← Carolina Clear Tech

Cyber Threat Brief

2026-03-20

Listen to this brief (19:34)

Download MP3
Show Notes

Show Notes - 2026-03-20

Stories Covered

CVEs Referenced

CVE-2024-55591, CVE-2025-53770, CVE-2025-71221, CVE-2025-71225, CVE-2025-71227, CVE-2025-71233, CVE-2025-71236, CVE-2025-71257, CVE-2025-71258, CVE-2025-71259, CVE-2025-71260, CVE-2026-20131, CVE-2026-20963, CVE-2026-2273, CVE-2026-23110, CVE-2026-23113, CVE-2026-23118, CVE-2026-23126, CVE-2026-23154, CVE-2026-23157, CVE-2026-23169, CVE-2026-23171, CVE-2026-23191, CVE-2026-23207, CVE-2026-23208, CVE-2026-23213, CVE-2026-23214, CVE-2026-23221, CVE-2026-23227, CVE-2026-23269, CVE-2026-32191

Indicators of Compromise

Domains: handala-redwanted[.]to, handala-hack[.]to, Justicehomeland[.]org, Handala-Hack[.]to, Karmabelow80[.]org, Handala-Redwanted[.]to.

Read the full brief

Get tomorrow's brief in your inbox

Protect Your Business

Need a security assessment? See our cybersecurity packages.

View Services

Cyber Threat Brief - March 20, 2026

Today: SharePoint CVE-2026-20963 under active exploitation with federal patch deadline Saturday. Gentlemen ransomware group exploiting FortiGate CVE-2024-55591 across 14,700 compromised devices. FBI seizes Handala hacktivist domains after Stryker attack wiped 80,000 devices via Intune.

Critical Alerts

SharePoint CVE-2026-20963 Under Active Exploitation

CISA added CVE-2026-20963 to the KEV catalog on Wednesday with a three-day federal remediation deadline of March 21. This critical deserialization flaw in SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition allows unauthenticated remote code execution. Microsoft patched this in January 2026 Patch Tuesday, but exploitation began immediately after. CISA has not confirmed ransomware involvement but warns this is a frequent attack vector. EPSS score is 0.099 (93rd percentile). SharePoint Server 2007, 2010, and 2013 are end-of-support and no longer receive patches.

This is the second major SharePoint exploitation wave in recent months. Last summer's ToolShell vulnerability (CVE-2025-53770) was exploited as a zero-day by Chinese state actors and ransomware groups, compromising over 400 organizations including the US Energy Department. Salt Typhoon and other Beijing-linked groups joined those attacks through fall 2025.

Cisco Firewall Management Deserialization Flaw (CVE-2026-20131)

CISA added CVE-2026-20131 affecting Cisco Secure Firewall Management Center (FMC) and Cisco Security Cloud Control (SCC) Firewall Management to the KEV catalog based on evidence of active exploitation. This deserialization of untrusted data vulnerability is under exploitation but details on threat actors and attack campaigns remain unknown. EPSS score is 0.006 (68th percentile).

Ransomware & Extortion

Gentlemen RaaS Exploiting FortiGate at Scale

The Gentlemen ransomware-as-a-service operation has compromised 14,700 FortiGate devices globally and maintains 969 validated brute-forced VPN credentials, according to Group-IB analysis. The group emerged from a payment dispute on RAMP forum when operator "hastalamuerte" accused Qilin ransomware of withholding $48,000 in affiliate commission. The group consists of about 20 members and has attacked 94 organizations since emerging in July/August 2025.

Initial access relies on CVE-2024-55591, a critical authentication bypass in FortiOS/FortiProxy. This vulnerability is on the CISA KEV catalog with a due date of January 21, 2025, and an EPSS score of 0.942 (100th percentile). The Gentlemen also uses bring your own vulnerable driver (BYOVD) techniques to terminate security processes at the kernel level, evading endpoint detection before deploying ransomware.

Medusa Ransomware Exfiltrated 1TB from University of Mississippi Medical Center

The University of Mississippi Medical Center (UMMC) breach disclosed in February involved exfiltration of over 1TB and more than 1 million files, according to Medusa ransomware's spokesperson. The attack disrupted Epic EMR access and resulted in a nine-day service suspension, closing most outpatient clinics statewide and canceling elective surgeries and imaging appointments. Medusa instructed affiliates not to encrypt the entire infrastructure, focusing instead on data exfiltration over operational disruption.

