Weekly review

ThreatNoir Afternoon Brief — May 6

2026-05-06Afternoon4 articles
Audio
Listen to the episode

Afternoon Review in IT Security — May 6, 2026

The threat landscape continues to evolve with critical vulnerabilities in enterprise infrastructure, sophisticated supply-chain targeting, and multi-stage credential theft campaigns emerging across platforms. Today's security briefing highlights active exploitation of network appliances, advanced Linux-based remote access tools, and cross-platform attack chains designed to compromise developer environments and steal authentication credentials.

Palo Alto PAN-OS Flaw Under Active Exploitation Enables Remote Code Execution

Palo Alto Networks has released a critical advisory regarding an active exploitation campaign targeting a buffer overflow vulnerability in PAN-OS software. The vulnerability, identified as CVE-2026-0300, permits unauthenticated remote code execution and carries a CVSS severity score of 9.3 when the User-ID Authentication Portal is configured to allow internet-facing access. This represents an immediate threat to organizations operating Palo Alto firewalls in internet-exposed configurations.

Source: Palo Alto PAN-OS Flaw Under Active Exploitation Enables Remote Code Execution

Sophisticated Quasar Linux RAT Targets Software Developers

Security researchers have identified a sophisticated remote access trojan targeting software developers through supply-chain attack vectors. The Quasar Linux RAT provides comprehensive remote access, surveillance, and credential exfiltration capabilities, representing a significant threat to development environments and downstream software distribution. The malware's focus on developer targeting suggests potential supply-chain compromise scenarios.

Source: Sophisticated Quasar Linux RAT Targets Software Developers

Quasar Linux (QLNX) – A Silent Foothold in the Supply Chain

TrendMicro Research has published detailed analysis of Quasar Linux, a previously undocumented Linux RAT demonstrating sophisticated evasion capabilities and low detection rates. The malware incorporates an LD_PRELOAD rootkit, a PAM backdoor module named pam_security.so, and comprehensive credential harvesting functionality. These components work in concert to establish stealthy persistence, maintain administrative access, and facilitate supply-chain attacks against development infrastructure and software distribution pipelines.

Source: Quasar Linux (QLNX) – A Silent Foothold in the Supply Chain: Inside a Full-Featured Linux RAT With Rootkit, PAM Backdoor, Credential Harvesting Capabilities

Windows Phone Link Exploited by CloudZ RAT to Steal Credentials and OTPs

Cybersecurity researchers have disclosed an intrusion campaign leveraging the CloudZ remote access tool in conjunction with a previously undocumented plugin called Pheno. The attack chain exploits Windows Phone Link to facilitate credential theft and one-time password exfiltration from compromised systems. The integration of the GoGra malware component further extends the attack surface, creating a multi-stage credential harvesting operation targeting authentication systems.

Source: Windows Phone Link Exploited by CloudZ RAT to Steal Credentials and OTPs

Summary

Today's threat intelligence reveals converging attack patterns targeting critical infrastructure, developer ecosystems, and authentication mechanisms. Organizations should prioritize patching CVE-2026-0300 in internet-exposed Palo Alto deployments, implement enhanced monitoring for Linux-based RAT activity within development environments, and strengthen credential protection mechanisms against multi-stage credential theft campaigns.

Sources & IOCs

Source articles and extracted indicators (defanged where appropriate).

Windows Phone Link Exploited by CloudZ RAT to Steal Credentials and OTPs
Malware3
  • CloudZ RAT
    Remote access trojan used to steal credentials and OTPs; modular architecture with plugin support
  • GoGra
    Linux backdoor mentioned in related threat activity; deployed via Microsoft Graph API
  • Pheno
    Custom undocumented plugin deployed via CloudZ to hijack Windows Phone Link and intercept mobile data