← Carolina Clear Tech

Cyber Threat Brief

2026-03-13

Listen to this brief (28:05)

Download MP3
Show Notes

Show Notes - 2026-03-13

Stories Covered

CVEs Referenced

CVE-2025-13913, CVE-2025-27769, CVE-2025-40943, CVE-2025-55018, CVE-2025-62439, CVE-2025-62522, CVE-2025-64157, CVE-2025-68613, CVE-2026-21666, CVE-2026-21667, CVE-2026-21669, CVE-2026-21708, CVE-2026-21858, CVE-2026-2441, CVE-2026-24858, CVE-2026-25049, CVE-2026-28252, CVE-2026-28253, CVE-2026-28254, CVE-2026-28255, CVE-2026-28256, CVE-2026-3805, CVE-2026-3909, CVE-2026-3910

Indicators of Compromise

Domains: vpn-fortinet[.]com, ivanti-vpn[.]org.

Read the full brief

Get tomorrow's brief in your inbox

Protect Your Business

Need a security assessment? See our cybersecurity packages.

View Services

Daily Cyber Threat Brief

March 13, 2026

Today: Google patches two Chrome zero-days actively exploited in the wild. Veeam releases emergency fixes for seven critical RCE flaws in Backup & Replication that attackers will reverse-engineer immediately. CISA confirms n8n workflow automation platform is under active attack, and Telus Digital reports a breach affecting nearly 1 petabyte of BPO customer data.

Critical Alerts

Google Chrome Zero-Days (CVE-2026-3909, CVE-2026-3910)

Google patched two high-severity Chrome vulnerabilities exploited in zero-day attacks. CVE-2026-3909 is an out-of-bounds write in Skia (the graphics library) allowing browser crashes or code execution. CVE-2026-3910 is an inappropriate implementation bug in the V8 JavaScript engine. Google discovered both flaws and rolled out fixes for Windows (146.0.7680.75), macOS (146.0.7680.76), and Linux (146.0.7680.75) within two days of reporting. These are the second and third Chrome zero-days exploited this year, following CVE-2026-2441 (now on CISA KEV with a March 10 due date, EPSS 33rd percentile).

CISA KEV: n8n Workflow Platform (CVE-2025-68613)

CISA confirmed active exploitation of a 9.9 CVSS RCE vulnerability in n8n workflow automation platform. CVE-2025-68613 (EPSS 99th percentile) allows authenticated attackers to inject payloads into expressions that execute without validation. Successful exploitation leads to full instance compromise, unauthorized data access, workflow modification, and system-level code execution. First disclosed in December, Resecurity reported 103,000 of 230,000 active users were vulnerable. CISA set a March 25 deadline for federal agencies. The n8n team has faced weeks of vulnerability disclosures, including CVE-2026-21858 (10.0 CVSS, no auth required) and CVE-2026-25049 (9.4 CVSS).

Fortinet Vulnerabilities in Siemens RUGGEDCOM (CVE-2026-24858)

Siemens RUGGEDCOM APE1808 devices are affected by Fortinet FortiOS vulnerabilities, including CVE-2026-24858 (CISA KEV due January 30, EPSS 86th percentile), an authentication bypass in FortiAnalyzer and FortiManager. Additional flaws include CVE-2025-55018 and CVE-2025-62439 (HTTP request smuggling allowing unlogged firewall policy bypass) and CVE-2025-64157 (format string vulnerability enabling code execution by authenticated admins). Siemens recommends updating Fortigate NGFW to v7.4.10 or later and contacting support for OTA patches.

Ransomware Claims (Last 48h)

4 claims tracked across 3 groups in the last 48 hours:

Group Victim Sector Country
Lynx Keller Polska Construction/Geotechnical Poland
Lynx Africa Insurance Insurance Africa
Loki Credit Freedom & Restoration Financial Services US
Exitium Fannin CAD Government/Appraisal District US (Texas)

Exitium claims 400 GB exfiltrated from Fannin Central Appraisal District (Texas). These are unverified claims from ransomware leak sites.

Ransomware & Extortion

AI-Generated Slopoly Malware in Interlock Attacks

IBM X-Force disclosed Slopoly, an AI-generated PowerShell backdoor deployed by financially motivated threat actor Hive0163 in Interlock ransomware attacks. Slopoly shows strong indicators of LLM-assisted development, including extensive comments, structured logging, error handling, and clearly named variables. The malware maintains persistence via a scheduled task ("Runtime Broker"), beacons heartbeat messages every 30 seconds, polls for commands every 50 seconds, and executes them via cmd.exe. Attack chains start with ClickFix social engineering, deploying NodeSnake and Interlock RAT before ransomware. While technically unsophisticated, Slopoly demonstrates how AI tools accelerate custom malware development for evasion.

