← Carolina Clear Tech

Cyber Threat Brief

2026-03-08

Listen to this brief (9:47)

Download MP3
Show Notes

Show Notes - 2026-03-08

Stories Covered

CVEs Referenced

CVE-2025-32988, CVE-2025-32989, CVE-2025-35430, CVE-2025-35431, CVE-2025-35432, CVE-2025-35433, CVE-2025-35434, CVE-2025-35435, CVE-2025-35436, CVE-2025-64175, CVE-2026-24881, CVE-2026-24882, CVE-2026-25242

Read the full brief

Get tomorrow's brief in your inbox

Protect Your Business

Need a security assessment? See our cybersecurity packages.

View Services

Cyber Threat Brief - 2026-03-08

Today: Velvet Tempest is linking ClickFix social engineering to Termite ransomware deployments through CastleRAT backdoor infrastructure. OpenAI's Codex Security found 10,561 high-severity vulnerabilities across major open-source projects including GnuPG and GnuTLS. Threat actors are scaling AI use across every attack stage, from phishing to malware debugging.

Ransomware & Extortion

Termite Ransomware Linked to ClickFix CastleRAT Campaigns

Velvet Tempest (DEV-0504), a ransomware affiliate active since 2018 with ties to Ryuk, REvil, Conti, BlackMatter, BlackCat, LockBit, and RansomHub, is now using ClickFix social engineering combined with Windows utilities to deploy DonutLoader malware and the CastleRAT backdoor. MalBeacon tracked the operation over 12 days in a replica environment with 3,000+ endpoints, observing hands-on-keyboard activity including Active Directory reconnaissance, credential harvesting from Chrome via PowerShell, and environment profiling. Initial access came through malvertising campaigns leading to fake CAPTCHA pages instructing victims to paste obfuscated commands into the Windows Run dialog. The commands triggered nested cmd.exe chains, used finger.exe to fetch loaders, and deployed components disguised as PDFs. Later stages used PowerShell to compile .NET components via csc.exe and establish Python-based persistence in C:\ProgramData, ultimately staging DonutLoader and retrieving the CastleRAT backdoor. While the observed intrusion did not deploy Termite ransomware, the PowerShell credential theft script was hosted on an IP linked to previous Termite operations targeting Blue Yonder and Genea.

Ransomware Claims (Last 48h)

1 claim tracked from worldleaks group in the last 48 hours. These are unverified claims from ransomware leak sites, not confirmed breaches.

Group Victim Sector Country
worldleaks Sagent Pharmaceuticals Pharmaceuticals US

General Security News

Microsoft: AI Being Weaponized Across Entire Attack Chain

Threat actors are integrating generative AI across all stages of cyberattacks to accelerate operations, scale malicious activity, and lower technical barriers. Microsoft Threat Intelligence observed AI being used for reconnaissance, phishing email drafting, content translation, stolen data summarization, malware debugging, infrastructure configuration, and post-compromise activities. North Korean groups Jasper Sleet (Storm-0287) and Coral Sleet (Storm-1877) use AI to generate realistic identities, resumes, and communications as part of remote IT worker schemes. Jasper Sleet prompts AI platforms to create culturally appropriate name lists and email formats, then uses AI to extract and summarize job posting requirements to tailor fake personas. Coral Sleet uses AI to generate fake company websites, provision infrastructure, and troubleshoot deployments. Threat actors are also using jailbreaking techniques to bypass LLM safeguards when generating malicious code. Microsoft is observing early experiments with agentic AI for autonomous task execution but notes AI is primarily used for decision-making support rather than fully autonomous attacks.

US Cyber Strategy Targets Adversaries and Emerging Technologies

The Trump administration released a new Cyber Strategy focused on stronger deterrence against cyber adversaries, modernization of federal networks, critical infrastructure protection, and investment in emerging technologies including AI and post-quantum cryptography. Details on specific implementation measures or timelines were not provided in the source content.

Patch Priority

Vulnerability Disclosures

OpenAI Codex Security Uncovers 10,561 High-Severity Issues Across Open-Source Projects

OpenAI launched Codex Security (evolution of Aardvark), an AI-powered security agent that scans codebases to identify vulnerabilities, validate findings, and propose fixes. Over 30 days of beta testing, Codex Security scanned 1.2 million commits across external repositories, identifying 792 critical and 10,561 high-severity findings. Vulnerabilities were discovered in GnuPG (CVE-2026-24881, CVE-2026-24882), GnuTLS (CVE-2025-32988, CVE-2025-32989), GOGS (CVE-2025-64175, CVE-2026-25242), and Thorium (CVE-2025-35430, CVE-2025-35431, CVE-2025-35432, CVE-2025-35433, CVE-2025-35434, CVE-2025-35435, CVE-2025-35436), among others including OpenSSH, libssh, PHP, and Chromium. All flagged CVEs have low EPSS scores ranging from 0.000 to 0.002 (0th to 39th percentile), indicating minimal current exploitation probability. The agent works in three stages: analyzing repository structure to build a threat model, identifying and classifying vulnerabilities based on real-world impact, and validating findings in sandboxed environments before proposing context-aware fixes. OpenAI reports false positive rates have declined by more than 50% across all scanned repositories. The feature is available in research preview to ChatGPT Pro, Enterprise, Business, and Edu customers with free usage for one month.

Trends & Context

AI is now embedded across the full attack lifecycle, not just in reconnaissance or phishing. Threat actors are using jailbreaking techniques to bypass LLM safety controls and generate malicious code, while also deploying AI to scale infrastructure provisioning and identity fabrication for insider threats. The volume of vulnerabilities discovered by AI-powered scanning tools like OpenAI Codex Security demonstrates both the scale of existing code security debt and the potential for AI to function as a force multiplier for defenders, provided false positive rates remain manageable.