CVE-2022-20775, CVE-2025-68146, CVE-2026-20122, CVE-2026-20127, CVE-2026-20128, CVE-2026-2796
Get tomorrow's brief in your inbox
Today: Cisco confirms active exploitation of two more SD-WAN flaws while federal agencies face a March 26 deadline to patch iOS vulnerabilities used in crypto-theft and surveillance attacks. Genesis ransomware posted eight new victim claims including healthcare providers and municipal governments, and Microsoft warns North Korean IT workers are scaling AI-powered identity fraud to infiltrate organizations worldwide.
Cisco SD-WAN Vulnerabilities Under Active Attack (CVE-2026-20122, CVE-2026-20128)
Cisco confirmed active exploitation of two vulnerabilities in Catalyst SD-WAN Manager this week. CVE-2026-20122 (CVSS 7.1, EPSS 0.000/13th percentile) allows authenticated remote attackers to overwrite arbitrary files on the local filesystem. CVE-2026-20128 (CVSS 5.5, EPSS 0.000/5th percentile) permits authenticated local attackers to gain Data Collection Agent privileges. These join CVE-2022-20775 (CISA KEV, due date passed Feb 27, EPSS 0.005/66th percentile) and CVE-2026-20127 (maximum severity, CISA KEV due Feb 27, EPSS 0.026/85th percentile) as actively exploited SD-WAN flaws. Five Eyes agencies warned last week that attackers are compromising SD-WAN deployments to add malicious rogue peers, achieve root access, and maintain persistence. Cisco Talos links exploitation to UAT-8616, a highly sophisticated threat actor possibly active since 2023.
iOS Exploits Used in Coruna Surveillance and Crypto-Theft Campaign
CISA added three iOS vulnerabilities to the Known Exploited Vulnerabilities catalog after Google Threat Intelligence Group discovered the Coruna exploit kit targeting 23 iOS flaws across iOS 13 through iOS 17.2.1. The kit provides Pointer Authentication Code bypass, sandbox escape, and Page Protection Layer bypass capabilities to achieve WebKit remote code execution and kernel privileges. Multiple threat actors deployed Coruna in 2025: a surveillance vendor customer, suspected Russian state-backed group UNC6353 targeting Ukrainian websites, and financially motivated Chinese actor UNC6691 operating fake gambling and crypto sites to steal cryptocurrency wallets. Federal agencies must patch by March 26 per BOD 22-01. The exploits fail on recent iOS versions, private browsing mode, and when Lockdown Mode is enabled.
Eight claims tracked across Genesis ransomware group from March 6-7. These are unverified claims from ransomware leak sites, not confirmed breaches.
| Group | Victim | Sector | Country |
|---|---|---|---|
| Genesis | Griswold Controls | Manufacturing (HVAC/Irrigation) | US |
| Genesis | NADAP | Non-Profit | US |
| Genesis | City of Hart | Government (Municipal) | US |
| Genesis | Brighton Eye | Healthcare | US |
| Genesis | Cornerstone Financial Advisors | Finance/Accounting | US |
| Genesis | Sanders Legal Group | Legal Services | US |
| Genesis | OneSource Medical Group | Healthcare | US |
| Genesis | Sierra Management Group | Healthcare | US |
Additional claims observed: Chaos group posted Nelson Worldwide (architecture/design), Everest group posted Hyundai Elevator.
Global Law Enforcement Disrupts Tycoon2FA, LeakBase, and Phobos
Europol disrupted Tycoon2FA phishing-as-a-service platform in an international operation, seizing 330 domains hosting phishing pages. Active since 2023, Tycoon2FA sent tens of millions of phishing emails monthly, enabling attackers to bypass multi-factor authentication using adversary-in-the-middle techniques capturing credentials and session cookies. The service sold for approximately $120 through Telegram. In a separate operation, the FBI and Europol took down LeakBase cybercrime forum with 142,000 members, seizing domains and preserving all forum data including accounts, messages, and IP logs. Russian national Evgenii Ptitsyn pleaded guilty to wire fraud conspiracy for running Phobos ransomware, which targeted over 1,000 organizations since 2020, collecting more than $39 million in ransom payments. Ptitsyn faces up to 20 years at sentencing on July 15.
InstallFix Social Engineering Delivers Amatera Stealer via Fake Claude Code Install Guides
Threat actors are using a new ClickFix variant called InstallFix to distribute malware through cloned installation pages for popular CLI tools. Push Security discovered fake Claude Code documentation pages promoted via Google Ads malvertising that deliver malicious install commands for macOS and Windows. The pages clone legitimate Anthropic branding and layout while serving Amatera Stealer from attacker-controlled endpoints. Attackers host these sites on legitimate platforms including Cloudflare Pages, Squarespace, and Tencent EdgeOne for evasion. BleepingComputer confirmed malicious sponsored search results still appear for queries like "install claude code" and "Claude Code CLI." Amatera is a subscription-based malware-as-a-service derived from ACR Stealer that collects passwords, cookies, session tokens, cryptocurrency wallets, and system information.
