CVE-2025-31277, CVE-2025-32432, CVE-2025-43510, CVE-2025-43520, CVE-2025-54068, CVE-2026-20131, CVE-2026-21992, CVE-2026-23204, CVE-2026-23271, CVE-2026-23272, CVE-2026-23274, CVE-2026-23276, CVE-2026-23277, CVE-2026-23278, CVE-2026-30922, CVE-2026-32766, CVE-2026-33017, CVE-2026-3479, CVE-2026-3632, CVE-2026-3633, CVE-2026-3634
Domains:
205[.]251
IP Addresses:
12.2.1.4, 14.1.2.1
Get tomorrow's brief in your inbox
2026-03-21
Today: CISA adds five actively exploited CVEs to KEV with a two-week patching deadline, while Cisco firewall admins face a Sunday deadline for CVE-2026-20131, already abused by Interlock ransomware since January. Langflow exploitation went from advisory to active attacks in 20 hours.
CISA Adds Five Known Exploited Vulnerabilities to Catalog
CISA added five CVEs to the KEV catalog on March 20, 2026, all under active exploitation. CVE-2025-32432 (Craft CMS code injection, CVSS 10.0, EPSS 99th percentile) has been exploited since February 2025 by unknown actors and the Mimo cryptocurrency mining group. CVE-2025-54068 (Laravel Livewire code injection, CVSS 9.8, EPSS 95th percentile) is linked to Iranian group MuddyWater targeting diplomatic and critical infrastructure. Three Apple vulnerabilities (CVE-2025-31277, CVE-2025-43510, CVE-2025-43520) are part of the DarkSword iOS exploit kit delivering GHOSTBLADE, GHOSTKNIFE, and GHOSTSABER malware for data theft against Saudi Arabian, Turkish, Malaysian, and Ukrainian users.
CISA Orders Feds to Patch Max-Severity Cisco Flaw by Sunday (CVE-2026-20131)
CVE-2026-20131 (CVSS 10.0, EPSS 90th percentile) is an unauthenticated remote code execution flaw in Cisco Secure Firewall Management Center caused by insecure deserialization. Interlock ransomware exploited this as a zero-day from late January 2026, more than a month before Cisco published the March 4 patch. Amazon threat intelligence confirmed active exploitation. The vulnerability allows attackers to execute arbitrary Java code as root by sending a specially crafted serialized Java object to the web-based management interface. No workarounds are available.
Critical Langflow Flaw CVE-2026-33017 Triggers Attacks within 20 Hours of Disclosure
CVE-2026-33017 (CVSS 9.3, EPSS 66th percentile) is a missing authentication combined with code injection flaw in Langflow that enables unauthenticated remote code execution. The vulnerability affects all versions up to 1.8.1 and is fixed in development version 1.9.0.dev8. Sysdig observed first exploitation attempts within 20 hours of the March 17, 2026 advisory, despite no public PoC existing. Attackers built exploits directly from the advisory and began scanning for vulnerable instances. The flaw abuses the /api/v1/build_public_tmp/{flow_id}/flow endpoint which accepts attacker-controlled flow data containing arbitrary Python code that gets passed to exec() with no sandboxing.
Oracle Patches Critical CVE-2026-21992 Enabling Unauthenticated RCE in Identity Manager
CVE-2026-21992 (CVSS 9.8, EPSS 13th percentile) is an unauthenticated remote code execution vulnerability in Oracle Identity Manager and Oracle Web Services Manager. The flaw is remotely exploitable over HTTP without authentication and could result in complete takeover of susceptible instances. Affected versions are Oracle Identity Manager 12.2.1.4.0 and 14.1.2.1.0, and Oracle Web Services Manager 12.2.1.4.0 and 14.1.2.1.0. Oracle released this as an emergency out-of-band Security Alert, strongly recommending immediate patching. Oracle declined to comment on whether the vulnerability has been exploited in the wild.
