Weekly review

ThreatNoir Morning Brief — April 6

2026-04-06Morning4 articles
Audio
Listen to the episode

Morning Review in IT Security — April 6, 2026

The cybersecurity landscape continues to evolve with critical vulnerabilities being actively exploited, supply chain threats targeting popular development tools, and malicious software being openly sold on underground forums. Today's review covers urgent patching requirements, automated credential theft campaigns, and compromised infrastructure affecting developers worldwide.

New FortiClient EMS Flaw Exploited in Attacks, Emergency Patch Released

Fortinet has released an emergency weekend security update addressing a critical vulnerability in FortiClient Enterprise Management Server (EMS) that is currently being exploited in active attacks. The vulnerability, tracked as CVE-2026-35616, requires immediate patching to prevent unauthorized access and potential compromise of managed endpoints. Additionally, CVE-2026-21643 has been identified as a related concern requiring attention from affected organizations. Source: New FortiClient EMS flaw exploited in attacks, emergency patch released

Hackers Exploit React2Shell in Automated Credential Theft Campaign

Threat actors are conducting a large-scale automated campaign exploiting the React2Shell vulnerability (CVE-2025-55182) to steal credentials from vulnerable Next.js applications. The campaign leverages the NEXUS Listener malware to harvest credentials at scale, targeting organizations that have not yet patched their Next.js deployments. This supply chain attack demonstrates the critical importance of maintaining current security patches across development frameworks and dependencies. Source: Hackers exploit React2Shell in automated credential theft campaign

ILSpy WordPress Domain Compromised to Deliver Malware

The ILSpy WordPress domain was compromised approximately two hours ago at 01:22 EST to deliver malware to unsuspecting users. The compromised domain (ilspy.wordpress.com) was redirecting download attempts away from the legitimate GitHub repository toward malicious payloads before returning a 502 error. This incident highlights the vulnerability of legitimate development tool distribution channels to compromise and underscores the need for developers to verify download sources and validate integrity checksums. Source: ILSpy WordPress domain compromise

Threat Actor JINKUSU Selling EvilNote Source Code

Threat actor JINKUSU is actively selling the complete source code for EvilNote, a bulk email sending tool, for $500 on underground markets. The EvilNote tool enables users to conduct mass email campaigns using their own SMTP servers with features including recipient list management, email templates, and message personalization. The availability of this malicious tool's source code for sale significantly increases the threat landscape for phishing and spam campaigns targeting organizations globally. Source: Threat actor JINKUSU selling EvilNote source code

Organizations should prioritize patching the critical Fortinet and React2Shell vulnerabilities while maintaining heightened vigilance regarding software download sources and email security controls. The combination of actively exploited vulnerabilities, compromised development infrastructure, and readily available malicious tools creates an elevated threat environment requiring immediate defensive action.

Sources & IOCs

Source articles and extracted indicators (defanged where appropriate).