England Hockey Data Breach (AiLock Ransomware)

England Hockey is investigating a data breach after AiLock ransomware gang claimed to steal 129GB of data and threatened to publish it unless ransom is paid. The organization oversees 800+ clubs, 150,000 registered players, and 15,000 coaches and officials nationwide. AiLock emerged in April 2025, uses ChaCha20 and NTRUEncrypt encryption, and employs 72-hour response deadlines with privacy law violations as leverage in negotiations. England Hockey has not confirmed the breach but is working with external specialists and law enforcement.

US Charges Third DigitalMint Ransomware Negotiator

The DOJ charged Angelo Martino, a former DigitalMint ransomware negotiator, for operating as a BlackCat (ALPHV) affiliate while simultaneously negotiating on behalf of victims. Five victims hired DigitalMint and were assigned Martino, who played both sides and allegedly extorted $75.25 million across 10 attacks. Victims included a nonprofit ($26.8M ransom paid) and a financial services firm ($25.7M paid). Martino is Co-Conspirator 1 from the October 2025 indictment of Kevin Tyler Martin (also DigitalMint) and Ryan Goldberg (Sygnia). Both pleaded guilty and face April sentencing. DigitalMint fired Martino in April 2025 and has cooperated with law enforcement.

Telus Digital Breach (ShinyHunters, 1 Petabyte Claimed)

Canadian BPO giant Telus Digital confirmed a breach after ShinyHunters claimed to steal nearly 1 petabyte of data in a multi-month attack. Threat actors discovered Google Cloud Platform credentials in data stolen during the Salesloft Drift breach and used them to access Telus BigQuery instances. They then used the trufflehog tool to pivot across systems. ShinyHunters claims the breach impacts 28 well-known BPO customers (names withheld), with data including customer support tickets, call records, and authentication credentials. BPO providers are attractive targets because one breach exposes data from multiple downstream companies.

Business & Infrastructure Threats

Veeam Backup & Replication Critical RCE Flaws (7 CVEs)

Veeam patched seven vulnerabilities in Backup & Replication, including four critical RCE flaws allowing low-privileged domain users to execute remote code on backup servers. CVE-2026-21666, CVE-2026-21667, and CVE-2026-21669 (all 9.9 CVSS) allow authenticated domain users to perform RCE. CVE-2026-21708 (9.9 CVSS) allows a Backup Viewer to gain RCE as the postgres user. Affected versions: 12.3.2.4165 and earlier v12 builds. Fixed in v12.3.2.4465 and v13.0.1.2067. Veeam warned that attackers will reverse-engineer patches to exploit unpatched systems. VBR servers are heavily targeted by ransomware gangs (FIN7, Cuba, Frag, Akira, Fog) because they enable lateral movement, simplify data theft, and allow attackers to delete backups.

SocksEscort Residential Proxy Botnet Takedown

US and European law enforcement (Operation Lightning) seized SocksEscort, a residential proxy service that enslaved 369,000 IP addresses across 163 countries since 2020. The service was powered by the AVrecon malware (disclosed by Lumen Black Lotus Labs in July 2023), which infected SOHO routers via RCE and command injection vulnerabilities. SocksEscort sold proxy access ($15/month for 30 IPs, $200/month for 500 IPs) primarily to ransomware operators, DDoS attackers, and CSAM distributors. Customers defrauded victims of $1M+ (cryptocurrency), $700K (manufacturing), and $100K (military STAR cards). Authorities seized 34 domains, 23 servers, and froze $3.5M in cryptocurrency. AVrecon targets 1,200 device models from Cisco, D-Link, Hikvision, Mikrotik, Netgear, TP-Link, and Zyxel.

Iranian Wiper Attacks Targeting Intune (Handala Hack)

Unit 42 warned of increased wiper attack risk from Iranian threat group Handala Hack (aka Void Manticore, COBALT MYSTIQUE, Storm-1084/Storm-0842), assessed to be an MOIS (Ministry of Intelligence and Security) front. Attacks exploit identity through phishing and administrative access via Microsoft Intune. Israel's National Cyber Directorate reported multiple cases where attackers deleted servers and workstations using legitimate corporate user credentials. Unit 42 recommends eliminating standing privileges, implementing JIT access via Entra PIM, hardening Entra ID admin accounts (cloud-only accounts, break-glass access, multi-administrator approval), and restricting mass wipe capabilities to emergency accounts only.

SEO Poisoning Distributes Fake VPN Clients (Storm-2561)

Microsoft Defender Experts identified a credential theft campaign using SEO poisoning to distribute fake VPN clients signed with legitimate certificates. Storm-2561 (active since May 2025) redirects users searching for enterprise VPN software (Pulse Secure, Fortinet, Ivanti) to malicious GitHub repositories hosting trojanized MSI installers. The malware installs Pulse.exe and drops malicious DLLs (dwmapi.dll, inspector.dll) that harvest VPN credentials via DLL side-loading. Malware was digitally signed by "Taiyuan Lihua Near Information Technology Co., Ltd." (certificate now revoked). Domains observed: vpn-fortinet[.]com, ivanti-vpn[.]org.

