- StrixOpen-source autonomous security testing project that discovered the API vulnerability
ThreatNoir Morning Brief — May 7
Morning Review in IT Security — May 7, 2026
The cybersecurity landscape continues to face mounting pressure from both unpatched vulnerabilities and newly discovered threats. Today's briefing covers critical exposures affecting government contractors, cloud infrastructure, enterprise firewalls, and endpoint security, each presenting distinct risks to organizational operations and data integrity.
A DOD Contractor's API Flaw Exposed Military Course Data and Service Member Records
Researchers have identified a significant API vulnerability in a Department of Defense contractor's platform that exposed sensitive military information before remediation. The exposed data included service member names, email addresses, base assignments, and course materials. The contractor, Schemata, has since patched the vulnerability and notified government authorities of the incident. Source: A DOD contractor's API flaw exposed military course data and service member records
Google Fixes CVSS 10 Gemini CLI Vulnerability Enabling GitHub Issue-Based RCE
Google has addressed a critical vulnerability in its Gemini CLI tool that carried a maximum CVSS score of 10. The flaw allowed attackers to exploit prompt injection techniques combined with privilege escalation to achieve remote code execution through GitHub issues, potentially enabling full supply chain compromise. The patch resolves a significant risk vector for organizations utilizing Google's AI-powered development tools. Source: Google Fixes CVSS 10 Gemini CLI Vulnerability Enabling GitHub Issue-Based RCE
A Critical Palo Alto PAN-OS Zero-Day Is Being Exploited in the Wild
A critical zero-day vulnerability in Palo Alto Networks PAN-OS firewall software is currently being actively exploited in production environments. The vulnerability, tracked as CVE-2026-0300, has not yet received a patch from the vendor, and details regarding the scope and objectives of confirmed attacks remain undisclosed. Organizations relying on affected PAN-OS installations face immediate risk and should monitor vendor communications closely for remediation guidance. Source: A critical Palo Alto PAN-OS zero-day is being exploited in the wild
CloudZ RAT: A Stealthy New Trojan Hijacks Microsoft Phone Link to Steal Your SMS OTPs
Security researchers have disclosed a newly identified remote access trojan that leverages Microsoft Phone Link, a built-in Windows feature, to intercept SMS-based one-time passwords without requiring access to the target mobile device. The malware, known as CloudZ RAT and associated with variants including Pheno and systemupdates.exe, represents a sophisticated threat to multi-factor authentication mechanisms. The trojan's ability to harvest credentials through a legitimate Windows feature significantly elevates the risk profile for endpoint compromise. Source: CloudZ RAT: A Stealthy New Trojan Hijacks Microsoft Phone Link to Steal Your SMS OTPs
Organizations should prioritize immediate action on the Palo Alto Networks vulnerability while implementing enhanced monitoring for CloudZ RAT indicators and reviewing API security postures across contractor and cloud-based systems. The convergence of these threats underscores the critical importance of rapid vulnerability assessment and coordinated incident response capabilities.
Sources & IOCs
Source articles and extracted indicators (defanged where appropriate).
- Critical memory corruption vulnerability in Palo Alto Networks PAN-OS authentication portal affecting PA-Series and VM-Series firewalls
- CloudZ RATModular .NET-based remote access trojan active since January 2026
- PhenoPlugin for CloudZ RAT that detects and exfiltrates Phone Link data
- systemupdates.exeFake ConnectWise ScreenConnect update used in initial infection chain
65fcd965040f…Rust-compiled dropper component of CloudZ RAT