CVE-2021-22054, CVE-2025-24893, CVE-2025-26399, CVE-2025-55182, CVE-2026-0628, CVE-2026-1492, CVE-2026-1603, CVE-2026-21385, CVE-2026-22719
Domains:
trackpipe[.]dev
Get tomorrow's brief in your inbox
Today: CISA adds three actively exploited vulnerabilities (SolarWinds, Ivanti, VMware), federal agencies have until March 12 to patch. ShinyHunters claims mass exploitation of Salesforce Experience Cloud misconfigurations, targeting 300-400 companies. Qualcomm chipset zero-day under active attack in Android devices.
CISA Adds SolarWinds Web Help Desk, Ivanti EPM, and VMware Workspace One to KEV Catalog
CISA flagged three actively exploited vulnerabilities requiring immediate patching. CVE-2025-26399 (CVSS 9.8) is a deserialization vulnerability in SolarWinds Web Help Desk that allows unauthenticated remote code execution. Microsoft and Huntress report exploitation by the Warlock ransomware crew. CVE-2026-1603 (CVSS 8.6) is an authentication bypass in Ivanti Endpoint Manager that leaks stored credentials. CVE-2021-22054 (CVSS 7.5) is an SSRF vulnerability in VMware Workspace One UEM that provides unauthenticated access to sensitive information. GreyNoise observed exploitation in March 2025 as part of a coordinated SSRF campaign.
Qualcomm Zero-Day Under Active Exploitation (CVE-2026-21385)
A high-severity buffer over-read vulnerability in Qualcomm chipsets (CVSS 7.8) is being exploited in the wild. The flaw affects the Graphics component and can cause memory corruption and arbitrary code execution. Google confirmed limited, targeted exploitation in Android devices. CISA added it to the KEV catalog with a March 24, 2026 remediation deadline. Affected chipsets are widely used in Android phones, tablets, and IoT devices.
Five claims tracked across 3 groups in the last 48 hours. These are unverified claims from ransomware leak sites, not confirmed breaches.
| Group | Victim | Sector | Country |
|---|---|---|---|
| Secp0 | Mike Brandner Law | Legal Services | Unknown |
| Secp0 | Richmond Plywood Corporation Limited | Manufacturing | Unknown |
| Secp0 | Indigo Group | Various | Unknown |
| Secp0 | JM Bozeman Enterprises | Unknown | Unknown |
| Interlock | Wagon Mound Public Schools | Education | USA |
| Embargo | NCH Corporation | Industrial Solutions | Global |
AkzoNobel Paint Manufacturer Hit by Anubis Ransomware
Netherlands-based global paint manufacturer AkzoNobel confirmed a cyberattack affecting one of its United States sites. The company contained the intrusion, but the Anubis ransomware group claims to have stolen 170 GB of data, including employee and financial records. The incident follows the Tycoon2FA and LeakBase infrastructure takedowns, which disrupted major phishing-as-a-service platforms but are expected to create only short-term disruptions as the ecosystem migrates to other channels.
LexisNexis Breach Exposes 3.9 Million Records
Global legal data and analytics provider LexisNexis suffered a breach with attackers claiming theft of 3.9 million records, including approximately 400,000 user profiles and some government accounts. The company stated that exposed systems mainly held legacy pre-2020 data. The breach highlights risks to organizations maintaining large archives of legacy data without adequate security controls.
EV Charger Company ELECQ Hit by Ransomware
ELECQ, a maker of smart electric vehicle chargers, warned customers that ransomware attackers encrypted and copied data from its AWS cloud platform on March 7. The compromised data includes customer names, email addresses, phone numbers, and home addresses. No financial data or payment records were exposed, and charging devices remain secure. The company has shut down SSH and Telnet remote access and reported the incident to UK and German regulators. The ransomware gang has not been identified.