Windows / AD Security

SMB Use-After-Free Vulnerability (CVE-2026-3805)

Microsoft published CVE-2026-3805, a use-after-free vulnerability in SMB connection reuse. Details are minimal (EPSS 12th percentile). Windows environments should monitor for patches in upcoming Patch Tuesday.

Microsoft Defender Email Security Benchmarking

Microsoft published Q1 2026 email security benchmarking data showing Defender removes 70.8% of malicious email post-delivery via zero-hour auto-purge. ICES vendors (Darktrace, KnowBe4, Cisco, VIPRE) provide incremental filtering of 13.7% for marketing/bulk email, but only 0.29% for spam and 0.24% for malicious messages (down from 1.65% and 0.5% in prior quarter). For malicious messages reaching the inbox, Defender handles 70.8% of post-delivery remediation, with ICES contributing 29.2%. SEG vendors missed more high-severity threats than Defender.

General Security News

Phishing Campaigns Weaponize SOC Workload (IDoS)

Security researchers documented "Informational Denial-of-Service" (IDoS) attacks where phishing campaigns flood SOCs with low-quality reports to hide targeted spear-phishing. 66% of SOC teams cannot keep up with incoming alerts. During high-volume periods, analysts spend less time per submission, investigation depth decreases, and decision quality drops. Red team exercises confirm adversaries time commodity phishing waves to coincide with spear-phishing targeting critical users. The SOC queue becomes the attack surface.

React-Based Phishing via EmailJS

SANS ISC documented a phishing campaign using a React-based credential harvesting page hosted on Cloudflare Workers. The fake Dropbox Transfer page dynamically constructs UI via JavaScript (main.90eaa1b0.js) and exfiltrates credentials via EmailJS (legitimate email service). Query string included Cyrillic characters (Russian word for "program"), suggesting Russian-speaking threat actors. Lure quality was low (sender spoofed recipient's own email address), but the credential collection mechanism was sophisticated.

OAuth Consent Abuse and Signal/WhatsApp Account Takeovers

Wiz warned of malicious OAuth applications exploiting consent fatigue to gain access to files and emails by impersonating brands (Adobe, DocuSign, OneDrive). Once users click "Accept," attackers receive access tokens without knowing passwords. Separately, Dutch and German intelligence services warned of Russian hackers targeting Signal and WhatsApp accounts of government officials, journalists, and military personnel by masquerading as Signal Support chatbots to steal verification codes and PINs or exploiting "linked devices" features.

Patch Priority

Vulnerability Disclosures

Trane HVAC Controllers (CVE-2026-28252, CVE-2026-28253, CVE-2026-28254, CVE-2026-28255, CVE-2026-28256)

Trane Tracer SC, SC+, and Concierge building automation controllers contain five vulnerabilities allowing authentication bypass (CVE-2026-28252, broken crypto), denial-of-service (CVE-2026-28253, memory allocation), sensitive information disclosure (CVE-2026-28254, missing authorization; CVE-2026-28255 and CVE-2026-28256, hard-coded credentials). Trane released v6.30.2313 for Tracer SC+ and implemented cloud security controls. Affected versions: Tracer SC <v4.4_SP7, Tracer SC+ and Concierge <v6.3.2310. Reported by Claroty.

Inductive Automation Ignition (CVE-2025-13913)

Ignition SCADA software <8.3.0 contains a deserialization vulnerability allowing privileged users to execute malicious code by importing specially crafted files. Malware executes with OS application service account permissions. Mitigation for 8.1.x includes creating dedicated service accounts, restricting filesystem permissions, and isolating gateways from corporate networks. Reported by Meta.

Siemens Heliox EV Chargers (CVE-2025-27769)

Heliox Flex 180 kW and Mobile DC 40 kW EV charging stations contain improper access control allowing attackers to reach unauthorized services via the charging cable. Siemens released OTA updates. Contact customer support for patches.

Siemens SIMATIC S7-1500 (CVE-2025-40943)

SIMATIC S7-1500 devices contain a code injection vulnerability allowing attackers to trick legitimate users into importing specially crafted trace files via the web interface. Siemens released v4.1.2 fixes for multiple ET 200SP and S7-1500 CPU models. Many older models remain unfixed with compensating controls recommended.

Trends & Context

Today's stories highlight the convergence of supply chain risk, credential sprawl, and AI-assisted malware development. The Telus Digital breach demonstrates how credentials in support tickets (Salesloft Drift) cascade into multi-petabyte BPO compromises affecting dozens of downstream customers. Slopoly malware shows LLMs accelerating custom tool development for evasion, while SEO poisoning and OAuth consent abuse exploit user trust in search engines and brand impersonation. Backup infrastructure (Veeam) remains the top ransomware target because one compromise enables data theft, lateral movement, and recovery sabotage across entire networks.