Weekly review

ThreatNoir Afternoon Brief — April 10

2026-04-10Afternoon4 articles
Audio
Listen to the episode

Afternoon Review in IT Security — April 10, 2026

The threat landscape continues to accelerate as critical vulnerabilities are weaponized within hours of disclosure, while supply chain attacks target widely deployed software infrastructure. Today's security briefing covers rapid exploitation of open-source flaws, compromised plugin distribution networks, targeted payroll theft campaigns, and multiple vulnerabilities in medical imaging systems.

Critical Marimo Flaw Exploited Hours After Public Disclosure

An unauthenticated vulnerability in Marimo has been actively exploited in the wild within nine hours of its public disclosure. Threat actors rapidly developed functional exploits from the vulnerability advisory and began deploying them against exposed systems. Source: Critical Marimo Flaw Exploited Hours After Public Disclosure

This incident demonstrates the compressed timeline between vulnerability announcement and active weaponization. The affected vulnerability, tracked as CVE-2026-39987, highlights the critical importance of rapid patching protocols for organizations running exposed Marimo instances. The speed of exploitation underscores how public disclosures can immediately enable threat actors to develop and deploy working exploits.

Backdoored Smart Slider 3 Pro Update Distributed via Compromised Nextend Servers

Unknown threat actors have compromised the update infrastructure for Smart Slider 3 Pro, a WordPress and Joomla slider plugin with over 800,000 active installations, to distribute a backdoored version. The poisoned update affects Smart Slider 3 Pro version 3.5.1.35 for WordPress and was distributed through hijacked Nextend servers. Source: Backdoored Smart Slider 3 Pro Update Distributed via Compromised Nextend Servers

This supply chain attack represents a significant threat to the WordPress ecosystem, as the compromised plugin update mechanism could have infected hundreds of thousands of websites. The attack infrastructure includes the domain wpjs1.com, which was used to deliver the malicious payload. Organizations running Smart Slider 3 Pro should immediately verify their plugin version and integrity, and consider rolling back to trusted versions until the official patch is released.

Microsoft: Canadian Employees Targeted in Payroll Pirate Attacks

A financially motivated threat actor tracked as Storm-2755 is conducting payroll theft attacks specifically targeting Canadian employees by compromising their accounts and redirecting salary payments. The attacker uses phishing techniques to gain initial access to employee accounts and subsequently hijack payroll transactions. Source: Microsoft: Canadian Employees Targeted in Payroll Pirate Attacks

The attack infrastructure includes the domain bluegraintours.com, which is utilized in the phishing campaign. This targeted campaign demonstrates the shift toward financially motivated attacks that directly impact employee compensation, making payroll systems and employee account security critical priorities for Canadian organizations.

Orthanc DICOM Vulnerabilities Lead to Crashes, RCE

Multiple vulnerabilities have been identified in Orthanc, an open-source DICOM server, that could enable denial-of-service attacks, information disclosure, and arbitrary code execution. The vulnerabilities span nine distinct CVEs, including CVE-2026-5437 through CVE-2026-5445. Source: Orthanc DICOM Vulnerabilities Lead to Crashes, RCE

These vulnerabilities in medical imaging infrastructure present a significant risk to healthcare organizations relying on Orthanc for DICOM server functionality. The range of impacts—from denial-of-service to remote code execution—means that healthcare providers should prioritize patching these systems to prevent potential disruption to clinical imaging services and unauthorized access to sensitive patient data.

Today's threat activity reflects an increasingly aggressive threat landscape where vulnerabilities are exploited within hours, supply chain mechanisms are weaponized at scale, and financially motivated attackers target critical business processes. Organizations must maintain vigilant patch management practices and implement robust account security measures to defend against these evolving threats.

Sources & IOCs

Source articles and extracted indicators (defanged where appropriate).

Backdoored Smart Slider 3 Pro Update Distributed via Compromised Nextend Servers
Malware1
  • Smart Slider 3 Pro v3.5.1.35 (backdoored)
    Trojaned plugin version distributed via compromised update servers; contains multi-layered remote access toolkit with credential theft and persistence capabilities.
Domain1
  • wpjs1.com
    Command-and-control (C2) domain used by Smart Slider 3 Pro backdoor to exfiltrate site credentials, configuration, and persistence method details.
Orthanc DICOM Vulnerabilities Lead to Crashes, RCE
CVE9