← Carolina Clear Tech

Cyber Threat Brief

2026-03-12

Listen to this brief (22:04)

Download MP3
Show Notes

Show Notes - 2026-03-12

Stories Covered

CVEs Referenced

CVE-2025-68613, CVE-2026-1965, CVE-2026-23239, CVE-2026-23240, CVE-2026-23868, CVE-2026-25679, CVE-2026-27493, CVE-2026-27495, CVE-2026-27497, CVE-2026-27577, CVE-2026-3537, CVE-2026-3783, CVE-2026-3784

Read the full brief

Get tomorrow's brief in your inbox

Protect Your Business

Need a security assessment? See our cybersecurity packages.

View Services

Daily Cyber Threat Brief - March 12, 2026

Today: CISA adds actively exploited n8n RCE flaw to KEV catalog with 24,700+ instances still exposed online. Stryker hit by Iranian wiper attack that stole 50 TB before destroying systems. New n8n sandbox bypass vulnerabilities allow attackers to steal every credential in the database. Federal agencies have until March 25 to patch.

Critical Alerts

CISA Adds n8n RCE Vulnerability to KEV Catalog (CVE-2025-68613)

CVE-2025-68613 is a critical expression injection vulnerability in n8n's workflow automation platform that allows authenticated attackers to execute arbitrary code with n8n process privileges. CISA added this to the Known Exploited Vulnerabilities catalog on March 11 based on evidence of active exploitation. The flaw has a CVSS score of 9.9, EPSS score of 0.790 (99th percentile), and affects the workflow expression evaluation system. Successful exploitation leads to full instance compromise, including access to sensitive data stored in n8n such as API keys, database credentials, OAuth tokens, cloud storage credentials, and CI/CD secrets. Shadowserver tracks over 24,700 unpatched instances exposed online, with 12,300+ in North America and 7,800+ in Europe.

Additional n8n Critical Vulnerabilities Allow Credential Theft

Pillar Security disclosed four additional critical n8n vulnerabilities that enable remote code execution and credential theft. CVE-2026-27577 (CVSS 9.4) is a sandbox escape in the expression compiler where a missing AST rewriter case allows process to slip through untransformed, granting authenticated users full RCE. CVE-2026-27493 (CVSS 9.5) is an unauthenticated expression evaluation flaw via Form nodes that requires no authentication and can be exploited by submitting a payload through public forms like "Contact Us." When chained with CVE-2026-27577, attackers can read the N8N_ENCRYPTION_KEY environment variable and decrypt every credential in the database, including AWS keys, database passwords, OAuth tokens, and API keys. CVE-2026-27495 (CVSS 9.4) is a code injection in the JavaScript Task Runner sandbox. CVE-2026-27497 (CVSS 9.4) affects the Merge node's SQL query mode, enabling arbitrary code execution and file writes.

Ransomware Claims (Last 48h)

7 claims tracked across 5 groups in the last 48 hours. These are unverified claims from ransomware leak sites, not confirmed breaches.

Group Victim Sector Country
Space Bears AbelZeta Pharmaceuticals China
Medusa Chartre Consulting Professional Services United States
Clop AIGHEALTHCARE.IN Healthcare India
Clop CLOUD.CLEARWAYGROUP.COM IT Services Unknown
Nasir Security (Mission Announcement) N/A N/A
CipherForce TCT Broadband Solutions Telecommunications Unknown
CipherForce Telcom Live Content Inc Media Unknown

Ransomware & Extortion

INC Ransomware Targets Healthcare in Oceania

INC ransomware group has conducted sustained attacks against healthcare infrastructure in Australia, New Zealand, and Tonga. Government agencies, emergency clinics, and medical facilities across Oceania have experienced serious incidents attributed to this prolific ransomware outfit. The campaign demonstrates INC's focus on high-impact targets in the healthcare vertical.

Handala Claims Destructive Attack on Medical Device Maker Stryker

Iranian-linked hacktivist group Handala claimed responsibility for a wiper malware attack on U.S. medical device manufacturer Stryker. The attack caused system disruptions and access limitations across the Michigan-based company's global operations. Handala claims to have stolen 50 TB of data before deploying wiper malware across tens of thousands of systems and servers. Stryker filed an SEC disclosure stating no indication of ransomware or malware, but Handala's Telegram posts and employee social media reports show the group's logo on company login pages. Stryker has 56,000 employees and operates in 61 countries. The company stated the incident is contained but provided no timeline for full restoration. Phone calls to global headquarters were met with a recording citing a "building emergency."

52% of U.S. School Districts Hit by Cybersecurity Incidents in 2025

Clever's Cybersecure 2026 Report found that 52% of U.S. school districts experienced a cybersecurity incident in 2025, up from 36% in 2024 and 31% in 2023. The survey of nearly 500 K-12 administrators and technology professionals shows cybersecurity incidents have become a persistent operating condition for school systems. These incidents translate to disrupted lessons, locked learning apps, and compromised student personal data.

Business & Infrastructure Threats

Contagious Interview Campaign Targets Developers with Malware

Microsoft Defender Experts documented the Contagious Interview campaign, a sophisticated social engineering operation active since December 2022 targeting software developers at enterprise solution providers and media firms. Threat actors pose as recruiters from cryptocurrency trading firms or AI solution providers and persuade victims to clone and execute malicious NPM packages hosted on GitHub, GitLab, or Bitbucket during fake technical interviews. Recent attacks abuse Visual Studio Code workflows by prompting victims to trust the repository author, which auto-executes the repository's task configuration file and loads backdoor payloads. The campaign deploys Invisible Ferret (Python-based backdoor), FlexibleFerret (Go/Python modular backdoor), and BeaverTail (information stealer). FlexibleFerret uses encrypted HTTP(S) and TCP C2 channels, plugin-based architecture, RUN registry persistence, and includes reconnaissance and lateral movement capabilities.

