Weekly review

ThreatNoir Morning Brief — April 23

2026-04-23Morning4 articles
Audio
Listen to the episode

Morning Review in IT Security — April 23, 2026

The threat landscape continues to evolve rapidly as attackers leverage both legacy vulnerabilities and cutting-edge cryptography techniques. Today's security briefing covers active botnet campaigns targeting outdated network infrastructure, emerging ransomware variants employing post-quantum encryption, a significant supply chain compromise affecting development tools, and a critical zero-day vulnerability in widely deployed security software.

New Mirai Campaign Exploits RCE Flaw in EoL D-Link Routers

A newly identified Mirai-based malware campaign is actively exploiting CVE-2025-29635, a high-severity command-injection vulnerability in D-Link DIR-823X routers, to recruit devices into the botnet infrastructure. The vulnerability affects end-of-life devices that no longer receive security updates, making them particularly attractive targets for threat actors seeking to expand their botnet capabilities. Source: Bleeping Computer

This campaign demonstrates the persistent danger posed by legacy network equipment in enterprise and consumer environments. Organizations continue to operate routers beyond their supported lifecycle, creating an expanding attack surface that threat actors actively monitor and exploit. The use of Mirai variants indicates attackers are maintaining focus on IoT device compromise as a reliable method for establishing distributed attack infrastructure.

Kyber Ransomware Gang Toys with Post-Quantum Encryption on Windows

The emerging Kyber ransomware operation is targeting both Windows systems and VMware ESXi endpoints, with recent variants incorporating Kyber1024 post-quantum encryption algorithms into their attack payloads. This represents a significant escalation in ransomware sophistication, as threat actors begin adopting cryptographic methods designed to resist future quantum computing capabilities. Source: Bleeping Computer

The deployment of post-quantum encryption in active ransomware campaigns signals a strategic shift in how threat actors approach data protection and extortion operations. By implementing Kyber1024, the gang ensures that encrypted files remain protected against decryption attempts even as computational capabilities advance. This development underscores the need for organizations to reassess their incident response capabilities and backup strategies in preparation for next-generation ransomware threats.

Malicious KICS Docker Images and VS Code Extensions Hit Checkmarx Supply Chain

Cybersecurity researchers have identified malicious Docker images within the official checkmarx/kics Docker Hub repository, where unknown threat actors successfully overwrote existing tags including v2.1.20 and alpine while introducing a fraudulent v2.1.21 tag that does not correspond to any official release. The compromised images contain modified KICS binaries with data exfiltration capabilities, creating a significant risk for developers relying on this infrastructure security tool. Source: The Hacker News

This supply chain compromise demonstrates the vulnerability of widely-used development tools to unauthorized modification and injection of malicious functionality. Organizations that have pulled these compromised images into their development pipelines or production environments face potential exposure of infrastructure secrets and configuration data. The incident highlights the critical importance of verifying image integrity and implementing strict controls over container registry access.

Don't Wait for a Patch: Mitigate RedSun Zero-Day Risk in Microsoft Defender Today

RedSun is a zero-day local privilege escalation vulnerability in Microsoft Defender that allows low-privileged users to gain full SYSTEM-level access on Windows systems without requiring kernel exploits or administrator interaction. The vulnerability is particularly dangerous because it weaponizes a trusted, always-on security component that operates continuously across most enterprise environments, creating a universal attack surface. Source: Qualys Blog

Given the ubiquitous deployment of Microsoft Defender across Windows infrastructure, organizations should prioritize implementing mitigation strategies immediately rather than waiting for official patches. The zero-day nature of this vulnerability means threat actors may already be developing or deploying exploits, making proactive defense measures essential to prevent privilege escalation attacks within protected environments.


Security teams should address these threats with appropriate urgency based on their operational environment and risk profile. The combination of legacy device exploitation, advanced ransomware capabilities, supply chain compromises, and zero-day vulnerabilities in core security tools represents a complex threat landscape requiring coordinated detection and response efforts.

Sources & IOCs

Source articles and extracted indicators (defanged where appropriate).