← Carolina Clear Tech

Cyber Threat Brief

2026-03-18

Listen to this brief (25:45)

Download MP3
Show Notes

Show Notes - 2026-03-18

Stories Covered

CVEs Referenced

CVE-2010-5250, CVE-2025-13957, CVE-2025-2595, CVE-2025-47813, CVE-2026-0667, CVE-2026-20643, CVE-2026-24061, CVE-2026-25569, CVE-2026-25570, CVE-2026-25571, CVE-2026-25572, CVE-2026-25573, CVE-2026-25605, CVE-2026-25750, CVE-2026-32746, CVE-2026-3888

Indicators of Compromise

IP Addresses: 2.8.0.138, 3.5.16.10, 3.5.21.20

Read the full brief

Get tomorrow's brief in your inbox

Protect Your Business

Need a security assessment? See our cybersecurity packages.

View Services

Daily Cyber Threat Brief - March 18, 2026

Today: LeakNet ransomware adopts ClickFix social engineering to bypass traditional initial access methods while deploying Deno-based in-memory loaders. GNU Telnetd has a critical unpatched buffer overflow (CVE-2026-32746) allowing unauthenticated root RCE via port 23. GlassWorm supply-chain malware hit 433+ packages across GitHub, npm, and VSCode extensions using blockchain C2. European Union sanctioned Chinese and Iranian cyber contractors for attacks on critical infrastructure.

Critical Alerts

Critical Unpatched Telnetd Flaw (CVE-2026-32746)

GNU InetUtils telnet daemon has a critical buffer overflow vulnerability allowing unauthenticated remote code execution as root. CVE-2026-32746 (CVSS 9.8) affects all versions through 2.7 via an out-of-bounds write in the LINEMODE SLC suboption handler. The flaw triggers during initial connection handshake before any login prompt appears. A single network connection to port 23 with specially crafted protocol messages is sufficient for exploitation. No credentials, user interaction, or special network position required. Successful exploitation results in complete system compromise if telnetd runs with root privileges. Fix expected by April 1, 2026.

CISA Adds Wing FTP Vulnerability to KEV Catalog

CISA flagged CVE-2025-47813 as actively exploited. The year-old Wing FTP vulnerability leads to disclosure of the full local installation path. Added to Known Exploited Vulnerabilities catalog with remediation due date March 30, 2026. EPSS score 21.0% (96th percentile) indicates high likelihood of exploitation.

Ubuntu Privilege Escalation (CVE-2026-3888)

Default installations of Ubuntu Desktop 24.04 and later vulnerable to local privilege escalation to root. CVE-2026-3888 (CVSS 7.8) stems from unintended interaction between snap-confine and systemd-tmpfiles. Attacker waits for systemd cleanup daemon to delete /tmp/.snap directory (30 days Ubuntu 24.04, 10 days later versions), recreates directory with malicious payloads, then snap-confine bind mounts files as root during sandbox initialization. Requires low privileges, no user interaction, but high attack complexity due to time-delay mechanism.

Ransomware Claims (Last 48h)

2 claims tracked across 1 group in the last 48 hours. These are unverified claims from ransomware leak sites, not confirmed breaches.

Group Victim Sector Country
Sinobi Summa Energy Energy/Fuel Services United States
Sinobi Interpack Northwest Food/Frozen Foods United States

Ransomware & Extortion

LeakNet Ransomware Uses ClickFix via Hacked Sites, Deploys Deno In-Memory Loader

LeakNet ransomware operation adopted ClickFix social engineering tactic delivered through compromised websites as initial access method. Users are tricked into manually running malicious commands (msiexec.exe via Windows Run dialog) to address fake CAPTCHA verification checks. This departure from relying on stolen credentials from initial access brokers reduces per-victim acquisition cost and removes operational bottleneck of waiting for valuable accounts. LeakNet uses staged C2 loader built on Deno JavaScript runtime to execute malicious payloads directly in memory, minimizing on-disk evidence and evading detection. Post-compromise activity follows consistent methodology: DLL side-loading to launch malicious DLL, lateral movement using PsExec, data exfiltration via Amazon S3, and encryption. ReliaQuest also observed Microsoft Teams-based phishing leading to similar Deno-based loader, suggesting either broadening of LeakNet's vectors or adoption by other actors.

Warlock Ransomware Group Augments Post-Exploitation Activities

Warlock ransomware group showcased stealthier cross-network activity using new BYOVD (Bring Your Own Vulnerable Driver) technique and additional tools in recent attack. Indicates evolution of post-exploitation tradecraft.

Ransomware Market Shifts as Payment Rates Hit Record Lows

Ransomware actors ditching Cobalt Strike in favor of native Windows tools as payment rates hit record lows and data theft surges. Less lucrative ransomware market forcing attackers to alter methods and reduce operational costs.

