← Carolina Clear Tech

Cyber Threat Brief

2026-03-19

Listen to this brief (19:16)

Download MP3
Show Notes

Show Notes - 2026-03-19

Stories Covered

CVEs Referenced

CVE-2025-14174, CVE-2025-31277, CVE-2025-3935, CVE-2025-43510, CVE-2025-43520, CVE-2025-43529, CVE-2025-66376, CVE-2025-71265, CVE-2025-71266, CVE-2025-71267, CVE-2026-20131, CVE-2026-20700, CVE-2026-20963, CVE-2026-23233, CVE-2026-23242, CVE-2026-23243, CVE-2026-23244, CVE-2026-23245, CVE-2026-23246, CVE-2026-23247, CVE-2026-23248, CVE-2026-27448, CVE-2026-27459, CVE-2026-3564, CVE-2026-3644, CVE-2026-4224

Read the full brief

Get tomorrow's brief in your inbox

Protect Your Business

Need a security assessment? See our cybersecurity packages.

View Services

Cyber Threat Brief - March 19, 2026

Today: Interlock ransomware exploited a Cisco firewall zero-day for five weeks before disclosure, ConnectWise patches a critical ScreenConnect flaw that allows session hijacking, and CISA adds Zimbra and SharePoint vulnerabilities to the KEV catalog with federal patching deadlines. A new DarkSword iOS exploit kit is circulating among multiple threat actors, targeting users in Saudi Arabia, Turkey, Malaysia, and Ukraine. Medical device manufacturer Stryker suffers a cyberattack targeting Microsoft Intune endpoint management, prompting CISA to release hardening guidance for all endpoint management platforms.

Critical Alerts

Cisco FMC Zero-Day CVE-2026-20131 (CVSS 10.0)

Interlock ransomware exploited a maximum-severity deserialization flaw in Cisco Secure Firewall Management Center as a zero-day starting January 26, 2026, 36 days before Cisco disclosed and patched it on March 4. Amazon's threat intelligence team discovered the activity via honeypot sensors and identified a misconfigured Interlock infrastructure server that exposed their full post-exploitation toolkit. The vulnerability allows unauthenticated remote attackers to execute arbitrary Java code as root on affected FMC devices.

The exposed toolkit includes a PowerShell reconnaissance script that enumerates Windows environments (OS, hardware, services, installed software, Hyper-V VMs, user files, browser artifacts from Chrome/Edge/Firefox/IE, network connections, RDP events), custom JavaScript and Java RATs with shell access, command execution, file transfer, SOCKS5 proxy capability, self-update and self-delete mechanisms, a bash script that configures Linux servers as HTTP reverse proxies with HAProxy and fail2ban to launder infrastructure origins, log erasure routines that run every five minutes, a memory-resident web shell that decrypts and executes command payloads from incoming requests, a lightweight network beacon for validating exploitation success, ConnectWise ScreenConnect for persistent remote access, and Volatility Framework for memory forensics.

Interlock has historically targeted education, engineering, architecture, construction, manufacturing, industrial, healthcare, and government sectors. The zero-day exploitation demonstrates continued investment by ransomware operators in discovering and weaponizing vulnerabilities in edge network devices from Cisco, Fortinet, Ivanti, and other vendors to gain initial access.

ConnectWise ScreenConnect CVE-2026-3564

ConnectWise patched a critical cryptographic signature verification vulnerability in ScreenConnect versions before 26.1 that allows unauthorized access and privilege escalation. An attacker can extract and abuse ASP.NET machine keys for unauthorized session authentication and unauthorized actions within ScreenConnect. ConnectWise observed attempts to abuse disclosed machine key material in the wild, though the vendor states there is no evidence of active exploitation of CVE-2026-3564 specifically and no indicators of compromise to share. There are claims that Chinese hackers have exploited this issue for years, though this is unconfirmed. Nation-state hackers previously exploited CVE-2025-3935 (now on CISA KEV, due date was June 23, 2025) to steal ScreenConnect secret machine keys.

Cloud-hosted ScreenConnect customers were automatically upgraded to version 26.1. On-premises customers must manually upgrade immediately. ConnectWise has added stronger protection for machine keys, including encrypted storage and improved handling.

CISA KEV: Zimbra CVE-2025-66376 and SharePoint CVE-2026-20963

CISA added two actively exploited vulnerabilities to the Known Exploited Vulnerabilities catalog. CVE-2025-66376 is a stored XSS flaw (CVSS 7.2) in Synacor Zimbra Collaboration Suite Classic UI that allows attackers to abuse CSS @import directives in HTML email messages. Zimbra patched this in November 2025 (versions 10.0.18 and 10.1.13). EPSS score is 0.000 (15th percentile), but CISA KEV inclusion confirms active exploitation.