BlackBasta Evolution: A0Backdoor Malware Campaign
Hackers contacted employees at financial and healthcare organizations over Microsoft Teams to deploy A0Backdoor malware. The attack uses social engineering (inbox spam followed by fake IT support contact), remote access via Quick Assist, and digitally signed malicious MSI files hosted in Microsoft cloud storage. The malware uses DLL sideloading and DNS MX-based C2 communication to evade detection. BlueVoyant assesses with moderate-to-high confidence that this is an evolution of BlackBasta ransomware tactics, though the group has dissolved after internal chat logs leaked.
ShinyHunters Claims Mass Salesforce Experience Cloud Data Theft
ShinyHunters claims to have exploited Salesforce Experience Cloud misconfigurations in 300-400 companies, including 100 high-profile targets in the cybersecurity sector. Salesforce warns that attackers are using a modified version of Mandiant's AuraInspector tool to scan for misconfigured guest user profiles with excessive permissions. The campaign targets the /s/sfsites/aura endpoint to extract sensitive CRM data without authentication. Salesforce states this is a configuration issue, not a platform vulnerability. ShinyHunters says exploitation began in September 2025.
Google: Cloud Attacks Exploit Flaws More Than Weak Credentials
Google reports that bug exploits are now the primary cloud access vector in 44.5% of intrusions, while credentials account for 27%. The exploitation window has collapsed from weeks to 48 hours. React2Shell (CVE-2025-55182) and XWiki (CVE-2025-24893) are the most exploited vulnerabilities. State-sponsored actors from Iran and China maintain access for 18+ months using stolen VPN credentials and malware. North Korean threat actor UNC4899 stole millions in cryptocurrency after tricking a developer into downloading a malicious archive posing as an open-source project.
Ericsson US Discloses Data Breach After Service Provider Hack
Ericsson Inc. disclosed that attackers stole employee and customer data after hacking a third-party service provider between April 17-22, 2025. The breach impacted 4,377 individuals in Texas alone and exposed names, addresses, Social Security Numbers, Driver's License numbers, government IDs, financial account numbers, medical information, and dates of birth. The service provider completed its investigation on February 23, 2026. No cybercrime group has claimed responsibility.
TriZetto Provider Solutions Healthcare Breach Affects 3.4 Million
TriZetto Provider Solutions, a Cognizant-owned healthcare technology company, disclosed a breach affecting more than 3.4 million people. Exposed data includes insurance and medical information. Investigators determined unauthorized access began in 2024. Notifications were issued in early March 2026. This breach adds to ongoing concerns about healthcare sector security, with HHS listing over 750 reported breaches under investigation as of January 2026.
Malicious npm Package Posing as OpenClaw Installer
A malicious npm package named "@openclaw-ai/openclawai" masquerades as an OpenClaw installer to deploy GhostLoader RAT and steal macOS credentials. The package was downloaded 178 times and remains available as of March 10. It harvests system passwords via fake iCloud Keychain prompts, steals browser data, crypto wallets, SSH keys, Apple Keychain databases, iMessage history, and developer credentials (AWS, Azure, GCP). Data is exfiltrated via C2 server (trackpipe[.]dev), Telegram Bot API, and GoFile.io.
FBI Warns of Phishing Attacks Impersonating US City Officials
The FBI warns that criminals are impersonating city and county planning and zoning officials to target businesses and individuals requesting land-use permits. Phishing messages cite permit information, zoning application numbers, and property addresses, and demand wire transfer or cryptocurrency payments for permit fees. Indicators include non-governmental sender domains (e.g., @usa.com) and pressure tactics to avoid permit delays.
Microsoft Agent 365 Launches Control Plane for AI Agents
Microsoft announced Agent 365 and Microsoft 365 E7 (The Frontier Suite), generally available May 1, 2026. Agent 365 provides a unified control plane for observing, governing, and securing AI agents across Microsoft and partner platforms. Key capabilities include Agent Registry (inventory of all agents), behavior and performance observability, risk signals across Defender/Entra/Purview, and security policy templates. E7 costs $99 per user per month and includes E5, Copilot, and Agent 365. Gartner criticized the 13.2% discount as insufficient and called Agent 365 "a work in progress with limited net new functionality."
