- Critical RCE vulnerability in Ninja Forms File Upload plugin, actively exploited
ThreatNoir Morning Brief — April 8
Morning Review in IT Security — April 8, 2026
The cybersecurity landscape faces mounting pressure from state-sponsored actors and financially motivated threat groups exploiting critical infrastructure vulnerabilities. Today's threat intelligence reveals coordinated law enforcement action against a Russian military intelligence operation while simultaneously exposing the ongoing risks posed by unpatched systems and supply chain compromises affecting major industries.
Aerospace Defense Contractor Firewall Access Sold on Dark Web
A well-known initial access broker is actively marketing root-level remote code execution access to a firewall belonging to a major US aerospace and defense company with $20 billion in revenue. The asking price of $1,000 represents a severe undervaluation of the critical infrastructure compromise, indicating either desperation to liquidate access or confidence in the vulnerability's persistence. Source: ‼️🇺🇸 A well-known initial access broker is selling root-level remote code execution access to a...
This incident underscores the vulnerability management failures endemic to critical infrastructure sectors. The rapid monetization of firewall access suggests that standard patching protocols have failed to address known or zero-day vulnerabilities within the aerospace and defense supply chain.
Federal Authorities Dismantle Russian GRU Espionage Network
The Department of Justice and FBI have announced a court-authorized technical operation to neutralize the US portion of a network of compromised small office and home office routers controlled by Russia's Main Intelligence Directorate of the General Staff, known as GRU Military Unit 26165 and operating under multiple aliases including APT28, Sofacy Group, Forest Blizzard, Pawn Storm, and Fancy Bear. Source: Justice Department Conducts Court-Authorized Disruption of DNS Hijacking Network Controlled by a Russian Military Intelligence Unit
The Forest Blizzard threat group hijacked network traffic to steal credentials and tokens for Microsoft accounts and other services across an estimated 18,000 compromised devices. Source: Feds quash widespread Russia-backed espionage network spanning 18,000 devices
This operation represents one of the most significant state-sponsored espionage campaigns targeting consumer-grade networking equipment. The scale of the compromise, affecting tens of thousands of devices globally, demonstrates the strategic value of SOHO router infrastructure for intelligence collection operations.
Critical Vulnerability Discovered in Ninja Forms WordPress Plugin
A critical vulnerability in the Ninja Forms File Uploads premium add-on for WordPress allows uploading arbitrary files without authentication, creating a direct pathway to remote code execution. The vulnerability, tracked as CVE-2026-0740, affects WordPress installations utilizing this popular form-building plugin. Source: Hackers exploit critical flaw in Ninja Forms WordPress plugin
Active exploitation of this vulnerability has already been reported in the wild. Organizations relying on Ninja Forms for customer-facing forms or data collection face immediate risk of compromise if the plugin remains unpatched. The unauthenticated nature of the vulnerability eliminates the requirement for valid credentials, making exploitation accessible to any threat actor with network access.
Conclusion
Today's threat intelligence demonstrates the convergence of nation-state operations, supply chain vulnerabilities, and plugin-level exploits creating a complex threat environment. Organizations must prioritize vulnerability management across all layers of their infrastructure, from critical firewall systems to WordPress plugins, while remaining vigilant against state-sponsored actors targeting unpatched network devices.
Sources & IOCs
Source articles and extracted indicators (defanged where appropriate).
- DNS Hijacking / Router CompromiseExploitation of TP-Link router vulnerabilities to redirect DNS requests to GRU-controlled servers and conduct MITM attacks