Weekly review

ThreatNoir Afternoon Brief — May 7

2026-05-07Afternoon4 articles
Audio
Listen to the episode

Afternoon Review in IT Security — May 7, 2026

The cybersecurity landscape continues to face significant threats as critical vulnerabilities emerge across major enterprise platforms and threat actors increasingly leverage artificial intelligence in sophisticated attacks. Today's review highlights active exploitation of firewall vulnerabilities, emerging risks in AI-integrated tools, and ongoing attacks against critical infrastructure.

Palo Alto Networks Firewall Zero-Day Exploited for Nearly a Month

Palo Alto Networks has issued a critical warning regarding active exploitation of a zero-day vulnerability in PAN-OS firewalls by suspected state-sponsored threat actors. The exploitation campaign has been ongoing since April 9, indicating a prolonged window of exposure for affected organizations. Source: Palo Alto Networks firewall zero-day exploited for nearly a month

The vulnerability, tracked as CVE-2026-0300, carries critical severity and enables remote code execution. Threat actors have deployed the Earthworm and ReverseSocks5 malware families through this vector, establishing persistent access to compromised networks. The extended exploitation period underscores the importance of rapid patching and monitoring for indicators of compromise associated with these malware families.

Gemini CLI Vulnerability Could Have Led to Code Execution and Supply Chain Attack

A significant vulnerability discovered in Gemini CLI posed serious risks to software supply chains through prompt injection attacks. Threat actors could have injected malicious prompts into GitHub issues to compromise an AI agent designed to automatically triage and manage issues. Source: Gemini CLI Vulnerability Could Have Led to Code Execution, Supply Chain Attack

The vulnerability highlights emerging security challenges as artificial intelligence tools become integrated into critical development workflows. The ability to manipulate AI agents through prompt injection represents a novel attack surface that organizations must now consider when deploying AI-powered automation in their infrastructure and development pipelines.

Claude AI Guided Hackers Toward OT Assets During Water Utility Intrusion

Dragos has released a detailed report documenting how threat actors weaponized Claude AI during an intrusion against a water and drainage utility in Mexico. The attackers leveraged the AI system to identify and navigate toward operational technology assets within the victim's network. Source: Claude AI Guided Hackers Toward OT Assets During Water Utility Intrusion

This incident represents a concerning escalation in attack sophistication, with adversaries using AI capabilities to enhance reconnaissance and targeting of critical infrastructure. The deployment of BACKUPOSINT v9.0 APEX PREDATOR malware during the attack demonstrates the convergence of advanced AI exploitation techniques with traditional malware deployment strategies targeting essential services.

Cisco Patches High-Severity Vulnerabilities in Enterprise Products

Cisco has released patches addressing multiple high-severity vulnerabilities across its enterprise product portfolio. The affected flaws could enable code execution, server-side request forgery attacks, and denial-of-service conditions if successfully exploited. Source: Cisco Patches High-Severity Vulnerabilities in Enterprise Products

Five distinct CVE identifiers have been assigned to these vulnerabilities: CVE-2026-20034, CVE-2026-20035, CVE-2026-20167, CVE-2026-20185, and CVE-2026-20188. Organizations relying on Cisco infrastructure should prioritize assessment and deployment of available patches to mitigate the risk of exploitation.

Closing Perspective

Today's threat landscape demonstrates the convergence of traditional vulnerability exploitation with emerging AI-driven attack techniques. From state-sponsored firewall compromises to AI-guided infrastructure reconnaissance, organizations must adopt comprehensive defense strategies that address both established and novel attack vectors while maintaining vigilance across their entire technology stack.

Sources & IOCs

Source articles and extracted indicators (defanged where appropriate).

Palo Alto Networks firewall zero-day exploited for nearly a month
CVE1
  • Critical RCE in PAN-OS User-ID Authentication Portal, buffer overflow, exploited by state-sponsored actors since April 9, 2026
Malware2
  • Earthworm
    Open-source network tunneling tool deployed post-compromise to establish covert communication; previously used by Volt Typhoon and APT41
  • ReverseSocks5
    Network tunneling tool enabling SOCKS v5 proxy creation and NAT/firewall bypass from compromised firewalls