CVE-2025-47812, CVE-2025-47813, CVE-2026-1703, CVE-2026-23066, CVE-2026-23069, CVE-2026-23941, CVE-2026-23942, CVE-2026-23943, CVE-2026-2673, CVE-2026-32249, CVE-2026-3909, CVE-2026-3910, CVE-2026-4105, CVE-2026-4111
Get tomorrow's brief in your inbox
Today: CISA adds actively exploited Wing FTP flaw to KEV catalog with March 30 deadline. Google patches two Chrome zero-days with confirmed in-the-wild exploits. Ransomware profitability declining but victim posts hit record highs. Iranian threat actors shift from custom wipers to identity weaponization. Microsoft Teams vishing campaign tricks users into granting Quick Assist access.
Wing FTP Server Path Disclosure (CVE-2025-47813)
CISA added CVE-2025-47813 to the Known Exploited Vulnerabilities catalog on March 16 due to active exploitation. This medium-severity (CVSS 4.3) information disclosure flaw leaks the server's full local installation path when an overly long UID cookie value is supplied to the /loginok.html endpoint. The vulnerability affects all versions prior to 7.4.4 and is being exploited in the wild, potentially chained with CVE-2025-47812 (CVSS 10.0), a critical RCE flaw patched in May 2025 that attackers used to download malicious Lua files and install remote management software.
Google Chrome Zero-Days (CVE-2026-3909, CVE-2026-3910)
Google patched two high-severity vulnerabilities in Chrome on March 16 that are actively exploited in the wild. CVE-2026-3909 is an out-of-bounds write in the Skia graphics library (EPSS 0.271, 96th percentile), and CVE-2026-3910 is an inappropriate implementation in the V8 JavaScript engine that enables out-of-bounds memory access (EPSS 0.219, 96th percentile). Both vulnerabilities were added to CISA's KEV catalog with a March 27 remediation deadline. Google acknowledged exploits exist but provided no details on how the flaws are being used.
Ransomware Profitability Declining Despite Record Victim Posts
Google Threat Intelligence Group's 2025 ransomware analysis shows signs of declining profitability across the ransomware ecosystem, driven by improved security practices, better recovery capabilities, and declining ransom payments. Despite this, data leak site posts jumped 48% to 7,784 in 2025, and unique leak sites climbed 35% to 128. The disconnect reflects a shift toward data theft extortion without encryption, which grew from 2% of incidents in 2020 to 15% in 2025. Ransomware incidents with encryption dropped from 39% in 2024 to 31% in 2025. REDBIKE was the most deployed ransomware family at 30% of incidents. Qilin and Akira RaaS brands dominated after disruptions to LockBit, ALPHV, Basta, and RansomHub.
Key findings: Initial access via vulnerability exploitation occurred in 33% of incidents (mostly VPNs and firewalls). Data theft occurred in 77% of ransomware intrusions, up from 57% in 2024. Targeting of virtualization infrastructure increased from 29% to 43%. BEACON and MIMIKATZ usage declined while reliance on remote management tools plateaued.
Iranian Threat Actors Shift to Identity Weaponization
Palo Alto's Unit 42 tracks Iranian cyber operations moving from custom wiper malware to living-off-the-land identity abuse tactics. Recent Void Manticore (Handala) attacks compromised privileged identities to push legitimate remote-wipe commands to over 200,000 devices globally, treating MDM platforms as weaponizable infrastructure that bypasses endpoint detection. This evolution began in 2016-2019 with MBR wipers like Shamoon, ZeroCleare, and Dustman targeting Middle Eastern energy sectors, then shifted to ransomware smokescreens (Apostle, Fantasy) in 2020-2022 for plausible deniability. The current phase weaponizes administrative tools without deploying malware, removing critical detection guardrails.
Boggy Serpens (MuddyWater), attributed to Iran's Ministry of Intelligence and Security, demonstrates similar evolution with sustained multi-wave campaigns against UAE maritime and energy infrastructure from August 2025 through February 2026. The group leverages hijacked accounts for trusted relationship compromises, employs AI-generated Rust-based tools like BlackBeard backdoor, and uses Telegram API for command and control.
