Weekly review

ThreatNoir Afternoon Brief — April 24

2026-04-24Afternoon4 articles
Audio
Listen to the episode

Afternoon Review in IT Security — April 24, 2026

The threat landscape continues to evolve with critical vulnerabilities affecting both government infrastructure and open-source software ecosystems. Today's security briefing highlights advanced persistent threats targeting federal systems, supply chain compromises in widely-used development tools, and newly discovered privilege escalation techniques in core Windows components.

US Federal Agency's Cisco Firewall Infected With 'Firestarter' Backdoor

A U.S. federal agency has discovered that one of its Cisco firewalls was compromised by the Firestarter backdoor malware. The malicious payload provides remote access and control capabilities to infected devices while maintaining persistence even after security patches are applied. This incident demonstrates the sophisticated nature of threats targeting critical infrastructure, with attackers employing multiple malware variants including Line Viper and RayInitiator in their operations. Source: US Federal Agency's Cisco Firewall Infected With 'Firestarter' Backdoor

The compromise leverages vulnerabilities tracked as CVE-2025-20333 and CVE-2025-20362, underscoring the importance of timely patching and monitoring for indicators of compromise on network perimeter devices. Federal agencies and organizations operating Cisco infrastructure should immediately review their firewall logs and implement enhanced detection mechanisms for these specific threats.

Bitwarden NPM Package Hit in Supply Chain Attack

The Bitwarden NPM package fell victim to a supply chain attack linked to a fresh campaign attributed to the Checkmarx security firm breach. The incident involves the Shai-Hulud worm and has been claimed by the threat actor group TeamPCP. Source: Bitwarden NPM Package Hit in Supply Chain Attack

This supply chain compromise poses significant risk to developers and organizations relying on Bitwarden's npm dependencies. The attack demonstrates how threat actors continue to target open-source software ecosystems to distribute malware at scale, potentially affecting thousands of downstream users and applications.

PhantomRPC: A New Privilege Escalation Technique in Windows RPC

Kaspersky researchers have identified PhantomRPC, a previously unknown vulnerability in Windows RPC architecture that enables attackers to create fraudulent RPC servers and escalate their privileges on compromised systems. Source: PhantomRPC: A new privilege escalation technique in Windows RPC

This vulnerability represents a critical weakness in core Windows components that could allow local attackers to gain elevated system access. Organizations should prioritize assessment of their Windows infrastructure for potential exploitation of this technique and monitor for suspicious RPC server creation activity.

Active Exploitation of CVE-2025-55182 in the Wild

Threat operators have been observed actively exploiting CVE-2025-55182 using sophisticated scanner infrastructure that relies on acquirer files containing target lists and lease files defining exploit parameters. The operators are obtaining target feeds from ZIP archives hosted on cs2.ip.thc.org and deploying payloads to compromise systems at scale. Source: The DFIR Report

This active exploitation campaign demonstrates the rapid weaponization of newly disclosed vulnerabilities. Organizations should immediately patch systems vulnerable to CVE-2025-55182 and implement network-level controls to block communications with known malicious infrastructure associated with this campaign.

The convergence of advanced backdoors in federal systems, supply chain compromises, and actively exploited zero-day vulnerabilities reflects an increasingly sophisticated threat environment. Security teams should prioritize vulnerability management, supply chain security monitoring, and enhanced logging on critical infrastructure to detect and respond to these emerging threats.

Sources & IOCs

Source articles and extracted indicators (defanged where appropriate).

US Federal Agency’s Cisco Firewall Infected With ‘Firestarter’ Backdoor
CVE2
  • Zero-day in Cisco ASA and Secure Firewall FTD VPN web server, exploited by ArcaneDoor/UAT-4356
  • Zero-day in Cisco ASA and Secure Firewall FTD VPN web server, exploited by ArcaneDoor/UAT-4356
Malware3
  • RayInitiator
    Bootkit component of ArcaneDoor campaign; resembles Firestarter persistence mechanism
  • Firestarter
    Persistent backdoor deployed on compromised Cisco firewalls; survives firmware patching by hooking into Lina engine
  • Line Viper
    Secondary payload deployed via Firestarter backdoor for additional capabilities
Bitwarden NPM Package Hit in Supply Chain Attack
Malware2
  • Shai-Hulud
    NPM worm referenced in Bitwarden payload with 'The Third Coming' string; previously infected 180+ packages in Sept and 640+ in Nov
  • TeamPCP
    Hacking group active since 2024 claiming responsibility for Checkmarx and related supply chain attacks; also known as DeadCatx3, PCPcat, ShellForce
Domain1
  • checkmarx.cx
    Exfiltration domain used in Checkmarx attack malware