Weekly review

ThreatNoir Afternoon Brief — April 15

2026-04-15Afternoon4 articles
Audio
Listen to the episode

Afternoon Review in IT Security — April 15, 2026

The threat landscape continues to evolve with critical vulnerabilities emerging across major platforms and active campaigns targeting enterprise infrastructure. Today's briefing covers supply chain risks, critical patches from major vendors, and ongoing malware campaigns affecting payment and logistics operations.

$10 Domain Could Have Handed Hackers 25k Endpoints, Including in OT and Gov Networks

Researchers have identified a critical supply chain vulnerability involving adware capable of disabling cybersecurity products and delivering more dangerous payloads to infected systems. The threat leveraged an inexpensive domain registration to potentially compromise approximately 25,000 endpoints across operational technology and government networks. The malware, identified as Dragon Boss Solutions adware, demonstrates how minimal investment in domain infrastructure can create widespread risk across critical sectors. The affected domain chromsterabrowser[.]com was used as part of a software update mechanism, highlighting the dangers of inadequate validation in update processes. Source: SecurityWeek

Fortinet Patches Critical FortiSandbox Vulnerabilities

Fortinet has released patches addressing critical vulnerabilities in FortiSandbox that could permit attackers to bypass authentication or execute arbitrary code through HTTP requests. Three critical CVEs have been identified: CVE-2026-39813, CVE-2026-39808, and CVE-2026-22828. These flaws represent a significant risk to organizations relying on FortiSandbox for threat analysis and malware detection. Immediate patching is recommended for all affected deployments. Source: SecurityWeek

Microsoft Issues Patches for SharePoint Zero-Day and 168 Other New Vulnerabilities

Microsoft released an unprecedented 169 security updates addressing vulnerabilities across its product portfolio, including a SharePoint zero-day actively exploited in the wild. Of these flaws, eight are rated Critical, 157 are rated Important, three are rated Moderate, and one is rated Low. The affected CVEs include CVE-2026-32201, CVE-2026-33824, CVE-2026-33825, CVE-2023-20585, CVE-2026-21637, CVE-2026-25250, and CVE-2026-32631. This record-breaking patch release underscores the volume of vulnerabilities requiring immediate attention across Microsoft's ecosystem. Source: The Hacker News

Active HanGhost Loader Campaign Targets Enterprise Payment and Logistics Workflows

A sustained campaign leveraging the HanGhost Loader is actively targeting enterprise payment and logistics operations through fileless attacks and multi-stage malware delivery. The campaign employs a sophisticated toolkit including PureHVNC, XWorm, Meduza, AgentTesla, Phantom, and UltraVNC to establish persistence and exfiltrate sensitive data. The stealthy nature of the attack chain and focus on critical business workflows make this campaign particularly dangerous for organizations handling financial transactions and supply chain operations. Source: Hackread

Organizations should prioritize patching critical vulnerabilities, validating software update mechanisms, and implementing enhanced monitoring for fileless malware techniques. The convergence of supply chain risks, critical patches, and active campaigns demands immediate attention to patch management and endpoint protection strategies.

Sources & IOCs

Source articles and extracted indicators (defanged where appropriate).

$10 Domain Could Have Handed Hackers 25k Endpoints, Including in OT and Gov Networks
Malware1
  • Dragon Boss Solutions adware/malware
    Signed software from UAE-based firm; evolved into PowerShell-based payload disabling security products and enabling secondary payload delivery.
Domain1
  • chromsterabrowser[.]com
    Unregistered malware C2/update domain used to deliver payloads to 25k infected endpoints; registered by Huntress as sinkhole.
Fortinet Patches Critical FortiSandbox Vulnerabilities
CVE3
  • Critical authentication bypass in FortiSandbox JRPC API, CVSS 9.1, exploitable via HTTP requests without authentication
  • High-severity buffer overflow in FortiAnalyzer Cloud, allows RCE without authentication but requires ASLR bypass and network access
  • Critical OS command injection in FortiSandbox, CVSS 9.1, enables arbitrary code/command execution via HTTP requests without authentication
Microsoft Issues Patches for SharePoint Zero-Day and 168 Other New Vulnerabilities
CVE7
  • Microsoft Defender privilege escalation; CVSS 7.8; publicly known at release
  • Git for Windows vulnerability addressed in patch
  • Windows IKE Service Extensions remote code execution; CVSS 9.8; unauthenticated RCE
  • Windows Secure Boot vulnerability addressed in patch
  • SharePoint Server spoofing zero-day actively exploited in the wild; CVSS 6.5
  • Node.js vulnerability addressed in patch
  • AMD vulnerability addressed in patch
Active HanGhost Loader Campaign Targets Enterprise Payment and Logistics Workflows
Malware7
  • XWorm
    Remote access and credential stealing malware deployed in campaign
  • HanGhost
    Multi-stage fileless loader used as primary attack vector
  • PureHVNC
    Remote access malware delivered via HanGhost
  • Meduza
    Malware family delivered through HanGhost loader
  • AgentTesla
    Credential stealer deployed via HanGhost campaign
  • Phantom
    Malware payload delivered in HanGhost attacks
  • UltraVNC
    Deployed for persistent remote access in some HanGhost cases