Multi-Stage VOID#GEIST Malware Campaign Delivers XWorm, AsyncRAT, and Xeno RAT
Securonix disclosed a multi-stage malware campaign using obfuscated batch scripts to deploy encrypted remote access trojans. The campaign begins with phishing emails containing batch scripts fetched from TryCloudflare domains. The scripts display decoy PDFs while launching PowerShell to re-execute hidden batch scripts, establish persistence via Startup directory, and download ZIP archives containing Python-based loaders and encrypted shellcode payloads. The attack deploys a legitimate embedded Python runtime from python.org to execute runn.py, which decrypts and injects shellcode for XWorm, AsyncRAT, and Xeno RAT directly into memory using Early Bird APC injection into explorer.exe. The fileless execution mechanism minimizes disk-based detection, with individual stages appearing harmless and resembling administrative activity.
Transparent Tribe Uses AI-Generated Malware to Target India
Pakistan-aligned APT group Transparent Tribe is using AI-powered coding tools to mass-produce malware implants in lesser-known programming languages including Nim, Zig, and Crystal. Bitdefender characterizes this as "vibe-coded malware" or "vibeware" designed to create a Distributed Denial of Detection effect by flooding environments with disposable polyglot binaries. Campaigns target Indian government entities, embassies, Afghan government, and private businesses via phishing emails with LNK files in ZIP/ISO archives or PDFs with download buttons. The infection chain deploys PowerShell scripts that download backdoors and adversary simulation tools including Cobalt Strike and Havoc. Custom tools include Warcode (Crystal shellcode loader), CreepDropper (.NET dropper), SHEETCREEP (Go infostealer using Microsoft Graph), MAILCREEP (C# backdoor using Google Sheets), SupaServ (Rust backdoor using Supabase/Firebase), LuminousStealer (Rust infostealer), CrystalShell (Discord C2 backdoor), and ZigShell (Slack C2 backdoor).
Cognizant TriZetto Breach Exposes 3.4 Million Patient Records
TriZetto Provider Solutions, a Cognizant-owned healthcare IT company, disclosed a data breach affecting 3.4 million individuals. Unauthorized access to a web portal began November 19, 2024, but was not detected until October 2, 2025, nearly a year later. Exposed data includes full names, addresses, dates of birth, Social Security numbers, Medicare beneficiary identifiers, health insurance member numbers, provider names, health insurer names, and demographic/health/insurance information from insurance eligibility verification transactions. Customer notification began in early February 2026. TriZetto states no payment card or bank account information was exposed and offers 12-month Kroll credit monitoring and identity protection to affected individuals.
North Korean IT Workers Scale AI-Powered Identity Fraud
Microsoft Threat Intelligence reports that North Korean threat actors tracked as Jasper Sleet and Coral Sleet are operationalizing AI to accelerate remote IT worker schemes. Groups use generative AI to draft phishing lures, translate content, summarize stolen data, generate and debug malware, and scaffold scripts and infrastructure. AI functions as a force multiplier reducing technical friction while human operators retain control over objectives, targeting, and deployment. Microsoft observed early experimentation with agentic AI supporting iterative decision-making and task execution. The company has disrupted thousands of accounts associated with fraudulent IT worker activity and partnered with industry and platform providers to mitigate misuse. Microsoft notes that while AI lowers barriers for attackers, it also strengthens defenders when applied at scale with appropriate safeguards.
Hamas-Linked Spyware Disguised as Emergency Alert App Targets Israeli Smartphones
Acronis Threat Research Unit discovered a malicious app impersonating the Red Alert rocket warning service distributed via SMS messages with spoofed sender IDs and bit.ly shortened links. The campaign likely links to Hamas-aligned group Arid Viper (APT-C-23, Desert Falcons, Two-tailed Scorpion) active since 2013. The trojanized app uses spoofed certificates and installer source to bypass Android security checks. The malware requests 20 permissions including GPS location, SMS messages, contact lists, device accounts, and automatic startup after reboot. It creates phishing overlays to intercept one-time passwords and credentials, then stages and transmits stolen data to attacker C2 servers. Israeli National Cyber Directorate and major news sites released warnings about the campaign.