Negotiations failed over deletion payment demands. Medusa demanded $800,000 while UMMC offered $550,000. Exfiltrated data allegedly includes protected health information of patients, employee and student personally identifiable information, and financial information. As of March 19, UMMC has not disclosed the total number of affected individuals.

Business & Infrastructure Threats

FBI Seizes Handala Domains After Stryker Attack

The FBI seized handala-redwanted[.]to and handala-hack[.]to domains following Handala's destructive cyberattack on medical technology giant Stryker. The seizure warrant was issued by the District Court for the District of Maryland. Handala (also known as Handala Hack Team, Hatef, Hamsa) is an Iranian-linked, pro-Palestinian hacktivist group first appearing in December 2023, reportedly linked to Iran's Ministry of Intelligence and Security (MOIS).

The Stryker attack compromised a Windows domain administrator account and created a new Global Administrator account to issue Microsoft Intune "wipe" commands to approximately 80,000 devices, including computers, mobile devices, and personal devices managed by the company. Handala acknowledged the seizures and stated they are building new digital infrastructure, with new websites forthcoming.

The Justice Department simultaneously seized four domains used by MOIS for cyber-enabled psychological operations: Justicehomeland[.]org, Handala-Hack[.]to, Karmabelow80[.]org, and Handala-Redwanted[.]to. These domains were used to claim credit for hacking activity, post stolen data, and call for killing journalists, regime dissidents, and Israeli persons.

BMC FootPrints Pre-Auth RCE Chain

Four vulnerabilities in BMC FootPrints ITSM platform (CVE-2025-71257, CVE-2025-71258, CVE-2025-71259, CVE-2025-71260) can be chained into pre-authentication remote code execution. The attack begins with an authentication bypass (CVE-2025-71257) extracting a guest session token from the password reset endpoint. This token enables exploitation of an unsanitized Java deserialization sink (CVE-2025-71260) in the "/aspnetconfig" endpoint's "__VIEWSTATE" parameter. Exploitation via AspectJWeaver gadget chain enables arbitrary file write to the Tomcat web root, achieving full RCE.

The SEC_TOKEN also unlocks two SSRF flaws (CVE-2025-71258 and CVE-2025-71259) for potential internal data leakage. All issues were addressed in September 2025.

Tax Season Phishing Campaigns Target Accountants

Microsoft Threat Intelligence identified multiple tax-themed phishing campaigns targeting individuals and accountants with credential theft and malware. Campaigns abuse phishing-as-a-service platforms like Energy365 and SneakyLog, using lures around W-2 forms, tax refunds, filing reminders, and CPA impersonation. Many campaigns deliver legitimate remote monitoring and management (RMM) tools for persistence and alternative command-and-control.

One campaign in early February 2026 delivered the Energy365 PhaaS kit using highly specific CPA lures. Emails with subject "See Tax file" contained Excel attachments named after real accountants, linking to OneNote files on OneDrive that hosted credential harvesting pages. Another campaign used QR codes and W-2 lures to deliver the SneakyLog phishing kit.

Tax-themed campaigns target accountants and professionals handling sensitive documents, financial data, and tax-related emails during peak season. Campaigns employ multi-step attack chains with Excel, OneNote, and OneDrive to complicate automated detection.

54 EDR Killers Abuse 35 Vulnerable Drivers

ESET analysis of EDR killer tools found that 54 of them leverage bring your own vulnerable driver (BYOVD) techniques by abusing 35 vulnerable drivers. EDR killers are a common component in ransomware intrusions, allowing affiliates to neutralize security software before deploying file-encrypting malware. BYOVD attacks gain kernel-mode (Ring 0) privileges by loading legitimate but vulnerable signed drivers, then terminate EDR processes, disable security tools, tamper with kernel callbacks, and undermine endpoint protections.

BYOVD-based EDR killers are developed by closed ransomware groups like DeadLock and Warlock, attackers forking proof-of-concept code (SmilingKiller, TfSysMon-Killer), and cybercriminals marketing tools as a service (DemoKiller, ABYSSWORKER, CardSpaceKiller). Ransomware groups produce EDR killers as specialized external components to keep encryptors simple, stable, and easy to rebuild.

Additional EDR killer categories include script-based tools using administrative commands (taskkill, net stop, sc delete) or Safe Mode reboots, anti-rootkit utilities with user interfaces (GMER, HRSword, PC Hunter), and emerging driverless EDR killers (EDRSilencer, EDR-Freeze) that block outbound EDR traffic.

Langflow Vulnerability Exploited Hours After Disclosure

A critical Langflow vulnerability was exploited hours after public disclosure. Langflow is a visual tool for building AI workflows. The vulnerability allows unauthenticated remote code execution because attacker-supplied flow data is used in public flows. Details on exploitation campaigns and threat actors are limited.

