Weekly review

ThreatNoir Morning Brief — April 15

2026-04-15Morning4 articles
Audio
Listen to the episode

Morning Review in IT Security — April 15, 2026

April 15, 2026 brings critical security developments across multiple fronts, from supply chain compromises affecting trusted software vendors to a historic volume of vulnerability disclosures from Microsoft. Organizations face mounting pressure to patch critical flaws while defending against increasingly sophisticated attacks targeting user credentials and system integrity.

CPU-Z Supply Chain Attack Exposes Legacy Security Blind Spots

Threat actors have successfully compromised the official CPUID domain and repackaged a legitimate signed binary, leveraging Windows trust mechanisms to distribute malware. This attack demonstrates a fundamental weakness in legacy security models that have spent decades cataloging known threats while remaining vulnerable to exploitation of user trust in legitimate software vendors. The compromise of cpuid.com and the distribution of a malicious CPU-Z variant highlight how attackers can bypass traditional security controls by weaponizing the very trust relationships that security infrastructure depends upon. Source: Legacy security has spent decades cataloging evil. The CPU-Z supply chain attack shows exactly wh...

Patch Tuesday, April 2026 Edition: Historic Vulnerability Volume

Microsoft released patches for 167 security vulnerabilities across Windows operating systems and related software during April 2026 Patch Tuesday, making this one of the largest monthly disclosure events on record. The update addresses a SharePoint Server zero-day vulnerability and a publicly disclosed weakness in Windows Defender designated "BlueHammer." Concurrently, Google released its fourth Chrome zero-day patch of 2026, and Adobe issued an emergency update for Reader addressing an actively exploited flaw capable of enabling remote code execution. The affected CVEs include CVE-2026-32201, CVE-2026-33825, CVE-2026-34621, and CVE-2026-5281. Source: Patch Tuesday, April 2026 Edition

Over 100 Chrome Web Store Extensions Steal User Accounts and Data

More than 100 malicious extensions distributed through the official Chrome Web Store are actively attempting to steal Google OAuth2 Bearer tokens, deploy backdoors, and execute ad fraud operations. These extensions employ multiple attack techniques including BITS Jobs execution, application access token theft, and web session cookie harvesting to compromise user accounts and sensitive data. The widespread presence of these malicious extensions in an official app store underscores the persistent challenge of supply chain security in browser ecosystems and the difficulty of maintaining adequate vetting processes at scale. Source: Over 100 Chrome Web Store extensions steal user accounts, data

Microsoft Drops Its Second-Largest Monthly Batch of Defects on Record

Microsoft disclosed an actively exploited zero-day vulnerability in Microsoft Office SharePoint that permits attackers to view sensitive information and make unauthorized modifications to disclosed data. This vulnerability represents one of the most critical flaws in the vendor's April disclosure batch, which constitutes the second-largest monthly vulnerability release in company history. The affected CVEs are CVE-2026-26149, CVE-2026-32201, CVE-2026-33824, and CVE-2026-33825. Source: Microsoft drops its second-largest monthly batch of defects on record

Organizations must prioritize immediate patch deployment across all affected systems while implementing enhanced monitoring for exploitation attempts targeting these newly disclosed vulnerabilities. The convergence of supply chain attacks, record-breaking vulnerability volumes, and malicious app store extensions demonstrates that defenders face an increasingly complex threat landscape requiring coordinated incident response and proactive vulnerability management strategies.

Sources & IOCs

Source articles and extracted indicators (defanged where appropriate).

Microsoft drops its second-largest monthly batch of defects on record
CVE4
  • Actively exploited zero-day in Microsoft Office SharePoint allowing unauthenticated spoofing and information disclosure; CVSS 6.5
  • Critical vulnerability in Microsoft Power Apps; designated less likely to be exploited
  • Critical vulnerability in Windows IKE Extension; designated less likely to be exploited
  • High-severity privilege escalation in Microsoft Defender with public exploit code available; locally exploitable