Iran and Ukraine Weaponize Hacked Security Cameras for Military Targeting
Check Point released research describing hundreds of hacking attempts targeting consumer security cameras around the Middle East, many timed to Iran's recent missile and drone strikes on Israel, Qatar, and Cyprus. The Financial Times reported Israeli military accessed nearly all traffic cameras in Tehran and used them with CIA partnership to target the air strike killing Ayatollah Ali Khamenei. Ukrainian officials warn Russia has hacked consumer surveillance cameras to target strikes and spy on troop movements, while Ukrainian hackers hijack Russian cameras for surveillance. Check Point attributes Middle East camera-hacking efforts to a group previously linked to Iranian intelligence. Security researchers note that exploiting insecure networked civilian cameras has become standard military procedure, providing direct visibility without expensive satellite assets and often with better resolution.
FBI Investigating Suspicious Activity on System Holding Surveillance Information
The FBI is investigating suspicious cyber activity on a system containing sensitive surveillance information, according to notifications sent to members of Congress. The bureau is working to determine the scope and impact of the incident. No additional details about the nature of the compromise, data accessed, or attribution have been released.
CVE-2025-68146: Filelock TOCTOU Race Condition Allows Symlink Attacks
Microsoft Security Response Center published CVE-2025-68146 affecting the filelock Python library. The vulnerability is a time-of-check-time-of-use race condition during lock file creation that permits symlink attacks. EPSS score is 0.000 (0th percentile), indicating minimal observed exploitation activity.
Anthropic AI Discovers 22 Firefox Vulnerabilities
Anthropic disclosed that its Claude Opus 4.6 AI model discovered 22 security vulnerabilities in Firefox during a two-week partnership with Mozilla in January 2026. The findings include 14 high-severity, seven moderate, and one low-severity bugs, all patched in Firefox 148. The AI identified a use-after-free JavaScript bug in 20 minutes and scanned nearly 6,000 C++ files, submitting 112 unique reports. Anthropic tested exploit development by feeding Claude the vulnerability list and attempting automated exploit creation. Claude succeeded in developing crude exploits in only two cases out of several hundred attempts costing approximately $4,000 in API credits. One successful exploit targeted CVE-2026-2796 (CVSS 9.8, EPSS 0.001/17th percentile), a JIT miscompilation in JavaScript WebAssembly. The exploits only worked in testing environments with security features like sandboxing intentionally disabled. Mozilla reported the AI-assisted approach discovered 90 additional bugs, most fixed, including assertion failures and logic errors that fuzzers failed to catch.
Microsoft 365 Backup Adds File-Level Restore
Microsoft is rolling out granular restore capabilities for Microsoft 365 Backup, allowing administrators to restore individual files and folders from SharePoint and OneDrive restore points instead of performing full site or drive restores. The feature entered public preview in early March 2026 with general availability expected between late April and early May 2026. Administrators with the SharePoint Backup Administrator role can browse, search, and restore specific files or folders, reducing recovery time. The feature respects existing backup policies and does not impact end users.
Anthropic Sues US Government After National Security Designation
Anthropic filed a lawsuit against the US government after the Department of War (Department of Defense) designated the company a supply chain risk to national security on March 4. The designation, typically reserved for foreign adversaries, marks the first time a US company has been classified this way and bars Anthropic from securing military contracts. The conflict stems from Anthropic's refusal to remove safety guardrails preventing its AI from being used for fully autonomous weapons and domestic mass surveillance. President Trump ordered all federal departments to stop using Anthropic products. CEO Dario Amodei stated the company sees no choice but to challenge the decision in court, calling it legally unsound. OpenAI struck a deal with the Department of War hours after the Anthropic ban, claiming its agreement has more guardrails than Anthropic's previous partnership.
Trump Administration Releases Cybersecurity Strategy
The Trump administration released its long-awaited cybersecurity strategy along with an executive order on cybercrime and fraud. No additional details about the strategy's contents or policy priorities are available.
Firefox 148 Security Updates (22 CVEs)
Mozilla patched 22 vulnerabilities discovered by Anthropic's Claude Opus 4.6 AI model, including 14 high-severity, seven moderate, and one low-severity issue. CVE-2026-2796 (CVSS 9.8) is a JIT miscompilation in JavaScript WebAssembly. Additional 90 bugs were discovered through AI-assisted analysis, including assertion failures and logic errors.
YARA-X 1.14.0 Release
SANS Internet Storm Center reported YARA-X version 1.14.0 includes four improvements and two bugfixes. New features include a deps CLI command showing rule dependencies. The release continues development of the next-generation YARA malware identification and classification tool.
AI is reshaping both offensive and defensive security operations. Transparent Tribe demonstrates how threat actors use AI to mass-produce disposable malware variants in multiple languages, while Anthropic's Firefox vulnerability discovery shows AI accelerating defensive security research. North Korean IT workers leverage AI for identity fabrication and social engineering at scale, and consumer security cameras are becoming tactical military assets in armed conflicts. The FBI investigating suspicious activity on surveillance systems underscores the escalating targeting of intelligence infrastructure.