Microsoft Teams Vishing Campaign Enables Quick Assist Compromise
Microsoft DART investigated an identity-first intrusion where a threat actor impersonated IT support via Microsoft Teams voice phishing calls in November 2025. After two failed attempts, the attacker convinced a third employee to grant remote access through Quick Assist, establishing a foothold on a corporate device. Once connected, the attacker directed the user to a spoofed credential harvesting page, then deployed a malicious MSI package that sideloaded a DLL to establish command-and-control. Subsequent payloads included encrypted loaders, remote execution tools, and credential harvesters enabling session hijacking. The attack exploited trust in collaboration platforms and built-in Windows tools designed to blend with legitimate enterprise activity.
Infostealer Credential Exposure Accelerating Throughout 2025
Recorded Future's 2025 Identity Threat Landscape Report shows credential theft accelerated dramatically in the second half of 2025, with 50% more credentials indexed than the first half and 90% more in Q4 than Q1. Total exposures: 1.95 billion from malware combo lists, 892 million from malware logs, 36 million from database combo lists, and 24 million from database dumps. Of credentials with identifiable authorization URLs, 63.2% targeted authentication systems, followed by web content management (9.95%), cloud computing (7.58%), RMM tools (6.19%), and VPNs (2.4%). Detection and response software (1.17%) and SIEM platforms (0.06%) were also targeted, giving attackers the ability to blind security teams.
Each compromised device yielded an average of 87 stolen credentials. 276 million credentials (31% of malware-sourced) included active session cookies enabling MFA bypass. Over half (53%) were indexed within one week of exfiltration, and 36.4% within 24 hours, meaning organizations have narrow windows to act on intelligence before credentials are exploited.
Router Botnets Enslaved for Criminal Proxy Services
Law enforcement dismantled SocksEscort, a criminal proxy service that enslaved thousands of residential routers into a botnet for large-scale fraud. The operation was powered by AVrecon malware targeting MIPS and ARM architectures via known vulnerabilities in edge network devices. The malware featured a persistence mechanism that flashed custom firmware to permanently disable updates, transforming SOHO routers into proxy nodes that blindside corporate monitoring. KadNap, a separate takedown-resistant botnet comprising over 14,000 routers and network devices, exploits known Asus router vulnerabilities to ferry traffic for cybercrime anonymously.
Storm-2561 Distributes Fake VPN Clients via SEO Poisoning
A threat actor identified as Storm-2561 is running a credential theft campaign targeting VPN users through SEO poisoning. The campaign distributes fake VPN clients that deploy trojans and steal login credentials.
Samsung Galaxy Connect App Locks Users Out of C:\ Drive
Microsoft and Samsung confirmed that the Samsung Galaxy Connect app caused access denial errors to the C:\ drive on Windows 11 systems running versions 24H2 and 25H2. Affected models include Samsung Galaxy Book 4 (NP750XGJ, NP750XGL, NP754XGJ, NP754XFG, NP754XGK) and Samsung Desktops (DM500SGA, DM500TDA, DM500TGA, DM501SGA). Users received "C:\ is not accessible - Access denied" errors that prevented launching Office apps, browsers, and utilities including Quick Assist. Some users could not elevate privileges, uninstall updates, or collect logs due to permission failures. Microsoft removed the app from the Store and Samsung republished a stable previous version, but recovery options for already-impacted devices remain limited.
Microsoft Exchange Online Outage Blocks Mailbox Access
Microsoft addressed an Exchange Online outage on March 16 (EX1253275) that prevented customers from accessing mailboxes and calendars via Outlook on the web, Outlook desktop, Exchange ActiveSync, and other protocols. The company attributed the issue to "a section of service infrastructure not processing traffic efficiently" and made configuration changes to remediate. A separate outage (MO1253428) affected Microsoft 365 Copilot web sign-in and Copilot web clients at office.com/chat, m365.cloud.microsoft, and copilot.cloud.microsoft. The Exchange Online outage was mitigated by 14:20 EDT, but the Copilot issue remained under investigation. This follows similar Exchange Online outages in January (IMAP4 access) and November (classic Outlook desktop client).
