Weekly review

ThreatNoir Morning Brief — May 7

2026-05-07Morning4 articles
Audio
Listen to the episode

Morning Review in IT Security — May 7, 2026

The cybersecurity landscape continues to face mounting pressure from both unpatched vulnerabilities and newly discovered threats. Today's briefing covers critical exposures affecting government contractors, cloud infrastructure, enterprise firewalls, and endpoint security, each presenting distinct risks to organizational operations and data integrity.

A DOD Contractor's API Flaw Exposed Military Course Data and Service Member Records

Researchers have identified a significant API vulnerability in a Department of Defense contractor's platform that exposed sensitive military information before remediation. The exposed data included service member names, email addresses, base assignments, and course materials. The contractor, Schemata, has since patched the vulnerability and notified government authorities of the incident. Source: A DOD contractor's API flaw exposed military course data and service member records

Google Fixes CVSS 10 Gemini CLI Vulnerability Enabling GitHub Issue-Based RCE

Google has addressed a critical vulnerability in its Gemini CLI tool that carried a maximum CVSS score of 10. The flaw allowed attackers to exploit prompt injection techniques combined with privilege escalation to achieve remote code execution through GitHub issues, potentially enabling full supply chain compromise. The patch resolves a significant risk vector for organizations utilizing Google's AI-powered development tools. Source: Google Fixes CVSS 10 Gemini CLI Vulnerability Enabling GitHub Issue-Based RCE

A Critical Palo Alto PAN-OS Zero-Day Is Being Exploited in the Wild

A critical zero-day vulnerability in Palo Alto Networks PAN-OS firewall software is currently being actively exploited in production environments. The vulnerability, tracked as CVE-2026-0300, has not yet received a patch from the vendor, and details regarding the scope and objectives of confirmed attacks remain undisclosed. Organizations relying on affected PAN-OS installations face immediate risk and should monitor vendor communications closely for remediation guidance. Source: A critical Palo Alto PAN-OS zero-day is being exploited in the wild

CloudZ RAT: A Stealthy New Trojan Hijacks Microsoft Phone Link to Steal Your SMS OTPs

Security researchers have disclosed a newly identified remote access trojan that leverages Microsoft Phone Link, a built-in Windows feature, to intercept SMS-based one-time passwords without requiring access to the target mobile device. The malware, known as CloudZ RAT and associated with variants including Pheno and systemupdates.exe, represents a sophisticated threat to multi-factor authentication mechanisms. The trojan's ability to harvest credentials through a legitimate Windows feature significantly elevates the risk profile for endpoint compromise. Source: CloudZ RAT: A Stealthy New Trojan Hijacks Microsoft Phone Link to Steal Your SMS OTPs

Organizations should prioritize immediate action on the Palo Alto Networks vulnerability while implementing enhanced monitoring for CloudZ RAT indicators and reviewing API security postures across contractor and cloud-based systems. The convergence of these threats underscores the critical importance of rapid vulnerability assessment and coordinated incident response capabilities.

Sources & IOCs

Source articles and extracted indicators (defanged where appropriate).