Windows / AD Security

March Windows 11 Update Breaks Microsoft Account Sign-Ins

KB5079473, the March 2026 Windows 11 cumulative update, breaks Microsoft account sign-ins across Teams, OneDrive, Microsoft Edge, Excel, Word, and Microsoft 365 Copilot. Affected devices display errors stating "You'll need the Internet for this. It doesn't look like you're connected to the Internet" even when connected. The issue occurs only with Microsoft accounts used for Microsoft Teams Free. Businesses using Entra ID (Azure Active Directory) for app authentication are not affected.

Microsoft's workaround is to restart the affected PC while connected to the internet, which may repair the device connectivity state. If the device is restarted without an active internet connection, the connectivity issue may return.

CISA Urges Intune Hardening After Stryker Breach

CISA warned US organizations to harden Microsoft Intune environments following the Handala cyberattack on Stryker. Recommendations apply to Intune and other endpoint management software: use least-privilege for admin roles via Intune's role-based access control (RBAC), enforce MFA and privileged-access hygiene via Microsoft Entra ID Conditional Access and risk signals, and require multi-admin approval for sensitive actions like device wipes, application updates, and RBAC modifications.

Combining these practices shifts from relying on "trusted administrators" toward protected administration by design: least-privilege to contain impact, Entra-based controls to ensure users are trusted and authenticated, and multi-admin approval to govern critical changes.

Microsoft Bing Images RCE (CVE-2026-32191)

CVE-2026-32191 is a remote code execution vulnerability in Microsoft Bing Images caused by improper neutralization of special elements used in OS command injection. An unauthorized attacker can execute code over a network. No CVSS score, EPSS score, or exploitation details are currently available.

Patch Priority

Vulnerability Disclosures

Schneider Electric EcoStruxure Automation Expert (CVE-2026-2273)

CWE-94 code injection vulnerability in Schneider Electric EcoStruxureTM Automation Expert versions prior to v25.0.1 allows execution of untrusted commands on the engineering workstation when an authenticated user opens a malicious project file. This could result in limited compromise of the workstation and potential loss of confidentiality, integrity, and availability. The product is plant automation software for digital control systems in discrete, hybrid, and continuous industrial processes. EPSS score is 0.000 (7th percentile).

Version v25.0.1 includes a fix and is available for download. Schneider Electric recommends storing solution and archive files within the user's home directory or locations protected by Windows file-system access controls in multi-user environments. Users must verify file authenticity before opening any solution or archive file.

Linux Kernel CVEs in MSRC Feed

Multiple Linux kernel CVEs published in the MSRC Security Update Guide with EPSS scores in the 0.000 to 0.006 range (1st to 68th percentile): CVE-2026-23227 (drm/exynos), CVE-2026-23214 (btrfs), CVE-2026-23221 (bus: fsl-mc), CVE-2025-71221 (dmaengine), CVE-2026-23110 (scsi: core), CVE-2026-23171 (bonding), CVE-2026-23213 (drm/amd/pm), CVE-2025-71225 (md), CVE-2025-71227 (wifi: mac80211), CVE-2025-71233 (PCI: endpoint), CVE-2025-71236 (scsi: qla2xxx), CVE-2026-23207 (spi: tegra210-quad), CVE-2026-23113 (io_uring/io-wq), CVE-2026-23118 (rxrpc), CVE-2026-23126 (netdevsim), CVE-2026-23154 (net), CVE-2026-23157 (btrfs), CVE-2026-23169 (mptcp), CVE-2026-23191 (ALSA: aloop), CVE-2026-23208 (ALSA: usb-audio), CVE-2026-23269 (apparmor).

These appear to be Linux kernel fixes published through Microsoft's advisory feed. No additional context or Windows-specific impact is provided.

Trends & Context

Exploitation timelines are collapsing. SharePoint CVE-2026-20963 was patched in January and under active exploitation by mid-March. Langflow's critical vulnerability was exploited within hours of public disclosure. Defenders must assume zero-day windows for patching critical internet-facing services, especially those with deserialization and RCE primitives. The Gentlemen ransomware operation demonstrates that payment disputes within cybercrime ecosystems spawn new, well-resourced threat groups with existing infrastructure and target lists. BYOVD remains the dominant EDR evasion technique across ransomware affiliates, with 54 distinct tools abusing 35 vulnerable drivers.


Generated by Carolina Clear Tech - https://carolinacleartech.com/brief/