Meta Discontinuing Instagram End-to-End Encryption in May 2026
Meta announced plans to discontinue end-to-end encryption for Instagram DMs after May 8, 2026, citing low adoption rates. A Meta spokesperson stated, "Very few people were opting in to end-to-end encrypted messaging in DMs, so we're removing this option from Instagram in the coming months. Anyone who wants to keep messaging with end-to-end encryption can easily do that on WhatsApp."
UNC6426 Leverages nx npm Supply Chain Attack for AWS Admin Access
Threat actor UNC6426 used keys stolen from the nx npm package supply chain compromise in August 2025 to completely breach a victim's AWS environment within 72 hours. The attacker abused GitHub-to-AWS OIDC trust to create a new administrator role, then exfiltrated files from S3 buckets and performed data destruction in production cloud environments.
Commonwealth Bank Builds AI Threat Hunting Agents
Australia's Commonwealth Bank built custom agentic AI tools for threat hunting because vendors cannot keep pace with AI-powered threats. The bank's weekly threat signal volume increased from 80 million six years ago to 400 billion last week. The bank's AI agent ingests threat intelligence, analyzes it against internal data, and identifies risks across legacy systems, on-prem infrastructure, SaaS, and cloud workloads. Response time for threat assessment dropped from two days to 30 minutes. A second agent searches for indicators of compromise and produces rapid reports.
Python pip (CVE-2026-1703)
Limited path traversal vulnerability when installing wheel archives. CVSS score and severity not published. EPSS 0.000 (6th percentile).
Libarchive (CVE-2026-4111)
Infinite loop denial of service in RAR5 decompression via archive_read_data(). EPSS 0.000 (11th percentile).
Systemd (CVE-2026-4105)
Privilege escalation via improper access control in RegisterMachine D-Bus method. EPSS 0.000 (4th percentile).
OpenSSL TLS 1.3 (CVE-2026-2673)
Server may choose unexpected key agreement group. EPSS 0.000 (5th percentile).
Erlang ssh_sftpd (CVE-2026-23942)
SFTP root escape via component-agnostic prefix check. EPSS 0.000 (4th percentile).
Erlang SSH (CVE-2026-23943)
Pre-authentication SSH DoS via unbounded zlib inflate. EPSS 0.000 (10th percentile).
Erlang inets httpd (CVE-2026-23941)
Request smuggling via first-wins Content-Length parsing. EPSS 0.000 (3rd percentile).
Vim (CVE-2026-32249)
NFA regex engine NULL pointer dereference affects Vim < 9.2.0137. EPSS 0.000 (2nd percentile).
Linux Kernel (CVE-2026-23066, CVE-2026-23069)
CVE-2026-23066: rxrpc recvmsg() unconditional requeue issue. CVE-2026-23069: vsock/virtio potential underflow in virtio_transport_get_credit(). Both EPSS 0.000 (3rd-4th percentile).
Today's stories show exploitation timelines collapsing. Wing FTP's path disclosure CVE is chained with a year-old RCE that attackers began exploiting one day after public disclosure. Chrome's two zero-days were patched the same day Google confirmed active exploitation, but defenders still have an 11-day CISA deadline. The shift from custom malware to identity abuse by Iranian actors and the Microsoft Teams vishing campaign both highlight that attackers now weaponize trusted tools and legitimate access rather than deploying detectable payloads. The infostealer data reinforces this: 36.4% of stolen credentials are indexed within 24 hours, meaning defenders have less than a day to detect and respond before credentials are sold and exploited. Ransomware profitability is declining, but attackers adapted by shifting to data theft extortion and targeting virtualization infrastructure that enables simultaneous encryption of multiple workloads.