← Carolina Clear Tech

Cyber Threat Brief

2026-03-04

Listen to this brief (17:43)

Download MP3
Show Notes

Show Notes - 2026-03-04

Stories Covered

CVEs Referenced

CVE-2024-4040, CVE-2025-31161, CVE-2025-54309, CVE-2026-1874, CVE-2026-1875, CVE-2026-1876, CVE-2026-21385, CVE-2026-22719

Indicators of Compromise

IP Addresses: 9.0.2.0, 5.189.139.225

Read the full brief

Get tomorrow's brief in your inbox

Protect Your Business

Need a security assessment? See our cybersecurity packages.

View Services

Cyber Threat Brief - March 4, 2026

Today: CISA adds two actively exploited vulnerabilities to the KEV catalog, including a VMware Aria Operations command injection flaw requiring federal agencies to patch by March 24. Microsoft reports phishing campaigns using signed malware impersonating Teams and Zoom to deploy RMM backdoors. CrushFTP administrators face brute-force attacks targeting default credentials.

Critical Alerts

CISA Adds VMware Aria Operations Command Injection to KEV Catalog (CVE-2026-22719)

CISA added CVE-2026-22719 to the KEV catalog due to active exploitation in the wild. The vulnerability is a command injection flaw in Broadcom VMware Aria Operations that allows unauthenticated attackers to execute arbitrary commands, leading to remote code execution while support-assisted product migration is in progress. Broadcom confirmed awareness of exploitation reports but cannot independently verify them. The flaw affects VMware Cloud Foundation/vSphere Foundation 9.x.x.x and VMware Aria Operations 8.x. EPSS scoring shows 0.005 (64th percentile), indicating low observed exploitation but confirmed KEV status proves active attacks.

Qualcomm Chipset Memory Corruption Exploited in Targeted Attacks (CVE-2026-21385)

CISA added CVE-2026-21385, a high-severity memory corruption vulnerability in Qualcomm chipsets, to the KEV catalog. The flaw is exploited in targeted Android attacks, potentially linked to commercial spyware or nation-state threat groups. The vulnerability is an integer overflow leading to memory corruption in the Qualcomm graphics component. EPSS shows 0.000 (3rd percentile), indicating very limited observed exploitation, but CISA KEV status confirms active use in the wild. Federal agencies have until March 24, 2026 to remediate.

CrushFTP Brute-Force Campaign Targets Default Credentials

Attackers are targeting CrushFTP instances with brute-force login attempts using the default username and password crushadmin/crushadmin. The attacks originate from 5.189.139.225, a French IP with a history of exploit attempts. While this is not exploitation of a specific CVE, it follows a series of critical CrushFTP vulnerabilities including CVE-2024-4040 (template injection RCE, EPSS 0.944), CVE-2025-31161 (auth bypass, EPSS 0.873), and CVE-2025-54309 (zero-day RCE, EPSS 0.696). All three are CISA KEV entries and have been used in ransomware attacks.

Ransomware Claims (Last 48h)

19 claims tracked across 14 groups in the last 48 hours. These are unverified claims from ransomware leak sites, not confirmed breaches.

Group Victim Sector Country
Inc Ransom Brockman Injury Lawyer Legal Services US
Inc Ransom Hersher Law Legal Services US
Inc Ransom Hopkins Law Legal Services US
Inc Ransom Napolin Law Firm Legal Services US
Inc Ransom Law Offices of Mark E. Lewis & Associates Legal Services US
Kairos Katz Kantor Stonestreet & Buckner Legal Services US
Payload Thai Solar Energy Public Energy Thailand
Payload United Limsun International Trading Retail/Distribution Unknown
Qilin Dr. Pizzoglio Healthcare Unknown
MetaEncryptor MPA Pharma GmbH Pharmaceutical Germany
Akira ICAFe Companies / Southwest Air Equipment Manufacturing US
DragonForce Bravo Electro Components Electronics Unknown
Nightspire AKOL LAW Legal Services Unknown
Vect Verlat Energy Energy Peru
SafePay Franz-Sales-Haus.de Social Services Germany
Play Equine Canada Non-Profit Canada
The Gentlemen CHS Villach Education Austria
Beast Camelot Electronics Technology Co. Manufacturing/PCB China
Ailock Demanor Manufacturing/Lifts Norway

Notable: Inc Ransom has posted 5 law firms in the last 48 hours, indicating a targeted campaign against legal sector organizations.

