infrastructure management. Two additional vulnerabilities, CVE-2026-20160 and CVE-2026-20131, were also patched in the same advisory. Source: Critical Cisco IMC auth bypass gives attackers Admin access

Mercor Hit by LiteLLM Supply Chain Attack

The AI recruiting firm Mercor is investigating a significant security incident involving a compromised PyPI package. The threat actor group Lapsus$ has claimed responsibility for stealing approximately 4TB of Mercor data through a supply chain attack targeting the LiteLLM library. The attack involved malicious versions of the LiteLLM PyPI package, specifically versions 1.82.7 and 1.82.8, which were distributed to downstream users. This incident demonstrates the continued risk posed by compromised dependencies in the software supply chain. Source: Mercor Hit by LiteLLM Supply Chain Attack

Possible US Government iPhone Hacking Tool Leaked

Security researchers at Google have documented a highly sophisticated iPhone hacking toolkit called Coruna that appears to have been leaked from a government source. The toolkit includes five complete hacking techniques capable of bypassing all iOS defenses to silently install malware on devices when users visit compromised websites. Coruna exploits 23 distinct vulnerabilities in iOS, an unusually large collection suggesting development by a well-resourced, state-sponsored group. The leak represents a significant breach of operational security and raises concerns about insider threats within government agencies. Source: Possible US Government iPhone Hacking Tool Leaked - Schneier on Security

Over 14,000 F5 BIG-IP APM Instances Still Exposed to RCE Attacks

Internet security watchdog Shadowserver has identified more than 14,000 F5 BIG-IP Access Policy Manager instances exposed online and vulnerable to active remote code execution attacks. These systems remain vulnerable to CVE-2025-53521, a critical-severity vulnerability that continues to be exploited by threat actors. The widespread exposure of these network appliances represents a significant risk to organizations that have not yet applied available patches. Source: Over 14,000 F5 BIG-IP APM instances still exposed to RCE attacks

Today's threat landscape underscores the critical importance of rapid patch deployment, supply chain security vigilance, and comprehensive vulnerability management. Organizations should prioritize patching the Cisco IMC authentication bypass and F5 BIG-IP RCE vulnerability while reviewing their PyPI dependencies for compromised packages.

Sources & IOCs

Source articles and extracted indicators (defanged where appropriate).

Mercor Hit by LiteLLM Supply Chain Attack
Malware2
  • LiteLLM PyPI package v1.82.7
    Malicious package published by TeamPCP via compromised maintainer credentials
  • LiteLLM PyPI package v1.82.8
    Malicious package published by TeamPCP via compromised maintainer credentials