Weekly review

ThreatNoir Weekend Brief — April 25

2026-04-25Morning8 articles
Audio
Listen to the episode

Morning Review in IT Security — April 25, 2026

The threat landscape continues to evolve rapidly, with researchers uncovering critical vulnerabilities across cloud infrastructure, open-source ecosystems, and firmware persistence mechanisms. Today's security briefing highlights emerging risks in AI-driven cloud services, supply chain attacks, and state-grade sabotage frameworks that predate known advanced persistent threats.

The npm Threat Landscape: Attack Surface and Mitigations

Unit 42 has released a comprehensive analysis of the npm supply chain evolution following the Shai Hulud incident. The research examines wormable malware, CI/CD persistence mechanisms, and multi-stage attacks targeting the JavaScript ecosystem. The investigation identified several indicators of compromise, including the domain audit.checkmarx.cx and IP address 94.154.172.43, along with variants of the Shai-Hulud and Shai-Hulud 2.0 malware families. Source: The npm Threat Landscape: Attack Surface and Mitigations

Cracks in the Bedrock: Agent God Mode

Researchers have discovered a critical privilege escalation vulnerability in Amazon Bedrock AgentCore dubbed "Agent God Mode." The flaw stems from overly broad IAM permissions that allow compromised agents to escalate privileges across AWS accounts and extract sensitive data through multi-stage attacks. The vulnerability enables attackers to abuse elevation control mechanisms, discover accounts, and steal application access tokens. Source: Cracks in the Bedrock: Agent God Mode

Firestarter Malware Survives Cisco Firewall Updates and Security Patches

Cybersecurity agencies in the United States and United Kingdom have issued warnings regarding Firestarter, a custom malware persisting on Cisco Firepower and Secure Firewall devices. The malware continues to operate on systems running Adaptive Security Appliance (ASA) or Firepower Threat Defense (FTD) software even after security patches are applied. The threat is associated with vulnerabilities CVE-2025-20333 and CVE-2025-20362, and researchers have linked the malware to a related threat known as Line Viper. Source: Firestarter malware survives Cisco firewall updates, security patches

New BlackFile Extortion Group Linked to Surge of Vishing Attacks

A financially motivated threat actor group tracked as BlackFile has emerged as a significant threat to retail and hospitality organizations. Since February 2026, the group has conducted data theft and extortion attacks, leveraging vishing techniques to compromise targets. The campaign demonstrates the group's focus on high-value sectors vulnerable to social engineering attacks combined with technical exploitation. Source: New BlackFile extortion group linked to surge of vishing attacks

Four Vulnerabilities Added to CISA KEV Catalog

The CISA Known Exploited Vulnerabilities catalog has been updated with four newly tracked vulnerabilities. CVE-2025-29635 affects D-Link DIR-823X routers through command injection, CVE-2024-7399 impacts Samsung MagicINFO 9 Server via path traversal, and CVE-2024-57728 and CVE-2024-57726 target SimpleHelp with path traversal flaws. These additions indicate active exploitation in the wild against IoT and OT infrastructure. Source: Four vulnerabilities have been added to the CISA KEV Catalog

fast16: State-Grade Sabotage Framework Predates Stuxnet

Sentinel Labs has discovered fast16, a state-grade sabotage framework dating back to 2005, five years before the Stuxnet operation. The discovery reveals implications extending into advanced physics, cryptographic research, and nuclear programs. The framework represents a significant rewriting of cyberwarfare history and demonstrates that sophisticated nation-state sabotage capabilities existed earlier than previously documented. Source: The history of cyberwar just got rewritten

New Pack2TheRoot Flaw Gives Hackers Root Linux Access

A vulnerability designated CVE-2026-41651 has been identified in the PackageKit daemon that could allow local Linux users to gain root permissions. The flaw, dubbed Pack2TheRoot, enables attackers to install or remove system packages with elevated privileges, representing a critical local privilege escalation risk on affected Linux systems. Source: New 'Pack2TheRoot' flaw gives hackers root Linux access

As organizations navigate today's threat environment, attention to supply chain security, cloud infrastructure hardening, and timely patching of both firmware and operating system components remains essential to maintaining effective security postures.

Sources & IOCs

Source articles and extracted indicators (defanged where appropriate).

The npm Threat Landscape: Attack Surface and Mitigations
Malware2
  • Shai-Hulud 2.0
    Updated variant impersonating @bitwarden/cli v2026.4.0 with credential harvesting and propagation
  • Shai-Hulud
    Self-replicating worm that automates compromise and redistribution of malicious npm packages
IP Address1
  • 94.154.172.43
    IP address hosting C2 server audit.checkmarx.cx on port 443
Domain1
  • audit.checkmarx.cx
    Primary C2 infrastructure used in Shai-Hulud and Checkmarx compromise campaign