Weekly review

ThreatNoir Morning Brief — April 9

2026-04-09Morning4 articles
Audio
Listen to the episode

Morning Review in IT Security — April 9, 2026

The threat landscape on April 9, 2026 reflects a troubling convergence of supply chain vulnerabilities, sophisticated credential theft operations, and critical infrastructure patching pressures. From e-commerce platforms to semiconductor manufacturers, attackers continue to exploit weak links in interconnected business ecosystems while government agencies race to remediate zero-day exposures.

Hackers Use Pixel-Large SVG Trick to Hide Credit Card Stealer

A widespread campaign targeting approximately 100 online stores running the Magento e-commerce platform has employed an innovative obfuscation technique to deploy credit card-stealing malware. Threat actors have hidden malicious code within pixel-sized Scalable Vector Graphics (SVG) images, making detection significantly more difficult for security teams relying on traditional signature-based analysis. The attack leverages the Magento platform's prevalence in retail environments to gain access to payment card data at scale. Source: Hackers use pixel-large SVG trick to hide credit card stealer

Google: New UNC6783 Hackers Steal Corporate Zendesk Support Tickets

Google has identified a previously undocumented threat actor designated UNC6783 that is systematically compromising business process outsourcing (BPO) providers to gain unauthorized access to high-value corporate targets across multiple industry sectors. This supply chain attack vector leverages the trusted relationship between companies and their outsourced service providers, allowing attackers to access sensitive support tickets and internal communications without directly targeting the intended victims. The campaign demonstrates the expanding sophistication of threat actors in identifying and exploiting third-party access points. Source: Google: New UNC6783 hackers steal corporate Zendesk support tickets

CISA Orders Feds to Patch Exploited Ivanti EPMM Flaw by Sunday

The Cybersecurity and Infrastructure Security Agency (CISA) has issued an emergency directive requiring all U.S. federal government agencies to patch critical vulnerabilities in Ivanti Endpoint Manager Mobile (EPMM) within four days. The affected vulnerabilities, tracked as CVE-2026-1281 and CVE-2026-1340, have been actively exploited in the wild since January 2026, making this one of the most urgent remediation orders issued in recent months. The compressed timeline reflects the severity of the threat and the widespread deployment of Ivanti solutions across federal infrastructure. Source: CISA orders feds to patch exploited Ivanti EPMM flaw by Sunday

Alleged Breach of Shanghai Fudan Microelectronics Leaks 175MB of IC Schematics and Intellectual Property

Shanghai Fudan Microelectronics has reportedly suffered a significant data breach resulting in the exposure of 175 megabytes of sensitive material, including integrated circuit schematics, internal documents, and proprietary intellectual property. The breach represents a serious compromise of critical semiconductor design information that could have implications for global supply chain security and national technology competitiveness. The incident underscores the vulnerability of semiconductor manufacturers to sophisticated threat actors seeking to obtain advanced chip designs and manufacturing processes. Source: Alleged Breach of Shanghai Fudan Microelectronics Leaks 175MB of IC Schematics, Internal Documents, and Intellectual Property

Today's threat environment demonstrates that attackers continue to evolve their tactics across multiple vectors—from obfuscated malware in e-commerce platforms to supply chain compromises targeting outsourced service providers and nation-state-level intellectual property theft. Organizations must prioritize both immediate patching of critical vulnerabilities and strategic assessment of their third-party risk posture.

Sources & IOCs

Source articles and extracted indicators (defanged where appropriate).

Hackers use pixel-large SVG trick to hide credit card stealer
Malware2
  • SVG-based credit card stealer
    Inline malware encoded in 1x1-pixel SVG onload handler; uses base64 encoding, XOR encryption, and Luhn verification for card validation
  • PolyShell
    Vulnerability (unauthenticated RCE) disclosed mid-March 2026; allows attackers to inject payment skimmers into Magento installations
IP Address1
  • 23.137.249.67
    C2 server IP address for payment data exfiltration; hosted by IncogNet LLC (AS40663) in Netherlands