Seqrite Labs reported a campaign called Operation GhostMail attributed to a suspected Russian state-sponsored group targeting the State Hydrographic Service of Ukraine. The attack uses a social-engineered internship inquiry email with obfuscated JavaScript payload embedded directly in the HTML body. No attachments, no links, no macros. When opened in a vulnerable Zimbra webmail session, it exploits CVE-2025-66376 and deploys a browser-resident credential stealer that harvests credentials, session tokens, backup 2FA recovery codes, browser-saved passwords, and mailbox contents going back 90 days. Exfiltration occurs over both DNS and HTTPS. The campaign email was sent on January 22, 2026, from a likely compromised National Academy of Internal Affairs email address.

CVE-2026-20963 is a deserialization vulnerability (CVSS 8.8) in Microsoft Office SharePoint that allows unauthorized attackers to execute code over a network. Microsoft patched this in January 2026. EPSS score is 0.016 (82nd percentile). CISA has not shared details on the exploitation but confirmed active attacks.

Federal agencies must patch CVE-2025-66376 by April 1, 2026, and CVE-2026-20963 by March 23, 2026 (this Friday). CISA strongly urges all organizations to prioritize these KEV vulnerabilities.

Ransomware Claims (Last 48h)

Group Victim Sector Country
kyber L3HARRIS Aerospace/Defense United States

1 claim tracked in the last 48 hours. L3Harris is a global aerospace and defense technology company providing mission-critical solutions for government, defense, and commercial sectors. This is an unverified claim from a ransomware leak site and has not been confirmed as a successful breach.

Ransomware & Extortion

Marquis Breach: 672,000 Records Stolen in August 2025 SonicWall Attack

Marquis, a Texas-based financial services provider serving over 700 banks and credit unions, disclosed that a ransomware gang stole data from 672,075 individuals in an August 14, 2025 attack. The attackers compromised a SonicWall firewall and exfiltrated names, dates of birth, addresses, phone numbers, Social Security numbers, Taxpayer Identification Numbers, and financial account information (without security or access codes). The incident disrupted operations at 74 banks across the United States.

In January, Marquis blamed the attack on SonicWall's September 17 security breach that affected 5% of firewall customers using cloud backup service. SonicWall warned that attackers could extract access credentials and tokens, making it significantly easier to compromise customer firewalls. A Mandiant investigation found evidence linking the September incident to a state-sponsored hacking group.

In February, Marquis filed a lawsuit against SonicWall for gross negligence and misrepresentation. The company is defending over 36 consumer class action lawsuits stemming from the attack and is seeking monetary damages, indemnification, contribution for judgments, attorneys' fees, and equitable relief.

Business & Infrastructure Threats

DarkSword iOS Exploit Kit Targets Multiple Countries

Google Threat Intelligence Group, iVerify, and Lookout reported a new iOS full-chain exploit kit called DarkSword that leverages six vulnerabilities (three zero-days) to fully compromise iPhones running iOS 18.4 through 18.7. Multiple commercial surveillance vendors and suspected state-sponsored actors have used DarkSword since at least November 2025 in campaigns targeting Saudi Arabia, Turkey, Malaysia, and Ukraine. UNC6353, a suspected Russian espionage group previously observed using the Coruna iOS exploit kit, has now incorporated DarkSword into watering hole campaigns.

The six vulnerabilities used in DarkSword are CVE-2025-31277 (JavaScriptCore memory corruption, patched in 18.6), CVE-2026-20700 (user-mode Pointer Authentication Code bypass in dyld, patched in 26.3, CISA KEV due date was March 5, 2026), CVE-2025-43529 (JavaScriptCore memory corruption, patched in 18.7.3 and 26.2, CISA KEV due date was January 5, 2026), CVE-2025-14174 (ANGLE memory corruption, patched in 18.7.3 and 26.2, CISA KEV due date was January 2, 2026), CVE-2025-43510 (iOS kernel memory management, patched in 18.7.2 and 26.1), and CVE-2025-43520 (iOS kernel memory corruption, patched in 18.7.2 and 26.1). EPSS scores are low across all six CVEs (0.000 to 0.009, percentiles 4% to 75%), but three were exploited as zero-days before Apple patched them.