Business & Infrastructure Threats

GlassWorm Malware Hits 400+ Code Repos on GitHub, npm, VSCode, OpenVSX

GlassWorm supply-chain campaign returned with coordinated attack targeting 433 compromised components: 200 GitHub Python repositories, 151 GitHub JS/TS repositories, 72 VSCode/OpenVSX extensions, and 10 npm packages. Attack uses same Solana blockchain address for C2 activity, identical payloads, and shared infrastructure linking all waves. Initial compromise occurs on GitHub where accounts are compromised to force-push malicious commits. Malicious packages and extensions published on npm and VSCode/OpenVSX feature obfuscated code using invisible Unicode characters. Malware queries Solana blockchain every 5 seconds for new instructions embedded as transaction memos. Between November 27, 2025 and March 13, 2026, 50 new transactions updated payload URLs. Malware targets cryptocurrency wallet data, credentials, access tokens, SSH keys, and developer environment data. Code comments indicate Russian-speaking threat actors and malware skips execution if Russian locale detected.

AI Flaws in Amazon Bedrock, LangSmith, and SGLang Enable Data Exfiltration and RCE

Amazon Bedrock AgentCore Code Interpreter's sandbox mode permits outbound DNS queries that can be exploited to enable interactive shells and bypass network isolation despite "no network access" configuration. BeyondTrust researchers demonstrated bidirectional communication channel using DNS queries and responses to obtain interactive reverse shell, exfiltrate sensitive information if IAM role has S3 permissions, and perform command execution. Amazon determined this to be intended functionality rather than defect, recommending VPC mode instead of sandbox mode for complete network isolation and DNS firewall to filter outbound DNS traffic. LangSmith vulnerability CVE-2026-25750 (CVSS 8.5) exposed users to token theft and account takeover via URL parameter injection from lack of validation on baseUrl parameter. Fixed in LangSmith version 0.12.71 released December 2025.

Europe Sanctions Chinese and Iranian Firms for Cyberattacks

European Union imposed sanctions on three hacking groups and two individuals for cyberattacks targeting EU member states. Integrity Technology Group (China) sanctioned for providing technical support that led to hacking 65,000+ devices in six EU states between 2022-2023, connected to Raptor Train botnet operated by Flax Typhoon APT. Anxun Information Technology/i-SOON (China) sanctioned for hacking services targeting critical infrastructure, with two co-founders also sanctioned. Emennet Pasargad (Iran) sanctioned for hack of French satirical magazine Charlie Hebdo, 2024 Paris Olympics, and Swedish SMS service. Previously sanctioned three times by US in 2021, September 2024, and December 2024. Works under Iran's Islamic Revolutionary Guard Corps conducting stunt-hacks and influence operations.

Credential Theft Soared in H2 2025

Credential theft surged in second half of 2025 driven by industrialization of infostealer malware and AI-enabled social engineering. More attackers logging in rather than breaking in as stolen credentials become primary attack vector.

Windows / AD Security

Microsoft: Enabling Teams Meeting Add-in Breaks Outlook Classic

Microsoft addressing known issue rendering classic Outlook email client unusable for users who enabled Microsoft Teams Meeting Add-in. Issue tracked under EX1254044 caused by previous Outlook build version. Affected users unable to use Microsoft Outlook Classic while Teams Meeting Add-in and previous build version enabled. Temporary fix: update Outlook or perform Online Repair for click-to-run installs (reinstalls all Office applications). Microsoft working with representatives to ensure latest Outlook version enabled to mitigate impact.

Microsoft Shares Fix for Windows C: Drive Access Issues on Samsung PCs

Microsoft and Samsung published recovery guidance for C:\ drive access issues and app failures on Samsung laptops running Windows 11 25H2 and 24H2. Samsung Galaxy Connect app caused problems accessing files, launching apps, performing administrative tasks, elevating privileges, uninstalling updates, and collecting logs due to permission failures. Microsoft temporarily removed Samsung app from Microsoft Store. Samsung published new version addressing bug. Recovery requires 29-step procedure taking up to 15 minutes to restore standard Windows permissions: sign in with Administrator account, uninstall Samsung Galaxy Connect/Samsung Continuity Service app, allow Windows to repair drive permissions, add temporary permission, restore Windows default permissions using .bat repair file. Restores drive ownership to Windows TrustedInstaller.

New Windows 11 Hotpatch Fixes Bluetooth Device Visibility Issue

Microsoft released emergency OOB KB5084897 hotpatch to fix Bluetooth device visibility issue on hotpatch-enabled Windows 11 Enterprise devices running 25H2 and 24H2. Bluetooth devices not appearing in Windows Settings or Quick Settings even though connected and functioning. Bug prevented adding new Bluetooth devices because available devices did not appear in connection list. Hotpatch installs automatically without restart, includes all improvements and security patches from March 2026 Windows hotpatch updates. Second OOB hotpatch in days following KB5084597 on March 13 to patch three high-severity RRAS vulnerabilities.

