Weekly review

ThreatNoir Morning Brief — April 13

2026-04-13Morning4 articles
Audio
Listen to the episode

Morning Review in IT Security — April 13, 2026

The cybersecurity landscape continues to evolve with alarming speed as artificial intelligence tools become weapons in the hands of sophisticated threat actors. Today's briefing covers critical incidents spanning AI-powered nation-state attacks, zero-day vulnerabilities in emerging platforms, and mobile exploit chains circulating in underground markets.

AI-Powered Attack Compromises Nine Mexican Government Agencies

A single threat actor leveraged ChatGPT and Claude to orchestrate one of the most technically advanced campaigns against Mexican government infrastructure. The campaign ran from late December 2025 through mid-February 2026, targeting nine separate government agencies and resulting in the exfiltration of hundreds of millions of citizen records. The attacker utilized Claude Code and GPT-4.1 to automate and enhance the attack methodology, demonstrating how modern AI tools can amplify the capabilities of individual operators. Source: Hacker Used Claude Code, GPT-4.1 to Exfiltrate Hundreds of Millions of Mexican Records

Critical Path Traversal Vulnerability in Langflow

A critical vulnerability designated CVE-2026-5027 has been identified in Langflow's file handling mechanism. The flaw exists in the POST /api/v2/files endpoint and allows path traversal combined with arbitrary file write capabilities. With a CVSS score of 8.8, this vulnerability poses severe risk to systems running affected versions of Langflow. The vulnerability enables unauthenticated attackers to compromise systems through a single malicious request. Source: CVE-2026-5027: Critical Path Traversal / Arbitrary File Write vulnerability in Langflow

iOS Zero-Day Exploit Chain Sold on Underground Markets

A full-chain one-click exploit targeting iOS versions 18 through 18.7 is being actively marketed on popular cybercrime forums. The exploit, attributed to threat actor rosestealer and labeled "EL Muncho," is bundled with a data stealer malware variant called GHOSTBLADE. The combination of a complete exploit chain with integrated malware functionality represents a significant threat to iOS users, as the single-click nature of the attack dramatically lowers the technical barrier for attackers. Source: A full-chain one-click exploit for iOS 18 through 18.7, bundled with a bonus stealer called "GHOSTBLADE"

The convergence of AI-assisted attacks, unpatched critical vulnerabilities, and sophisticated mobile exploits underscores the urgent need for organizations to enhance their detection capabilities, apply security updates immediately, and implement AI-aware threat modeling in their defensive strategies.

Sources & IOCs

Source articles and extracted indicators (defanged where appropriate).