Weekly review

ThreatNoir Afternoon Brief — April 20

2026-04-20Afternoon4 articles
Audio
Listen to the episode

Afternoon Review in IT Security — April 20, 2026

The cybersecurity landscape continues to present critical challenges across multiple vectors today, with vulnerabilities affecting widely-deployed open-source libraries, breaches impacting infrastructure providers, and emerging threats targeting cryptocurrency users on mainstream platforms. These developments underscore the persistent risks facing organizations and individuals relying on third-party tools and services.

52M-Download protobuf.js Library Hit by RCE in Schema Handling

A critical remote code execution vulnerability has been discovered in the protobuf.js library, which has accumulated over 52 million downloads. The flaw allows attackers to execute arbitrary code by crafting malicious schemas, posing a significant risk to applications that depend on this widely-used JavaScript library for protocol buffer handling. Organizations utilizing affected versions must prioritize patching to prevent exploitation of this vulnerability in their supply chains. Source: Hackread

Next.js Creator Vercel Hacked

Vercel, the company behind the popular Next.js framework, has confirmed a security breach after a threat actor claiming affiliation with ShinyHunters publicly offered to sell stolen data for $2 million. The incident highlights the risks posed by compromises at infrastructure and platform providers, where attackers can gain access to sensitive information affecting numerous downstream users and developers. The Lumma stealer malware has been identified in connection with this incident. Source: SecurityWeek

Network 'Background Noise' May Predict the Next Big Edge-Device Vulnerability

Researchers at GreyNoise have identified a consistent pattern in network reconnaissance activity that precedes major vulnerabilities affecting security tools and edge devices. By analyzing what appears as background noise in network traffic, defenders can potentially gain an early-warning system for imminent attacks targeting vulnerable infrastructure. This discovery provides security teams with a proactive methodology for anticipating and preparing for exploitation of zero-day and newly-disclosed vulnerabilities. Source: CyberScoop

FakeWallet Crypto Stealer Spreading Through iOS Apps in the App Store

Over twenty malicious applications masquerading as legitimate cryptocurrency wallets have been discovered in the Apple App Store as of March 2026. The FakeWallet malware steals user credentials and funds by deceiving users into believing they are interacting with trusted wallet services. This campaign demonstrates how threat actors continue to exploit the app store review process, bypassing security controls to distribute credential-stealing malware to unsuspecting users. Source: Securelist

Today's threat landscape reflects a multi-layered attack surface spanning open-source ecosystems, cloud infrastructure providers, network reconnaissance patterns, and consumer-facing platforms. Organizations and individuals must maintain vigilance across all these domains while prioritizing rapid patching and verification of third-party application authenticity.

Sources & IOCs

Source articles and extracted indicators (defanged where appropriate).

Next.js Creator Vercel Hacked
Malware1
  • Lumma stealer
    Infostealer malware used to obtain Context.ai employee credentials in February 2026, facilitating access chain