- Improper certificate validation in Webex Services SSO integration; CVSS 9.8; unauthenticated user impersonation
- Insufficient input validation in ISE; CVSS 9.9; arbitrary command execution with read-only admin credentials
- Insufficient input validation in ISE; CVSS 9.9; arbitrary command execution with read-only admin credentials
- Insufficient input validation in ISE and ISE-PIC; CVSS 9.9; remote code execution with admin credentials
ThreatNoir Afternoon Brief — April 16
Afternoon Review in IT Security — April 16, 2026
The threat landscape continues to evolve rapidly as critical vulnerabilities surface across enterprise platforms, supply chain attacks leverage trusted applications, and data breaches expose millions of user records. Today's security briefing covers significant developments affecting identity services, financial sector targeting, educational institutions, and banking infrastructure.
Cisco Patches Four Critical Identity Services and Webex Flaws Enabling Code Execution
Cisco has released patches addressing four critical security vulnerabilities affecting Identity Services Engine (ISE) and Webex Services that could enable arbitrary code execution and user impersonation across the platform. The vulnerabilities carry severe risk ratings, with CVE-2026-20184 assigned a CVSS score of 9.8, stemming from improper certificate validation in single sign-on (SSO) integration. The affected CVEs include CVE-2026-20147, CVE-2026-20180, and CVE-2026-20186, collectively representing a significant threat to organizations relying on these services for identity management and unified communications.
Organizations using Cisco Identity Services and Webex should prioritize deploying these patches immediately to prevent potential exploitation. The ability for attackers to execute arbitrary code or impersonate users within these critical services poses substantial risk to enterprise security posture. Source: Cisco Patches Four Critical Identity Services, Webex Flaws Enabling Code Execution
Obsidian Plugin Abuse Delivers PHANTOMPULSE RAT in Targeted Finance and Crypto Attacks
Security researchers have identified a novel social engineering campaign exploiting the Obsidian note-taking application to distribute PHANTOMPULSE, a previously undocumented remote access trojan targeting the financial and cryptocurrency sectors. Elastic Security Labs has designated this activity as REF6598 and determined that attackers leverage malicious plugins within Obsidian's ecosystem to gain initial access and establish persistent command and control capabilities. The campaign demonstrates how threat actors continue to abuse trusted productivity tools and their plugin ecosystems as vectors for sophisticated malware distribution.
The targeting of financial and cryptocurrency professionals suggests this operation focuses on high-value objectives where compromised systems could facilitate fraud, theft, or espionage. The use of a legitimate application as a delivery mechanism underscores the importance of monitoring plugin sources and maintaining strict application control policies. Source: Obsidian Plugin Abuse Delivers PHANTOMPULSE RAT in Targeted Finance, Crypto Attacks
Data Breach at EdTech Giant McGraw Hill Affects 13.5 Million Accounts
The ShinyHunters extortion group has leaked data from 13.5 million McGraw Hill user accounts following a breach of the company's Salesforce environment earlier this month. The incident represents a significant exposure of educational records and personal information stored within the compromised Salesforce instance. McGraw Hill's failure to adequately secure its Salesforce deployment allowed threat actors to extract and subsequently threaten to publicly release the sensitive data.
This breach underscores the critical importance of properly configuring and securing cloud-based customer relationship management platforms, particularly when they contain personally identifiable information and educational records. Organizations must implement robust access controls, monitor for suspicious activity, and conduct regular security assessments of their Salesforce environments. Source: Data breach at edtech giant McGraw Hill affects 13.5 million accounts
Hidden Passenger: How Taboola Routes Logged-In Banking Sessions to Temu
Security researchers have discovered that a Taboola advertising pixel approved by a financial institution silently redirected authenticated banking sessions to Temu tracking endpoints without the bank's knowledge, user consent, or detection by security controls. The hidden redirect funneled logged-in users from banking environments to Temu's data collection infrastructure through endpoints including sync.taboola.com and www.temu.com, demonstrating a critical gap in third-party tracking oversight. This "first-hop bias" vulnerability reveals how malicious or compromised tracking pixels can operate undetected within banking environments despite existing security measures.
The incident exposes a fundamental blind spot in how organizations vet and monitor third-party advertising and analytics code deployed on customer-facing platforms. Banks and financial institutions must implement enhanced controls over pixel approvals, establish real-time monitoring of redirect chains, and maintain strict policies governing which third parties can access authenticated user sessions. Source: Hidden Passenger? How Taboola Routes Logged-In Banking Sessions to Temu
Today's threat landscape demonstrates that security challenges span from critical infrastructure vulnerabilities requiring immediate patching to sophisticated supply chain attacks and third-party risks embedded within trusted platforms. Organizations must prioritize vulnerability management, enhance third-party oversight, and implement comprehensive monitoring to detect unauthorized data flows and malicious activity.
Sources & IOCs
Source articles and extracted indicators (defanged where appropriate).
- PHANTOMPULSEAI-generated Windows RAT using Ethereum blockchain for C2 resolution
- PHANTOMPULLIntermediate loader that decrypts and launches PHANTOMPULSE in memory
- Salesforce misconfiguration exploitationAttack vector used to breach McGraw Hill and other organizations
www.temu.comUnauthorized fourth-party tracking domain receiving banking session associationssync.taboola.comTaboola pixel domain approved in CSP allow-list but routing to unauthorized destinations
hxxps://sync[.]taboola[.]com/sg/temurtbnative-network/1/rtb/Initial Taboola redirect endpoint initiating tracking chainhxxps://www[.]temu[.]com/api/adx/cm/pixel-taboolaTemu tracking endpoint receiving authenticated session data via 302 redirect