Weekly review

ThreatNoir Weekend Brief — April 19

2026-04-19Afternoon4 articles
Audio
Listen to the episode

Afternoon Review in IT Security — April 19, 2026

The cybersecurity landscape continues to face mounting pressure as threat actors actively exploit multiple critical vulnerabilities across enterprise and infrastructure systems. Today's security briefing highlights urgent threats spanning endpoint protection platforms, water treatment facilities, and widely-deployed message broker software that demand immediate attention from defenders.

Three Microsoft Defender Zero-Days Actively Exploited; Two Still Unpatched

Huntress has issued a warning regarding active exploitation of three security vulnerabilities in Microsoft Defender that allow threat actors to achieve elevated privileges on compromised systems. The vulnerabilities, identified as BlueHammer, RedSun, and UnDefend, were initially disclosed as zero-days by a researcher operating under the handle Chaotic Eclipse. The exploitation campaign demonstrates that threat actors are moving quickly to weaponize these flaws before patches can be broadly deployed, leaving organizations with unpatched systems at significant risk. Source: The Hacker News

New ZionSiphon Malware Discovered Targeting Israeli Water Systems

Researchers at Darktrace have uncovered a new malware strain called ZionSiphon that specifically targets Israeli water treatment plants. This operationally-focused threat represents a concerning escalation in nation-state activity against critical infrastructure. The malware employs techniques including USB-based propagation and exploitation of industrial control system protocols to compromise water infrastructure systems. Source: Hackread

Recent Apache ActiveMQ Vulnerability Exploited in the Wild

A remote code execution vulnerability in Apache ActiveMQ, tracked as CVE-2026-34197, emerged in early April and is now being actively exploited by threat actors in real-world attacks. The vulnerability represents a significant supply chain risk given ActiveMQ's widespread deployment across enterprise environments. Organizations running affected versions face immediate risk of compromise through remote exploitation. Source: SecurityWeek

CISA Flags Apache ActiveMQ Flaw as Actively Exploited in Attacks

The Cybersecurity and Infrastructure Security Agency has formally flagged the Apache ActiveMQ vulnerability as actively exploited in ongoing attacks. The flaw remained undetected for 13 years before being patched earlier this month, creating an extended window of vulnerability across production systems. CISA's warning indicates that attackers are leveraging this vulnerability in coordinated campaigns, with some attacks associated with the TellYouThePass malware family. Organizations should prioritize patching ActiveMQ deployments immediately to prevent compromise. Source: BleepingComputer

The convergence of active exploitation across Microsoft Defender, critical infrastructure targeting, and widely-deployed open-source software underscores the importance of rapid vulnerability assessment and patching protocols. Organizations should conduct immediate inventory reviews of affected systems and prioritize remediation efforts accordingly.

Sources & IOCs

Source articles and extracted indicators (defanged where appropriate).

Three Microsoft Defender Zero-Days Actively Exploited; Two Still Unpatched
CVE1
  • Microsoft Defender LPE vulnerability (BlueHammer), patched in Patch Tuesday
Malware3
  • UnDefend
    Denial-of-service vulnerability affecting Microsoft Defender definition updates, unpatched
  • RedSun
    Local privilege escalation vulnerability in Microsoft Defender, unpatched as of April 17, 2026
  • BlueHammer
    Local privilege escalation flaw in Microsoft Defender, exploited since April 10, 2026