15 claims tracked across 2 groups in the last 48 hours. These are unverified claims from ransomware leak sites, not confirmed breaches.
| Group | Victim | Sector | Country |
|---|---|---|---|
| morpheus | SURTECHINC | Plating Industry | South Korea |
| gunra | Frontier Financial Group | Financial Services | Not specified |
| gunra | El Ezh Building Contracting LLC | Construction | UAE |
| gunra | Thai Petroleum & Trading Co. | Energy/Petroleum | Thailand |
| gunra | Grupo PyD | Not specified | Not specified |
| gunra | Ipiranga Contábil | Accounting | Brazil |
| gunra | NeoDerm | Healthcare | Not specified |
| gunra | INCARFE S.L. | Not specified | Spain |
| gunra | Eric Davis Dental | Healthcare | Not specified |
| gunra | Ventilaciones Nerual, S.L. | Manufacturing | Spain |
| gunra | Envy Recycling | Recycling | Not specified |
| gunra | VINTAGE HOMESTEAD GmbH | Not specified | Germany |
| gunra | Diamond | Not specified | Not specified |
| gunra | ASPShips | Maritime | Not specified |
| gunra | triotech.com.sg | Technology | Singapore |
Interlock Ransomware Targets Cisco Enterprise Firewalls
Interlock ransomware gained access to CVE-2026-20131 in Cisco Secure Firewall Management Center weeks before Cisco publicly disclosed the vulnerability on March 4, 2026. Amazon threat intelligence confirmed the gang exploited the flaw as a zero-day since late January 2026. Interlock is known for double-extortion attacks and has compromised high-profile victims including DaVita, Kettering Health, Texas Tech University System, and the City of Saint Paul, Minnesota. The group also uses ClickFix technique for initial access and deploys custom RATs and malware strains like NodeSnake and Slopoly.
Beast Gang Exposes Ransomware Server
Operational security failure by the Beast ransomware gang exposed a central cloud server, revealing systematic tactics for attacking network backups. Files on the server highlight aggressive backup destruction as a key technique. This operational exposure provides defenders insight into the group's infrastructure and methods.
City of Hamilton Ransomware Highlights Insurance Gaps
The City of Hamilton, Ontario suffered a ransomware attack on February 25, 2024, that crippled 80% of the city's network. Attackers demanded $18.5 million CAD, which the city refused to pay. Recovery costs reached $18.3 million CAD. The city's $5 million cyber insurance claim was denied because multi-factor authentication was not fully implemented across all required systems. A single missing security control voided the entire policy, leaving taxpayers to cover all expenses. This follows a pattern across Canadian municipalities where 54% of Ontario cities allocate less than 5% of IT spending to cybersecurity, and 79% of Canadian ransomware victims paid attackers in 2024.
Trivy Supply Chain Attack Triggers Self-Spreading CanisterWorm
Threat actors compromised Trivy scanner credentials and published malicious trivy, trivy-action, and setup-trivy releases containing credential stealers. This attack cascaded into CanisterWorm, a self-propagating worm that has compromised 47 npm packages (28 in @EmilGroup scope, 16 in @opengov scope, plus @teale.io/eslint-config, @airtm/uuid-base32, and @pypestream/floating-ui-dom). The worm uses an Internet Computer Protocol (ICP) canister as a decentralized, takedown-resistant command-and-control dead drop. Malware establishes persistence via systemd user service masquerading as PostgreSQL tooling (pgmon). The backdoor polls the ICP canister every 50 minutes with spoofed browser User-Agent to fetch payload URLs. A rickroll YouTube video currently serves as the C2 response, indicating dormant state. The worm includes deploy.js for manual propagation using stolen npm tokens, and newer versions in @teale.io/eslint-config self-propagate without manual intervention. TeamPCP is suspected.
Russian Intelligence Services Target Commercial Messaging Applications
CISA and FBI issued a PSA warning about Russian Intelligence Services conducting ongoing phishing campaigns targeting commercial messaging applications like Signal and WhatsApp. The campaigns aim to bypass encryption by compromising individual user accounts. Targets include current and former U.S. government officials, military personnel, political figures, and journalists. Evidence shows threat actors have compromised thousands of individual CMA accounts globally to view messages, contact lists, send messages, and conduct additional phishing. The encryption of the applications themselves remains secure, but account-level compromise defeats encryption protections.
