← Carolina Clear Tech

Cyber Threat Brief

2026-03-05

Listen to this brief (27:30)

Download MP3
Show Notes

Show Notes - 2026-03-05

Stories Covered

CVEs Referenced

CVE-2020-27932, CVE-2022-20775, CVE-2023-32434, CVE-2023-38606, CVE-2024-23222, CVE-2024-24856, CVE-2024-42317, CVE-2024-57875, CVE-2025-21985, CVE-2025-37745, CVE-2025-71238, CVE-2026-0038, CVE-2026-20079, CVE-2026-20122, CVE-2026-20127, CVE-2026-20128, CVE-2026-20131, CVE-2026-23231, CVE-2026-23234, CVE-2026-23235, CVE-2026-23236, CVE-2026-23237, CVE-2026-23238, CVE-2026-23865, CVE-2026-25541, CVE-2026-3336

Indicators of Compromise

Domains: verify-lastpass[.]com

Read the full brief

Get tomorrow's brief in your inbox

Protect Your Business

Need a security assessment? See our cybersecurity packages.

View Services

Daily Cyber Threat Brief - March 5, 2026

Today: Cisco confirms active exploitation of two more SD-WAN vulnerabilities as federal agencies face March 25 remediation deadline. Phobos ransomware admin pleads guilty after $39M in victim payments. Microsoft disrupts Tycoon2FA phishing platform that bypassed MFA for 500,000 organizations monthly.

Critical Alerts

Cisco Catalyst SD-WAN Manager Actively Exploited (CVE-2026-20122, CVE-2026-20128)

Cisco flagged two additional SD-WAN Manager flaws as exploited in the wild on top of the critical auth bypass (CVE-2026-20127) disclosed last week. CVE-2026-20122 (high-severity arbitrary file overwrite) requires valid read-only API credentials. CVE-2026-20128 (medium-severity info disclosure) needs local vmanage credentials. The auth bypass vulnerability has been exploited since 2023, enabling sophisticated threat actors to add malicious rogue peers to SD-WAN networks for deeper lateral movement. CISA Emergency Directive 26-03 requires federal agencies to inventory systems, collect forensic artifacts, ensure external log storage, and apply updates by March 25. CVE-2026-20127 has CISA KEV listing (85th percentile EPSS), CVE-2022-20775 also on KEV with due date February 27. Vulnerabilities affect all Catalyst SD-WAN Manager software regardless of configuration.

Cisco Secure Firewall Management Center Root Access Flaws (CVE-2026-20079, CVE-2026-20131)

Cisco released patches Wednesday for two maximum-severity vulnerabilities in Secure Firewall Management Center (FMC). CVE-2026-20079 is an authentication bypass allowing unauthenticated remote attackers to gain root access to the underlying OS. CVE-2026-20131 is a remote code execution flaw enabling arbitrary Java code execution as root. Both exploitable remotely without authentication.

Ransomware Claims (Last 48h)

7 claims tracked across 4 groups in the last 48 hours. These are unverified claims from ransomware leak sites, not confirmed breaches.

Group Victim Sector Country
Tengu Community Mosaic Cic Non-profit UK
Tengu Eos Technology srl IT Services Italy
Tengu Dainty Cloud Inc Cloud Services Global
Tengu Al Arif Contracting Construction UAE
Tengu Martec Marine Maritime Defense Italy
Tridentlocker Jameson Pepple Cantu PLLC Legal Services US
XP95 Eholo Health Healthcare/Psychology Global

Ransomware & Extortion

Phobos Ransomware Admin Pleads Guilty to Wire Fraud Conspiracy

Russian national Evgenii Ptitsyn (43) pleaded guilty to wire fraud conspiracy for administering the Phobos ransomware operation. Phobos collected $39M in ransom payments from 1,000+ victims globally, accounting for 11% of all ID Ransomware submissions from May to November 2024. Ptitsyn was extradited from South Korea in November 2024 after operating since at least November 2020. He sold ransomware access via darknet sites under the handles "derxan" and "zimmermanx," charging affiliates $300 per decryption key and taking a cut of ransom payments. All decryption fees from December 2021 to April 2024 flowed to a single wallet controlled by Ptitsyn. Affiliates targeted schools, hospitals, and government agencies using stolen credentials, exfiltration, encryption, and extortion via email and phone threats. Sentencing scheduled for July 15, facing up to 20 years. Europol's Operation Aether disrupted Phobos infrastructure in February 2025, detaining two affiliates, seizing 27 servers, and warning 400+ companies of imminent attacks. Another affiliate arrested in Italy in 2023, and Polish police detained a 47-year-old with stolen credentials and server access data earlier this year.

