- GPUHammerPredecessor attack demonstrating GPU rowhammer data corruption
- GPUBreachNew rowhammer-based GPU privilege escalation attack
ThreatNoir Morning Brief — April 7
Morning Review in IT Security — April 7, 2026
The IT security landscape continues to face escalating threats across multiple fronts this morning, with hardware vulnerabilities, actively exploited zero-days, and geopolitically motivated campaigns demanding immediate attention from defenders worldwide.
New GPUBreach Attack Enables System Takeover via GPU Rowhammer
A newly discovered attack mechanism called GPUBreach can induce Rowhammer bit-flips on GPU GDDR6 memories to achieve privilege escalation and complete system compromise. This vulnerability represents a critical threat to systems relying on GPU acceleration, particularly in cloud and artificial intelligence infrastructure environments. The attack leverages hardware-level weaknesses that traditional software-based defenses may struggle to mitigate. Source: New GPUBreach attack enables system takeover via GPU rowhammer
Fortinet Customers Confront Actively Exploited Zero-Day with Patch Pending
Two critical defects in FortiClient EMS are currently being exploited in active attacks, with a complete patch still under development. Security experts are urging users to immediately apply available hotfixes to mitigate exposure while waiting for comprehensive remediation. The CVE identifiers CVE-2026-21643 and CVE-2026-35616 have been assigned to these vulnerabilities, and the ongoing exploitation underscores the urgency of rapid patching cycles. Source: Fortinet customers confront actively exploited zero-day, with a full patch still pending
Disgruntled Researcher Leaks BlueHammer Windows Zero-Day Exploit
Exploit code for an unpatched Windows privilege escalation vulnerability has been publicly released by a disgruntled researcher who previously reported the flaw privately to Microsoft. The BlueHammer exploit enables attackers to gain SYSTEM or elevated administrator permissions on vulnerable Windows systems, creating an immediate risk window until Microsoft releases an official patch. The public disclosure significantly accelerates the threat timeline for organizations running affected Windows versions. Source: Disgruntled researcher leaks "BlueHammer" Windows zero-day exploit
Iran-Linked Password-Spraying Campaign Targets 300+ Israeli Microsoft 365 Organizations
An Iran-nexus threat actor is conducting a sustained password-spraying campaign against over 300 Microsoft 365 environments in Israel and the United Arab Emirates, with activity assessed as ongoing. The campaign has occurred in three distinct waves on March 3, March 13, and March 23, 2026, according to analysis from Check Point. The targeting of cloud-based productivity environments suggests attackers are seeking initial access for potential ransomware deployment or data exfiltration operations. Source: Iran-Linked Password-Spraying Campaign Targets 300+ Israeli Microsoft 365 Organizations
As these threats demonstrate, organizations must prioritize rapid vulnerability assessment, implement multi-factor authentication controls, and maintain heightened monitoring for both hardware-level attacks and credential-based intrusions in the coming days.
Sources & IOCs
Source articles and extracted indicators (defanged where appropriate).
- Related FortiClient EMS vulnerability disclosed Feb 6, also actively exploited
- Active zero-day in FortiClient EMS, CVSS 9.8, unauthenticated RCE
- BlueHammerWindows local privilege escalation zero-day exploit
- BPFDoorStealthy implant used by China-linked Red Menshen for telecom network espionage
- Pay2KeyIranian ransomware-as-a-service gang with government ties; resurfaced Feb 2026 with improved evasion and anti-forensics techniques
- BQTlock (Baqiyat 313 Locker)Pro-Palestinian ransomware actively targeting U.A.E., U.S., and Israel since July 2025; promoted by Sicarii admin for pro-Iranian operators