Microsoft Teams Will Tag Third-Party Bots in Lobbies
Microsoft Teams will automatically tag third-party bots in lobbies starting May 2026, requiring organizers to explicitly admit them. The feature prevents bots from being accidentally accepted alongside human attendees. This follows earlier fraud-protection updates including external caller warnings and the ability for admins to block external Teams users via the Defender portal.
Russian State Hackers Hijack Signal and WhatsApp Accounts
Dutch intelligence agencies (MIVD and AIVD) report Russian state-sponsored hackers are targeting government officials, military personnel, and journalists via Signal and WhatsApp phishing campaigns. Attackers impersonate fake Signal Security Support Chatbots to harvest SMS codes and PINs, then register accounts on attacker-controlled devices. A second method abuses device linking via malicious QR codes. Once compromised, attackers can change the phone number associated with the account and monitor incoming messages, including group chats. Victims can re-register with the same number but may not realize their account is still compromised.
Anthropic Finds 22 Vulnerabilities in Firefox Using Claude Opus
Anthropic discovered 22 new security vulnerabilities in Firefox using its Claude Opus 4.6 model during a two-week security partnership with Mozilla in January 2026. The vulnerabilities include 14 high, 7 moderate, and 1 low severity issues. All were addressed in Firefox 148 released in late January. Anthropic noted that identifying vulnerabilities with AI is cheaper than creating exploits, and the model is better at finding issues than exploiting them.
Wikipedia Hit by Self-Propagating JavaScript Worm
The Wikimedia Foundation faced a self-propagating JavaScript worm that vandalized pages and replaced editor scripts across multiple wikis. Engineers briefly restricted editing while cleaning up the incident. Approximately 3,996 pages were modified and roughly 85 users' personal scripts were affected. The incident highlights risks of cross-site scripting in collaborative editing platforms.
AI-Themed Browser Extensions Harvest LLM Chat Histories
Researchers uncovered AI-themed Chrome and Edge extensions distributed via the Chrome Web Store that harvest LLM chat histories and browsing activity. The extensions impersonate legitimate tools and have impacted 900,000 users across 20,000 enterprise environments. This campaign demonstrates the growing threat surface created by AI adoption.
Pakistan APT36 Uses AI Coding Tools to Generate Malware
Pakistan-linked APT36 has used AI coding tools to produce large volumes of low-quality malware aimed at Indian government entities and embassies. The group generates variants in less common programming languages and uses legitimate cloud services for command channels, complicating detection and response.
VMware Aria Operations Command Injection (CVE-2026-22719)
VMware patched a high-severity command injection flaw in Aria Operations cloud management platform. The vulnerability allows unauthenticated remote code execution during support-assisted migrations. Affected versions include 8 through 8.18.5 and 9 through 9.0.1. Patches and a workaround script are available. CISA added this to the KEV catalog with a March 24 remediation deadline.
WordPress User Registration Plugin RCE (CVE-2026-1492)
A critical (CVSS 9.8) privilege escalation flaw in the User Registration & Membership WordPress plugin allows unauthenticated attackers to create administrator accounts and take over sites. A patch has been released.
Google Chrome Gemini AI Panel Vulnerability (CVE-2026-0628)
Google patched a high-severity vulnerability in Chrome's Gemini AI panel that allowed malicious extensions to inject code and access cameras, microphones, local files, and launch phishing content. Researchers demonstrated that attackers could take screenshots and access sensitive data inside the panel.
This week demonstrates the shrinking window for exploitation of disclosed vulnerabilities, with attackers weaponizing flaws within 48 hours. The shift from credential-based to exploit-based cloud attacks reflects improved security controls forcing threat actors to adapt. The convergence of AI and cybersecurity is creating new attack surfaces (AI-themed extensions, malicious npm packages) while also improving defensive capabilities (Anthropic finding Firefox bugs). State-sponsored actors continue to demonstrate sophisticated social engineering, from Teams phishing to Signal account takeovers, requiring heightened user awareness alongside technical controls.