University of Mississippi Medical Center Resumes Operations After 9-Day Ransomware Attack

UMMC reopened all clinics Monday after a ransomware attack blocked access to electronic medical records and took down IT systems. The attack forced cancellation of outpatient procedures, ambulatory surgeries, and imaging appointments for nine days, though hospital services continued using downtime procedures. UMMC restored patient record access Friday and announced clinic reopening plans. Clinics opened extended hours and extra days to accommodate rescheduled appointments. Hospital officials confirmed communication with attackers during Thursday press conference but did not disclose ransom demands or payment status. No ransomware group has claimed responsibility. FBI and CISA assisting with investigation. UMMC is one of Mississippi's largest employers with 10,000+ employees, operating seven hospitals, 35 clinics, and 200+ telehealth sites. Facilities include the state's only organ transplant program, only children's hospital, only Level I trauma center.

Brute Force Attack Exposes Ransomware Infrastructure Network

Huntress Tactical Response Team uncovered a ransomware-as-a-service infrastructure network after investigating what appeared to be routine RDP brute forcing. A single compromised account was accessed from multiple IP addresses with timestamps suggesting one threat actor using geo-distributed infrastructure rather than multiple attackers. After gaining RDP access via successful brute force, the actor enumerated domain groups and configurations before SOC isolation prevented lateral movement. Investigation revealed unusual activity patterns pointing to a shady VPN service enabling initial access brokers to sell network access to ransomware affiliates. The case demonstrates how commodity attack techniques (RDP brute forcing) serve as entry points for sophisticated ransomware operations when combined with access-as-a-service infrastructure.

XP95 Ransomware Claims Eholo Health Psychology Platform (1.1M Medical Notes)

XP95 group claimed a breach of Eholo, a practice management platform used by 10,000+ psychologists. The group claims 1.1M medical notes and 601K user PII records, demanding $300K ransom with a March 15 deadline. Eholo provides patient management, automated billing, scheduling, secure clinical histories, and integrated videoconferencing for psychology practices. Contact methods include Session messenger and Keybase. This represents a supply chain attack targeting a vertical-specific SaaS platform affecting thousands of downstream psychology practices.

Business & Infrastructure Threats

Microsoft Disrupts Tycoon2FA Phishing Platform

Microsoft DCU, Europol, and industry partners disrupted Tycoon2FA, one of the most widespread phishing-as-a-service platforms since August 2023. Tycoon2FA (operated by Storm-1747) enabled tens of millions of phishing messages reaching 500,000+ organizations monthly across all sectors including education, healthcare, finance, non-profit, and government. The platform provided adversary-in-the-middle (AiTM) capabilities allowing less-skilled actors to bypass MFA by intercepting session cookies during authentication while simultaneously capturing credentials. Likely rose in popularity after disruptions of Caffeine and RaccoonO365 phishing services. Platform features included mimicking Microsoft 365, OneDrive, Outlook, SharePoint, and Gmail sign-in pages, anti-bot screening, browser fingerprinting, heavy obfuscation, self-hosted CAPTCHAs, custom JavaScript, and dynamic decoy pages. Pricing started at $120 for 10 days, $350 monthly. Lures distributed via phishing emails containing SVG, PDF, HTML, or DOCX files, often with embedded QR codes or JavaScript. Captured session tokens allowed persistent access even after password resets unless active sessions were explicitly revoked.

Cloudflare: Attackers Weaponizing Cloud Infrastructure at Scale

Cloudflare's inaugural threat report identifies attackers turning victim-deployed cloud services into "attack factories" with industrialized exploitation of platform weaknesses. Attackers routinely exploit public cloud resources to blend with legitimate traffic, provision operational infrastructure, and bypass email protections. Identity-based attacks achieve the same outcomes as complex malware or zero-days by exploiting blind spots in cloud interconnections. The everything-as-a-service model creates interconnected systems with numerous entry points, making components nearly as accessible to attackers as legitimate users. Cloudflare argues the industry should focus on attacker "effectiveness" (effort-to-outcome ratio) rather than sophistication. The Salesloft Drift incident last summer exemplified supply chain risks, impacting Cloudflare and 700+ companies through a third-party AI agent's Salesforce connection. Trusted relationships between interconnected services need greater scrutiny as data exposure becomes "almost infinite" without visibility into third-party data flows.

LastPass Phishing Campaign Using Fake Support Email Threads

LastPass warns of phishing campaign using fake unauthorized access alerts impersonating LastPass support. Emails spoof display names and use subject lines mimicking forwarded internal conversations about email address change requests. Fake email chains reference "report suspicious activity," "disconnect and lock vault," and "revoke device" actions directing users to phishing pages on verify-lastpass[.]com and variations. Multiple sender addresses from compromised websites or abandoned domains hide behind 'LastPass Support' display name. No LastPass infrastructure compromise. Support agents never ask for master passwords. LastPass working with partners to take down fake sites. This is the fourth major LastPass phishing campaign since late 2025, following fake maintenance notifications (January), fake user death claims, and fake breach notifications.

