Weekly review

ThreatNoir Afternoon Brief — April 14

2026-04-14Afternoon4 articles
Audio
Listen to the episode

Afternoon Review in IT Security — April 14, 2026

The IT security landscape continues to face mounting pressure as critical vulnerabilities across enterprise and consumer platforms remain under active exploitation. Today's briefing covers significant threats spanning supply-chain risks, ransomware infrastructure, malicious browser extensions, and unpatched remote code execution flaws affecting organizations globally.

SAP Patches Critical ABAP Vulnerability

SAP has released 19 new security notes addressing vulnerabilities across more than a dozen enterprise products. The patches address critical flaws in the ABAP platform, with tracked identifiers including CVE-2026-27681 and CVE-2026-34256. These vulnerabilities represent significant risks to organizations relying on SAP infrastructure for core business operations. Source: SAP Patches Critical ABAP Vulnerability

Ransomware-Linked ViperTunnel Malware Hits UK and US Businesses

A Python-based backdoor known as ViperTunnel has been identified targeting businesses across the United States and United Kingdom, with direct links to the DragonForce ransomware operation. The malware leverages Windows servers as primary attack vectors and operates within a broader ecosystem that includes FAKEUPDATES (SocGholish), ShadowCoil, and RansomHub variants. Organizations running unpatched Windows infrastructure face heightened exposure to this threat chain. Source: Ransomware-Linked ViperTunnel Malware Hits UK and US Businesses

108 Malicious Chrome Extensions Steal Google and Telegram Data, Affecting 20,000 Users

A coordinated campaign has deployed 108 malicious Google Chrome extensions communicating with unified command-and-control infrastructure to harvest user credentials and sensitive data. The extensions, including variants such as Telegram Multi-account, Web Client for Telegram - Teleside, and Formula Rush Racing Game, have affected approximately 20,000 users by injecting advertisements and arbitrary JavaScript code into browsing sessions. Infrastructure analysis has identified the C2 server at IP address 144.126.135.238. Source: 108 Malicious Chrome Extensions Steal Google and Telegram Data, Affecting 20,000 Users

ShowDoc RCE Flaw CVE-2025-0520 Actively Exploited on Unpatched Servers

A critical remote code execution vulnerability in ShowDoc, a document management platform widely deployed in China, is experiencing active exploitation in the wild. CVE-2025-0520, also tracked as CNVD-2020-26585, carries a CVSS severity score of 9.4 and stems from improper validation of file uploads. Organizations operating unpatched ShowDoc instances remain vulnerable to immediate compromise through this unrestricted upload mechanism. Source: ShowDoc RCE Flaw CVE-2025-0520 Actively Exploited on Unpatched Servers

Security teams are advised to prioritize patching of identified vulnerabilities, implement application whitelisting to restrict malicious extensions, and conduct immediate assessments of Windows and ShowDoc deployments for indicators of compromise. The convergence of active exploitation campaigns across multiple attack vectors underscores the critical importance of timely security updates and robust endpoint monitoring.

Sources & IOCs

Source articles and extracted indicators (defanged where appropriate).

Ransomware-Linked ViperTunnel Malware Hits UK and US Businesses
Malware5
  • DragonForce
    Ransomware group deploying ViperTunnel for encryption attacks
  • ViperTunnel
    Python-based backdoor linked to DragonForce ransomware
  • FAKEUPDATES (SocGholish)
    Initial infection vector leading to ViperTunnel deployment
  • ShadowCoil
    Credential-stealing tool used alongside ViperTunnel by UNC2165
  • RansomHub
    Ransomware group purchasing network access from ViperTunnel operators
108 Malicious Chrome Extensions Steal Google and Telegram Data, Affecting 20,000 Users
Malware3
  • Web Client for Telegram - Teleside
    Extension ID mdcfennpfgkngnibjbpnpaafcjnhcjno; strips security headers and steals Telegram sessions
  • Formula Rush Racing Game
    Extension ID akebbllmckjphjiojeioooidhnddnplj; steals Google account identity via OAuth2
  • Telegram Multi-account
    Extension ID obifanppcpchlehkjipahhphbcbjekfa; steals Telegram Web user_auth tokens
IP Address1
  • 144.126.135.238
    C2 server hosting backend for all 108 malicious extensions