Microsoft Stops Force-Installing the Microsoft 365 Copilot App

Microsoft stopped automatically installing Microsoft 365 Copilot app on Windows devices with Microsoft 365 desktop client apps. Forced rollout began early December 2025, scheduled for completion mid-December for devices outside EEA. Now temporarily disabled without explanation. Existing installations remain unaffected. When rollout resumes, app will be added to Windows Start Menu and enabled by default. IT admins can opt out via Apps Admin Center under Customization > Device Configuration > Modern App Settings by clearing "Enable automatic installation of Microsoft 365 Copilot app" checkbox.

General Security News

UK Companies House Portal Had Major Bug

UK government shut down business web filing service to fix major vulnerability. Bug allowed threat actors with account on Companies House portal to view and edit registration data of other companies. Exploiting bug required pressing Back key four times while in "File for another company" section, which returned attacker to that company's dashboard with full rights.

Apple Fixes WebKit Vulnerability Enabling Same-Origin Policy Bypass (CVE-2026-20643)

Apple released first Background Security Improvements update to address WebKit security flaw CVE-2026-20643 affecting iOS 26.3.1, iPadOS 26.3.1, macOS 26.3.1, and macOS 26.3.2. Cross-origin issue in WebKit's Navigation API could be exploited to bypass same-origin policy when processing maliciously crafted web content. Addressed with improved input validation in iOS 26.3.1 (a), iPadOS 26.3.1 (a), macOS 26.3.1 (a), and macOS 26.3.2 (a). Background Security Improvements deliver lightweight security releases for Safari, WebKit framework stack, and system libraries through smaller ongoing security patches rather than larger software updates. Feature supported on iOS 26.1+, iPadOS 26.1+, and macOS 26+ with automatic installation option in Privacy and Security menu. Thomas Espach credited with discovery.

South Korean Police Accidentally Post Cryptocurrency Wallet Password

South Korea's National Tax Service exposed publicly the mnemonic recovery phrase of seized cryptocurrency wallet during announcement of successful operation. Someone stole $4.4 million in crypto assets from Ledger cold wallet seized in law enforcement raids at 124 high-value tax evaders. Funds stored in wallet originally worth 8.1 billion won (approximately $5.6 million).

Patch Priority

Vulnerability Disclosures

Siemens SICAM SIAPP SDK (6 CVEs)

Siemens SICAM SIAPP SDK contains multiple vulnerabilities exploitable if API used improperly or hardening measures not applied. CVE-2026-25569 out-of-bounds write vulnerability could allow writing data beyond buffer leading to DoS or arbitrary code execution. CVE-2026-25570 missing input value checks resulting in stack overflow enabling code execution and DoS. CVE-2026-25571 (client) and CVE-2026-25572 (server) lack maximum length checks on certain variables allowing oversized input triggering stack overflow and DoS. CVE-2026-25573 builds shell commands with caller-provided strings enabling command injection and full system compromise. CVE-2026-25605 performs file deletion without validating file path or target allowing deletion of files/sockets process has permission to remove. Affects SICAM SIAPP SDK versions prior to 2.1.7.

Schneider Electric EcoStruxure Data Center Expert (CVE-2025-13957)

Hard-coded credentials vulnerability in EcoStruxure IT Data Center Expert (DCE) versions 9.0 and prior could lead to information disclosure and remote code execution when SOCKS Proxy enabled and administrator credentials and PostgreSQL database credentials known. SOCKS Proxy disabled by default. Fixed in version 9.1.

Schneider Electric SCADAPack and RemoteConnect (CVE-2026-0667)

Improper check for unusual or exceptional conditions vulnerability could cause arbitrary code execution, DoS, and loss of confidentiality and integrity when communicating over Modbus TCP protocol. Affects SCADAPackTM 57x all versions and RemoteConnect versions prior to R3.4.2 (firmware 9.12.2).

CODESYS in Festo Automation Suite (CVE-2025-2595, CVE-2010-5250)

CVE-2025-2595 allows unauthenticated remote attacker to bypass user management in CODESYS Visualization and read visualization template files or static elements via forced browsing. CVE-2010-5250 untrusted search path vulnerability in pthreadGC2.dll allows local users to gain privileges via Trojan horse quserex.dll file in current working directory. Affects Festo Automation Suite versions prior to 2.8.0.138 with CODESYS Development System 3.0 or 3.5.16.10. Starting from version 2.8.0.138, CODESYS no longer bundled and must be downloaded separately.

Trends & Context

Social engineering and supply-chain attacks dominate today's threat landscape. LeakNet's adoption of ClickFix demonstrates ransomware operators seeking cost-effective initial access methods that bypass traditional security controls. GlassWorm's 433-component compromise across multiple open-source ecosystems highlights developer toolchain as high-value target. Both threats leverage legitimate functionality (Deno runtime, invisible Unicode, blockchain C2) to evade detection. Critical infrastructure vulnerabilities (Siemens SICAM, Schneider Electric) and unpatched Telnetd flaw underscore persistent risk in industrial control systems and legacy network services. EU sanctions against Chinese and Iranian cyber contractors reflect continued nation-state targeting of critical infrastructure. Microsoft's multiple OOB hotpatches in three days indicate quality control issues affecting enterprise Windows deployments.