Weekly review

ThreatNoir Morning Brief — April 24

2026-04-24Morning4 articles
Audio
Listen to the episode

Morning Review in IT Security — April 24, 2026

The threat landscape continues to shift rapidly as researchers uncover historical cyber operations while simultaneously responding to active exploitation campaigns. Today's security briefing highlights critical vulnerabilities across cloud infrastructure, WordPress plugins, and networking equipment, alongside newly deciphered malware that predates some of the most significant cyber operations in history.

Vercel Attack Fallout Expands to More Customers and Third-Party Systems

The Vercel platform breach continues to widen in scope as the company discovers additional evidence of compromise affecting a larger portion of its customer base. The exposure, which remains incompletely characterized, creates significant downstream risk for affected organizations and their downstream dependencies. Source: CyberScoop. The investigation has identified the Lumma Stealer malware as part of the attack infrastructure, indicating a sophisticated threat actor with access to sensitive credentials and configuration data stored on the platform.

Newly Deciphered Sabotage Malware May Have Targeted Iran's Nuclear Program—and Predates Stuxnet

Researchers have successfully deciphered Fast16, a previously mysterious malware capable of silently tampering with calculation and simulation software used in critical infrastructure environments. The malware was created in 2005, predating the well-known Stuxnet operation by several years, and was likely deployed by the United States or an allied nation. Source: Wired. The discovery of Fast16 suggests a longer and more sophisticated history of cyber operations targeting Iran's nuclear program than previously understood by the security community.

Hackers Exploit File Upload Bug in Breeze Cache WordPress Plugin

Active exploitation is underway for a critical vulnerability in the Breeze Cache plugin for WordPress that permits unauthenticated attackers to upload arbitrary files to affected servers. Source: Bleeping Computer. The vulnerability, tracked as CVE-2026-3844, represents a severe risk to the millions of WordPress installations utilizing this caching solution, as successful exploitation grants attackers direct code execution capabilities on compromised web servers.

US, UK Agencies Warn Hackers Were Hiding on Cisco Firewalls Long After Patches Were Applied

Joint warnings from US and UK cybersecurity agencies reveal that threat actors successfully maintained persistent access to Cisco firewall devices even after security patches were deployed, highlighting a critical gap in patching validation and endpoint hardening practices. Source: CyberScoop. Investigators identified malware designated Firestarter, along with associated tools Line Viper and RayInitiator, on a federal agency network in a campaign dating back to at least September 2025, exploiting vulnerabilities CVE-2025-20333 and CVE-2025-20362 to establish and maintain unauthorized access.

As threat actors continue to exploit both newly discovered and legacy vulnerabilities across multiple attack surfaces, organizations must prioritize comprehensive vulnerability management, supply chain security, and post-patch verification procedures to defend against increasingly sophisticated adversaries.

Sources & IOCs

Source articles and extracted indicators (defanged where appropriate).

US, UK agencies warn hackers were hiding on Cisco firewalls long after patches were applied
CVE2
  • Remote code execution in Cisco VPN web server component, exploited by UAT-4356
  • Unauthorized access vulnerability in Cisco firewalls, exploited by UAT-4356
Malware3
  • RayInitiator
    Related implant with technical similarities to Firestarter, attributed to UAT-4356
  • Line Viper
    Separate implant used to exfiltrate device configs, credentials, and encryption keys
  • Firestarter
    Custom backdoor persisting on Cisco firewalls via mount list manipulation