DarkSword is delivered via compromised websites hosting malicious iFrame elements that load JavaScript to fingerprint devices and route targets to the exploit chain. The kit breaks out of the Safari WebContent sandbox, escalates privileges, and deploys three malware families: GHOSTBLADE, GHOSTKNIFE, and GHOSTSABER. The payloads are designed to extract an extensive set of personal information, including credentials and crypto wallet data, with a hit-and-run approach that collects and exfiltrates within seconds or minutes, followed by cleanup.

Google reported the vulnerabilities to Apple in late 2025, and all have been patched with iOS 26.3 (most were patched earlier). Google has added DarkSword delivery domains to Safe Browsing.

CISA Alert: Endpoint Management System Hardening After Stryker Attack

CISA issued an alert urging organizations to harden endpoint management system configurations following a March 11, 2026 cyberattack against U.S.-based medical technology firm Stryker Corporation that affected their Microsoft environment. CISA is conducting enhanced coordination with FBI to identify additional threats and determine mitigation actions.

CISA recommends implementing Microsoft's best practices for securing Microsoft Intune, with principles that apply broadly to other endpoint management software: use least privilege for administrative roles, leverage role-based access control (RBAC) to assign minimum permissions necessary for each role, enforce phishing-resistant MFA and privileged access hygiene with Microsoft Entra ID capabilities (Conditional Access, MFA, risk signals, privileged access controls), and configure Multi Admin Approval policies in Intune to require a second administrative account's approval for sensitive or high-impact actions (device wiping, applications, scripts, RBAC changes, configurations).

Aura Data Breach: 900,000 Marketing Contacts Exposed via Vishing

Identity protection company Aura confirmed that an unauthorized party accessed nearly 900,000 customer records containing names and email addresses. The incident was caused by a voice phishing (vishing) attack targeting an employee. 20,000 current and 15,000 former Aura customers were affected. The data originated from a marketing tool used by a company acquired by Aura in 2021.

The ShinyHunters threat group claimed the attack and leaked 12GB of stolen files after failing to reach an agreement with Aura. The leaked data includes full names, email addresses, home addresses, phone numbers, customer service comments, and IP addresses. Have I Been Pwned added 901,000+ email addresses to its database, with 90% already present from past incidents. Aura stated that Social Security Numbers, account passwords, and financial information were not compromised.

Windows / AD Security

Microsoft AI Observability Framework

Microsoft's Security Blog published guidance on observability for AI systems as part of expanding the Secure Development Lifecycle (SDL) to address AI-specific security concerns. Traditional observability tools track latency, errors, and throughput for deterministic code flows. AI systems are probabilistic and make complex decisions at runtime, requiring evolved telemetry to understand and govern AI behavior.

Microsoft highlighted a scenario where an email agent asks a research agent to retrieve web content, the research agent fetches a page with hidden instructions (prompt injection), and passes poisoned content back to the email agent as trusted input. The email agent, now operating under attacker influence, forwards sensitive documents to unauthorized recipients, resulting in data exfiltration. Traditional health metrics (uptime, latency, errors) stay green, missing the boundary compromise between untrusted external content and trusted agent context.

Microsoft's enhanced AI observability practices track how context was assembled at each step, what was retrieved, how it impacted model behavior, and where it propagated across agents. Traditional monitoring built around uptime and error rates cannot detect these AI-specific risks or provide signal for attribution or reconstruction.

Microsoft Pauses Copilot Auto-Deployment

Microsoft paused plans to automatically deploy the Microsoft 365 Copilot app to customer devices for an unspecified period. The app provides a centralized entry point for Copilot experiences and AI-powered capabilities across Microsoft 365. The rollout was originally planned for early October 2025, slipped to December 2025, and is now temporarily halted.

Existing installations are unaffected. Customers in the European Economic Area (EEA) were already excluded. Administrators can still deploy the app via other methods and should await further updates. The decision reflects negative reaction from Microsoft's commercial customers, who objected to the opt-out-by-default approach that increased administrative workload and forced IT leaders to make decisions based on Microsoft's schedule rather than corporate timelines.

General Security News

Talos: Ransomware Exfiltration Playbook

Cisco Talos published research on data exfiltration tactics used by ransomware operators, noting that attackers increasingly leverage legitimate native utilities, commonly deployed third-party tools, and cloud service clients to exfiltrate data. This reduces the effectiveness of static indicators of compromise (IOCs) and tool-based blocking strategies.

