Weekly review

ThreatNoir Weekend Brief — April 5

2026-04-05Morning5 articles
Audio
Listen to the episode

Morning Review in IT Security — April 5, 2026

Today's security landscape reveals continued threats across open-source software, financial institutions, and government infrastructure, with social engineering and supply-chain attacks remaining favored vectors for threat actors worldwide.

Axios npm Package Compromised Through Social Engineering Campaign

The maintainers of the widely-used Axios HTTP client library have released a detailed post-mortem documenting how one of their developers fell victim to a sophisticated social engineering attack attributed to North Korean threat actors. The campaign leveraged a fake Microsoft Teams error fix to compromise the developer's account and gain access to the npm package repository. Two malware variants, plain-crypto-js and WAVESHAPER.V2, were identified as part of the attack infrastructure. This incident underscores the vulnerability of open-source maintainers to targeted social engineering despite their technical expertise. Source: Axios npm hack used fake Teams error fix to hijack maintainer account

Root-Level Firewall Access Offered for Major US Financial Institution

An initial access broker operating under the handle miyako has allegedly listed root-level firewall access to an unnamed major United States financial services corporation with revenues exceeding $2 billion on a prominent cybercrime forum. The offering represents a significant escalation in potential compromise severity, as firewall-level access provides threat actors with comprehensive visibility and control over network traffic and security infrastructure. The identity of the affected financial institution remains undisclosed. Source: Root-level firewall access to an unnamed major US financial services corporation with $2B+

Paraguay's Civil Registry Database Exposed with 5 Million Records

Paraguay's Civil Status Registry, known as Registro del Estado Civil, has had its database allegedly placed for sale on a cybercrime forum by a threat actor using the alias GordonFreeman. The breach encompasses approximately five million records containing sensitive civil status information. This government-sector compromise represents a significant privacy violation affecting a substantial portion of Paraguay's population and highlights ongoing vulnerabilities in state-level identity management systems. Source: Paraguay's Civil Status Registry (Registro del Estado Civil) allegedly has its database put up for sale on a popular cybercrime forum

BRUSHWORM Malware Spreads via USB Drives in South Asian Financial Attack

Elastic Security Labs has uncovered a targeted attack campaign against a South Asian financial institution utilizing the BRUSHWORM malware, which propagates across USB drives by disguising itself with deceptive filenames such as "Salary Slips.exe," "Dont Delete.exe," and "Important.exe." The attack leverages social engineering tactics combined with insufficient removable media controls to achieve distribution across the target organization's network. The discovery of custom malware components working in tandem demonstrates the sophistication of this supply-chain oriented threat. Source: BRUSHWORM copies itself as when spreading across USB drives in a targeted attack on a South Asian financial institution

Wynn Resorts Notifies Customers of External Systems Breach

Wynn Resorts has begun sending consumer notifications to individuals affected by a breach of external systems attributed to the ShinyHunters threat group. The compromise occurred on October 5, 2025, but was not discovered until February 20, 2026, with notification letters commencing on April 3, 2026. The incident reflects both the extended dwell time threat actors can maintain within compromised environments and the significant lag between breach discovery and customer notification. Source: Wynn Resorts has sent a consumer notification to those affected by the ShinyHunters external systems breach

Security teams should prioritize awareness training for high-value targets like open-source maintainers, implement robust firewall access controls, strengthen removable media policies, and establish rapid breach notification procedures to minimize customer impact and regulatory exposure.

Sources & IOCs

Source articles and extracted indicators (defanged where appropriate).