LeakBase Data Trading Forum Seized in Global Operation

Europol coordinated international operation dismantled LeakBase, a major forum specializing in stolen databases and stealer logs (credentials harvested via infostealer malware). Accessible on the open web in English, the platform combined forum and discussion board elements enabling cybercriminals to buy, sell, and exchange compromised data. Between March 3-4, coordinated actions across multiple jurisdictions included arrests, house searches, and knock-and-talk interventions. Around 100 enforcement actions conducted worldwide, targeting 37 most active users. March 3 saw arrests and searches, March 4 included domain seizure with law enforcement splash page. Operation now in prevention phase to deter further criminal activity.

FreeScout Mail2Shell Zero-Click RCE Vulnerability

Maximum severity vulnerability in FreeScout helpdesk platform allows remote code execution without user interaction or authentication. FreeScout is a self-hosted customer support platform. No CVE details provided in article.

Windows / AD Security

Bitwarden Adds Passkey Login Support for Windows 11

Bitwarden announced support for passkey-based Windows 11 authentication, enabling phishing-resistant login using passkeys stored in the Bitwarden vault. Available for all plans including free tier. Users log into Windows by selecting security key option and scanning QR code with mobile device to confirm passkey access. Requirements: Entra ID-joined devices, FIDO2 security key sign-in enabled, registered Entra ID passkey in Bitwarden vault. Bitwarden acts as passkey provider in Windows authentication flow, storing credentials in synced vault rather than binding to single device. Enables recovery via other devices if phone is lost. Removes password entry from login process, using cryptographic challenges signed with private keys. Microsoft rolling out passkey login on Windows this month depending on Entra ID configuration. This extends November 2025 passkey provider API announcement that allowed third-party apps to manage passkeys for websites and apps, now reaching OS-level authentication.

General Security News

Kaspersky Dismisses Claims Coruna iPhone Exploit Kit is NSA-Linked

Kaspersky disputes claims that Coruna iPhone exploit kit disclosed by Google is connected to Operation Triangulation, which Moscow alleged was an NSA campaign. After Google's Threat Intelligence Group published Coruna findings, some experts suggested NSA involvement based on overlap with vulnerabilities used in 2023's Operation Triangulation targeting Russian diplomats. Rocky Cole (iVerify cofounder) told Wired the kit is "highly sophisticated, took millions of dollars to develop, and it bears the hallmarks of other modules that have been publicly attributed to the US government." Kaspersky principal security researcher Boris Larin stated: "We see no evidence of actual code reuse in the published reports to support attributing Coruna to the same authors." Google first tracked Coruna in February 2025 after capturing parts of an iOS exploit chain from a surveillance company customer. The kit comprises 23 distinct vulnerabilities targeting iOS 13-17.2.1 (September 2019 to December 2023) across five unique full exploit chains. Most advanced exploits use non-public techniques bundled into novel JavaScript frameworks. Seen in campaigns targeting Ukrainian websites (industrial equipment, local services, ecommerce) in summer 2025, delivered via hidden iFrames to selected iPhone users from specific geolocations. Also hosted on fake Chinese finance and cryptocurrency websites encouraging iOS device visits. CVE-2020-27932, CVE-2023-32434, CVE-2024-23222, and CVE-2023-38606 all on CISA KEV list. Suggests active market for second-hand zero-days catering to well-resourced buyers.

APT28 Campaign Deploys BadPaw Loader and MeowMeow Backdoor in Ukraine

Russian APT28-linked campaign targeting Ukrainian entities with two undocumented malware families: BadPaw and MeowMeow. Attack chain initiates with phishing email containing link to ZIP archive. Extracted HTA file displays Ukrainian-language lure document about border crossing appeals.

Patch Priority

Vulnerability Disclosures

Windows 10 KB5075039 Fixes Broken Recovery Environment

Microsoft released KB5075039 Windows Recovery Environment update for Windows 10 fixing issue preventing WinRE startup. October 2025 KB5068164 update broke WinRE, disclosed in February 2026. WinRE partition must be at least 256MB for installation. If smaller, partition must be resized using Microsoft instructions. Always back up data before resizing partitions including WinRE.

Microsoft Security Update Guide CVE Disclosures

Microsoft published multiple CVE disclosures today with minimal detail:

No severity scores or detailed descriptions provided. EPSS scores range from 1st to 20th percentile, indicating low observed exploitation probability.

Trends & Context

Today's threat landscape shows the convergence of sophisticated platform abuse with commodity attack techniques. Tycoon2FA's disruption demonstrates how phishing-as-a-service platforms enable MFA bypass at massive scale, while Cloudflare's report confirms attackers systematically weaponizing cloud infrastructure rather than developing complex malware. Cisco's SD-WAN exploitation highlights continued targeting of network infrastructure for persistent access. The Phobos guilty plea and LeakBase seizure show law enforcement making progress against ransomware operators and data trading ecosystems, though the $39M in Phobos payments demonstrates the financial incentives remain strong.