Talos developed the Exfiltration Framework to systematically normalize behavioral and forensic characteristics of these tools, enabling cross-environment comparison independent of operating system, deployment model, or infrastructure domain. The framework models execution context, parent-child process relationships, network communication patterns, artifact persistence, and destination characteristics to expose detection-relevant signals that remain stable even when tools are renamed, relocated, or operated within trusted infrastructure.

The analysis demonstrates that reliable detection requires correlation across endpoint, network, and cloud telemetry, with emphasis on behavioral baselining, contextual anomalies, and cumulative transfer analysis rather than protocol-level or allow-list-based controls. Attackers abuse trusted, allow-listed tools such as cloud CLI interfaces, file synchronization utilities, managed file transfer platforms, and legitimate file storage services, making the distinction between legitimate use and malicious abuse subtle, contextual, and difficult to identify.

Palo Alto Networks: AI Agent Security Tradeoffs

Unit 42 published guidance on securing AI agents, noting that the open-source AI ecosystem forms the backbone of AI infrastructure but contains more risk due to lack of standardized signing or integrity checks for models and high trust in popular repositories. Attacks spread widely and rapidly before threats are detected.

Unit 42 outlined two attack pathways: targeting the open-source AI ecosystem (model file attacks, rug pull attacks on MCP servers) and targeting an organization's internal AI agents. In model file attacks, attackers upload malicious AI model files to trusted repositories. These files look legitimate but contain hidden executable code. When a developer loads the model, the malicious payload executes automatically, stealing AWS credentials, downloading remote access trojans, and exfiltrating data. In rug pull attacks, attackers compromise MCP servers (Model Context Protocol servers that add tools and capabilities to AI agents) to perform malicious actions after LLM integration, such as copying data and sending it to external sources.

Patch Priority

Vulnerability Disclosures

pyOpenSSL Vulnerabilities (CVE-2026-27448, CVE-2026-27459)

Microsoft published two CVEs in pyOpenSSL. CVE-2026-27448 allows TLS connection bypass via unhandled callback exception in set_tlsext_servername_callback (EPSS 0.000, 12th percentile). CVE-2026-27459 is a DTLS cookie callback buffer overflow (EPSS 0.000, 12th percentile). No severity scores or exploitation details are available yet.

Linux Kernel and Filesystem CVEs

Microsoft published multiple Linux kernel and filesystem CVEs: CVE-2026-23233 (f2fs: fix to avoid mapping wrong physical block for swapfile), CVE-2026-23242 (RDMA/siw: potential NULL pointer dereference), CVE-2026-23245 (net/sched: act_gate RCU snapshot issue), CVE-2025-71266 (ntfs3: check return value of indx_find to avoid infinite loop), CVE-2025-71267 (ntfs3: infinite loop triggered by zero-sized ATTR_LIST), CVE-2026-23244 (nvme: memory allocation in nvme_pr_read_keys), CVE-2026-23243 (RDMA/umad: reject negative data_len), CVE-2026-23248 (perf/core: refcount bug and potential UAF in perf_mmap), CVE-2026-23246 (wifi: mac80211 bounds-check link_id), CVE-2026-23247 (tcp: secure_seq add back ports to TS offset), CVE-2025-71265 (ntfs3: infinite loop in attr_load_runs_range). All have EPSS scores between 0.000 and 0.001 (2nd to 7th percentiles). No exploitation details are available yet.

Expat XML Parser CVE-2026-4224

Microsoft published CVE-2026-4224, a stack overflow when parsing XML with deeply nested DTD content models in the Expat parser (EPSS 0.000, 4th percentile). No severity score or exploitation details are available yet.

Python http.cookies CVE-2026-3644

Microsoft published CVE-2026-3644, incomplete control character validation in Python's http.cookies module (EPSS 0.001, 28th percentile). No severity score or exploitation details are available yet.

Trends & Context

Today's stories highlight the persistent targeting of edge network devices and management platforms by ransomware operators and nation-state actors. The Cisco FMC zero-day (exploited for five weeks before disclosure), ConnectWise ScreenConnect machine key vulnerability, Stryker's Intune compromise, and Marquis's SonicWall breach all demonstrate that perimeter and management infrastructure remains a high-value target for initial access. The DarkSword iOS exploit kit proliferation across multiple commercial surveillance vendors and state-sponsored groups mirrors Coruna, showing a mature second-hand exploit market for mobile devices. Organizations should prioritize hardening endpoint management platforms, patching edge devices immediately when vendors issue advisories, and implementing behavioral detection for exfiltration activities that leverage legitimate tools and cloud services.