Ransomware & Extortion

Insight Hospital Data Leaked Following September 2025 Breach

Insight Hospital and Medical Center in Chicago experienced unauthorized network access between August 22 and September 11, 2025. The hospital issued a substitute notice in January 2026 indicating that names, Social Security numbers, dates of birth, driver's license numbers, passport numbers, financial account information, and treatment-related health information may have been accessed. As of the notice date, affected individuals had not been notified and no mitigation services were offered. On February 24, 2026, the Termite ransomware group leaked 360 GB (approximately 900,000 files) of confidential data, including numerous JPEG and DICOM medical imaging files. The group did not publish proof of claims but immediately released the full dataset.

Business & Infrastructure Threats

Signed Malware Impersonating Workplace Apps Deploys RMM Backdoors

Microsoft Defender Experts identified phishing campaigns using workplace meeting lures to deliver signed malware impersonating Teams, Zoom, Adobe Reader, and Google Meet. The malicious executables are digitally signed using an Extended Validation certificate issued to TrustConnect Software PTY LTD. Phishing emails contain PDF attachments or links that redirect users to spoofed download pages displaying "out of date" or "update required" prompts. Once executed, the files deploy ScreenConnect, Tactical RMM, and Mesh Agent remote monitoring tools. The malware creates a secondary copy in C:\Program Files, registers as a Windows service, and establishes persistence via HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run with the value TrustConnectAgent. The service then establishes outbound connections to attacker-controlled infrastructure.

Fake Tech Support Spam Deploys Havoc C2 Framework

Threat actors used email spam and fake IT support phone calls to deploy the Havoc command-and-control framework across five organizations. The attack chain begins with email bombing to overwhelm inboxes, followed by a phone call from fake IT support offering to remediate the problem via Quick Assist or AnyDesk. Once connected, attackers direct victims to a fake Microsoft landing page on AWS that prompts for email and password to access "Outlook's anti-spam rules update system." The page harvests credentials while downloading a supposed anti-spam patch. The payload uses DLL sideloading (ADNotificationManager.exe, DLPUserAgent.exe, or Werfault.exe) to execute Havoc shellcode. The malicious DLL (vcruntime140_1.dll) uses control flow obfuscation, timing delays, and Hell's Gate/Halo's Gate techniques to bypass EDR. Attackers moved from initial access to nine additional endpoints over eleven hours, creating scheduled tasks for persistence and deploying legitimate RMM tools alongside Havoc.

Starkiller Phishing Suite Bypasses MFA with AitM Reverse Proxy

A new phishing platform called Starkiller uses adversary-in-the-middle (AitM) reverse proxy to bypass multi-factor authentication. Advertised by the Jinkusu threat group, the service launches a headless Chrome instance in a Docker container, loads the real target brand's website, and acts as a reverse proxy between the victim and the legitimate site. Recipients see genuine page content served through attacker infrastructure, eliminating the need for template updates and evading fingerprinting. Every keystroke, form submission, and session token is captured for account takeover. The platform centralizes infrastructure management, phishing page deployment, and session monitoring in a single control panel with URL shorteners (TinyURL) for obfuscation.

Patch Priority

Vulnerability Disclosures

Mitsubishi Electric MELSEC iQ-F Series Ethernet Modules (CVE-2026-1874, CVE-2026-1875, CVE-2026-1876)

Three denial-of-service vulnerabilities affect Mitsubishi Electric MELSEC iQ-F Series EtherNet/IP and Ethernet modules. CVE-2026-1874 is an always-incorrect control flow implementation that allows remote attackers to cause DoS by continuously sending UDP packets. It affects both FX5-ENET/IP (version 1.106 and prior) and FX5-EIP (all versions). CVE-2026-1875 is an improper resource shutdown vulnerability affecting only FX5-EIP. CVE-2026-1876 affects FX5-ENET/IP. EPSS scores are 0.001 (35th percentile) for all three, indicating low likelihood of exploitation.

Trends & Context

Three patterns emerge today: active exploitation of enterprise infrastructure (VMware, Qualcomm), phishing evolution toward signed malware and MFA bypass techniques, and sustained ransomware targeting of legal sector organizations. The Inc Ransom campaign against five law firms in 48 hours suggests coordinated targeting based on sector-specific vulnerabilities or initial access. The use of legitimate EV certificates (TrustConnect Software PTY LTD) to sign RMM backdoors demonstrates abuse of trust infrastructure, requiring certificate-based blocking rather than relying solely on reputation or signature validation.