- Lumma StealerInfostealer malware used to infect Context.ai employee's computer in February; initial vector for Vercel attack chain
ThreatNoir Morning Brief — April 24
Morning Review in IT Security — April 24, 2026
The threat landscape continues to shift rapidly as researchers uncover historical cyber operations while simultaneously responding to active exploitation campaigns. Today's security briefing highlights critical vulnerabilities across cloud infrastructure, WordPress plugins, and networking equipment, alongside newly deciphered malware that predates some of the most significant cyber operations in history.
Vercel Attack Fallout Expands to More Customers and Third-Party Systems
The Vercel platform breach continues to widen in scope as the company discovers additional evidence of compromise affecting a larger portion of its customer base. The exposure, which remains incompletely characterized, creates significant downstream risk for affected organizations and their downstream dependencies. Source: CyberScoop. The investigation has identified the Lumma Stealer malware as part of the attack infrastructure, indicating a sophisticated threat actor with access to sensitive credentials and configuration data stored on the platform.
Newly Deciphered Sabotage Malware May Have Targeted Iran's Nuclear Program—and Predates Stuxnet
Researchers have successfully deciphered Fast16, a previously mysterious malware capable of silently tampering with calculation and simulation software used in critical infrastructure environments. The malware was created in 2005, predating the well-known Stuxnet operation by several years, and was likely deployed by the United States or an allied nation. Source: Wired. The discovery of Fast16 suggests a longer and more sophisticated history of cyber operations targeting Iran's nuclear program than previously understood by the security community.
Hackers Exploit File Upload Bug in Breeze Cache WordPress Plugin
Active exploitation is underway for a critical vulnerability in the Breeze Cache plugin for WordPress that permits unauthenticated attackers to upload arbitrary files to affected servers. Source: Bleeping Computer. The vulnerability, tracked as CVE-2026-3844, represents a severe risk to the millions of WordPress installations utilizing this caching solution, as successful exploitation grants attackers direct code execution capabilities on compromised web servers.
US, UK Agencies Warn Hackers Were Hiding on Cisco Firewalls Long After Patches Were Applied
Joint warnings from US and UK cybersecurity agencies reveal that threat actors successfully maintained persistent access to Cisco firewall devices even after security patches were deployed, highlighting a critical gap in patching validation and endpoint hardening practices. Source: CyberScoop. Investigators identified malware designated Firestarter, along with associated tools Line Viper and RayInitiator, on a federal agency network in a campaign dating back to at least September 2025, exploiting vulnerabilities CVE-2025-20333 and CVE-2025-20362 to establish and maintain unauthorized access.
As threat actors continue to exploit both newly discovered and legacy vulnerabilities across multiple attack surfaces, organizations must prioritize comprehensive vulnerability management, supply chain security, and post-patch verification procedures to defend against increasingly sophisticated adversaries.
Sources & IOCs
Source articles and extracted indicators (defanged where appropriate).
- Fast16State-sponsored sabotage malware capable of tampering with simulation software; created ~2005, possibly deployed against Iranian nuclear research.
- StuxnetUS/Israeli malware deployed in 2007 against Iranian nuclear centrifuges; compared as more direct sabotage approach.
- Critical file upload vulnerability in Breeze Cache WordPress plugin allowing unauthenticated RCE
- Remote code execution in Cisco VPN web server component, exploited by UAT-4356
- Unauthorized access vulnerability in Cisco firewalls, exploited by UAT-4356
- RayInitiatorRelated implant with technical similarities to Firestarter, attributed to UAT-4356
- Line ViperSeparate implant used to exfiltrate device configs, credentials, and encryption keys
- FirestarterCustom backdoor persisting on Cisco firewalls via mount list manipulation