PhantomRaven NPM Supply Chain Campaign Resurges with 88 Malicious Packages

A new wave from the PhantomRaven supply-chain campaign is hitting the npm registry with 88 malicious packages designed to exfiltrate sensitive data from JavaScript developers. The packages target developer credentials, environment variables, and source code. This represents a sustained supply chain threat against the JavaScript ecosystem.

Polyfill Supply Chain Attack Linked to North Korea

The 2024 polyfill supply chain attack that impacted over 100,000 websites has been linked to North Korean threat actors. Initial attribution pointed to China, but analysis of an infostealer infection revealed North Korean involvement. The polyfill attack injected malicious JavaScript into hundreds of thousands of websites that relied on the compromised polyfill.io CDN service.

Windows / AD Security

CVE-2026-23240: TLS Race Condition in Windows

Microsoft published CVE-2026-23240, a race condition in the tls_sw_cancel_work_tx() function. EPSS score is 0.000 (4th percentile), suggesting low exploitation probability at this time. No additional details or patches are publicly available yet.

Multiple Microsoft CVE Disclosures (CVE-2026-25679, CVE-2026-23868, CVE-2026-3783, CVE-2026-23239, CVE-2026-1965, CVE-2026-3784)

Microsoft published information for six CVEs with minimal details. CVE-2026-25679 involves incorrect parsing of IPv6 host literals in net/url. CVE-2026-3783 is a token leak with redirect and netrc. CVE-2026-23239 is a race condition in espintcp_close(). CVE-2026-1965 affects HTTP Negotiate connection reuse. CVE-2026-3784 involves wrong proxy connection reuse with credentials. All have low EPSS scores (0.000 to 0.001), indicating minimal active exploitation.

General Security News

FBI Epstein Files Compromised by Foreign Hacker in 2023

A foreign hacker compromised files relating to the FBI's Jeffrey Epstein investigation during a 2023 break-in at the bureau's New York Field Office. The breach occurred after a server at the Child Exploitation Forensic Lab was inadvertently left vulnerable by Special Agent Aaron Spivack while navigating complex procedures for handling digital evidence. The intrusion happened on February 12, 2023, according to Spivack's timeline included in recently released Epstein documents.

Atlassian Lays Off 10% of Workforce, Cites AI Skill Mix Changes

Atlassian announced plans to shed 10% of staff (approximately 1,600 people), with CEO Mike Cannon-Brookes citing AI's impact on required skill mix and organizational structure. The company is "reshaping our skill mix and changing how we work to build for the future" to self-fund AI and enterprise sales investment. Atlassian's market cap peaked at $112 billion in 2021 but fell to around $20 billion currently. The company has been included in the "SaaSpocalypse" list of SaaS companies threatened by organizations replacing them with AI-coded tools.

Microsoft Adds Xbox Mode to Windows 11

Microsoft announced Xbox mode coming to Windows 11 PCs in April, bringing a controller-optimized Xbox experience to laptops, desktops, and tablets in select markets. The feature allows seamless switching between Xbox and Windows desktop modes. While likely excluded from Windows Professional editions, consumer-grade PCs and BYOD schemes may introduce Xbox-capable devices into business environments.

UK Launches Online Crime Centre to Combat Fraud

The UK government unveiled a new fraud strategy creating an Online Crime Centre backed by over £30 million ($40.3 million), launching next month. The disruption hub brings together government agencies (National Crime Agency, GCHQ) and private sector partners from financial, telecom, and technology sectors to share data, identify criminal infrastructure, and shut down scam operations at scale. The center will block scam text messages, freeze accounts, and remove fraudulent social media profiles.

Patch Priority

Vulnerability Disclosures

SQL Injection in Elementor Ally WordPress Plugin

An unauthenticated SQL injection vulnerability affects the Ally web accessibility plugin from Elementor, installed on over 250,000 WordPress sites. The flaw allows attackers to steal sensitive data from the database without authentication. No CVE has been assigned yet.

Chromium CVE-2026-3537: Object Lifecycle Issue in PowerVR

Microsoft published CVE-2026-3537 affecting Chromium-based Edge browsers. The vulnerability is an object lifecycle issue in PowerVR with EPSS score of 0.001 (24th percentile). Microsoft Edge ingests Chromium patches that address this flaw.

Six Android Malware Families Target Pix Payments and Banking Apps

Researchers identified six new Android malware families including PixRevolution, TaxiSpy RAT, BeatBanker, Mirax, Oblivion RAT, and SURXRAT. The malware ranges from traditional banking trojans to full remote administration tools capable of data theft, financial fraud, and device control. PixRevolution specifically targets Pix payment systems popular in Brazil.

AI Browser Phishing: Perplexity's Comet Tricked in Under Four Minutes

Researchers demonstrated that agentic AI browsers like Perplexity's Comet can be tricked into falling for phishing scams in under four minutes. The attack exploits the AI browser's tendency to reason actions and uses that reasoning against the model to lower security guardrails. This represents a new class of vulnerabilities specific to AI-powered autonomous browsing agents.

Trends & Context

Today's headlines are dominated by critical n8n vulnerabilities under active exploitation. With over 24,700 exposed instances and multiple chained RCE paths that allow full credential database decryption, this is a top priority for organizations using workflow automation tools. The Stryker wiper attack demonstrates Iran-linked groups continue to target critical infrastructure with destructive malware. Supply chain attacks remain a persistent threat, with PhantomRaven targeting npm and North Korean operators compromising polyfill CDN infrastructure. Developer-focused social engineering campaigns like Contagious Interview show threat actors adapting recruitment processes into malware delivery workflows.