Morning Review in IT Security — April 25, 2026
The threat landscape continues to evolve rapidly, with researchers uncovering critical vulnerabilities across cloud infrastructure, open-source ecosystems, and firmware persistence mechanisms. Today's security briefing highlights emerging risks in AI-driven cloud services, supply chain attacks, and state-grade sabotage frameworks that predate known advanced persistent threats.
The npm Threat Landscape: Attack Surface and Mitigations
Unit 42 has released a comprehensive analysis of the npm supply chain evolution following the Shai Hulud incident. The research examines wormable malware, CI/CD persistence mechanisms, and multi-stage attacks targeting the JavaScript ecosystem. The investigation identified several indicators of compromise, including the domain audit.checkmarx.cx and IP address 94.154.172.43, along with variants of the Shai-Hulud and Shai-Hulud 2.0 malware families. Source: The npm Threat Landscape: Attack Surface and Mitigations
Cracks in the Bedrock: Agent God Mode
Researchers have discovered a critical privilege escalation vulnerability in Amazon Bedrock AgentCore dubbed "Agent God Mode." The flaw stems from overly broad IAM permissions that allow compromised agents to escalate privileges across AWS accounts and extract sensitive data through multi-stage attacks. The vulnerability enables attackers to abuse elevation control mechanisms, discover accounts, and steal application access tokens. Source: Cracks in the Bedrock: Agent God Mode
Firestarter Malware Survives Cisco Firewall Updates and Security Patches
Cybersecurity agencies in the United States and United Kingdom have issued warnings regarding Firestarter, a custom malware persisting on Cisco Firepower and Secure Firewall devices. The malware continues to operate on systems running Adaptive Security Appliance (ASA) or Firepower Threat Defense (FTD) software even after security patches are applied. The threat is associated with vulnerabilities CVE-2025-20333 and CVE-2025-20362, and researchers have linked the malware to a related threat known as Line Viper. Source: Firestarter malware survives Cisco firewall updates, security patches
New BlackFile Extortion Group Linked to Surge of Vishing Attacks
A financially motivated threat actor group tracked as BlackFile has emerged as a significant threat to retail and hospitality organizations. Since February 2026, the group has conducted data theft and extortion attacks, leveraging vishing techniques to compromise targets. The campaign demonstrates the group's focus on high-value sectors vulnerable to social engineering attacks combined with technical exploitation. Source: New BlackFile extortion group linked to surge of vishing attacks
Four Vulnerabilities Added to CISA KEV Catalog
The CISA Known Exploited Vulnerabilities catalog has been updated with four newly tracked vulnerabilities. CVE-2025-29635 affects D-Link DIR-823X routers through command injection, CVE-2024-7399 impacts Samsung MagicINFO 9 Server via path traversal, and CVE-2024-57728 and CVE-2024-57726 target SimpleHelp with path traversal flaws. These additions indicate active exploitation in the wild against IoT and OT infrastructure. Source: Four vulnerabilities have been added to the CISA KEV Catalog
fast16: State-Grade Sabotage Framework Predates Stuxnet
Sentinel Labs has discovered fast16, a state-grade sabotage framework dating back to 2005, five years before the Stuxnet operation. The discovery reveals implications extending into advanced physics, cryptographic research, and nuclear programs. The framework represents a significant rewriting of cyberwarfare history and demonstrates that sophisticated nation-state sabotage capabilities existed earlier than previously documented. Source: The history of cyberwar just got rewritten
New Pack2TheRoot Flaw Gives Hackers Root Linux Access
A vulnerability designated CVE-2026-41651 has been identified in the PackageKit daemon that could allow local Linux users to gain root permissions. The flaw, dubbed Pack2TheRoot, enables attackers to install or remove system packages with elevated privileges, representing a critical local privilege escalation risk on affected Linux systems. Source: New 'Pack2TheRoot' flaw gives hackers root Linux access
As organizations navigate today's threat environment, attention to supply chain security, cloud infrastructure hardening, and timely patching of both firmware and operating system components remains essential to maintaining effective security postures.