Justice Department Disrupts Botnet Networks Hijacking 3 Million Devices
The Department of Justice disrupted four large-scale botnets (Aisuru, Kimwolf, JackSkid, and Mossad) that collectively hijacked 3 million devices. These botnets enabled cybercriminals to initiate thousands of attacks. The crackdown continues amid growing challenges in combating large-scale botnet operations.
Operation Alice Shuts Down 373,000 Dark Web Sites
German authorities and Europol led Operation Alice, a global operation that shut down over 373,000 fraudulent dark web sites advertising CSAM and cybercrime-as-a-service. The operation began in mid-2021 targeting the operator of "Alice with Violence CP" platform. Law enforcement identified 440 customers across 23 countries who attempted to purchase illegal material. The operation seized 105 servers (many in Germany) and issued an international arrest warrant for the Chinese operator. The fraudulent sites collected roughly $400,000 from approximately 10,000 users who paid between EUR 17 and EUR 250 in Bitcoin for material that was never delivered.
Operation Synergia III Disrupts Global Cybercrime Infrastructure
Interpol-led Operation Synergia III (July 2025 to January 2026) disrupted global cybercrime infrastructure across 72 countries. Authorities sinkholed 45,000 malicious IP addresses, seized 212 devices and servers, resulting in 94 arrests and 110 ongoing investigations. The operation focused on phishing, ransomware, malware, and fraud networks. Bangladesh police arrested 40 suspects tied to scams and identity theft. In Macau, investigators uncovered over 33,000 phishing sites impersonating casinos, banks, and government services. The EU sanctioned three companies and two individuals tied to major cyberattacks, including China-linked Integrity Technology Group and Anxun Information Technology (i-SOON), plus Iran-based Emennet Pasargad.
UK Cyber Watchdog Warns JLR Bailout Sets Worrying Precedent
The UK's cyber watchdog warned that the government's £1.5 billion bailout of Jaguar Land Rover following a cyber incident risks setting a troubling precedent for how Britain handles major cyber crises. The lack of clear criteria for government intervention may encourage firms to lean on state support instead of securing adequate insurance coverage and implementing proper cybersecurity controls.
Microsoft Breaks Microsoft Account Sign-Ins in Windows 11 with Latest Update
Microsoft broke Microsoft account sign-ins in Windows 11 25H2 and 24H2 with a recent update. Users of Microsoft Teams Free, OneDrive, Office, Word, Excel, and Microsoft 365 Copilot see phantom "no internet" errors when signing in with Microsoft accounts, even when devices are connected. Businesses using Entra ID (Azure Active Directory) for application authentication are not affected. The issue occurs when devices enter a specific network connectivity state. A restart may fix it if the device is online, but restarting without an active internet connection can trigger the issue again. Microsoft is working on a fix to be released in the next few days, likely as another out-of-band update to address problems caused by the March 10 update.
Microsoft Publishes Multiple CVE Advisories
Microsoft published multiple CVE advisories for Linux kernel components, libsoup vulnerabilities, Python pkgutil issues, and other components. Notable items include CVE-2026-3632 and CVE-2026-3634 (libsoup HTTP smuggling and header injection vulnerabilities), CVE-2026-3479 (Python pkgutil security bypass), and several netfilter and networking CVEs. These appear to be informational publications for components included in Microsoft products or Azure infrastructure.
MuddyWater (Boggy Serpens) Increases Technological Capabilities
Iranian state-sponsored group MuddyWater (also known as Boggy Serpens), attributed to the Iranian Ministry of Intelligence and Security (MOIS), is increasing technological capabilities while maintaining its hallmark social engineering tactics. The group consistently targets diplomatic and critical infrastructure including energy, maritime, and finance across the Middle East and strategic targets worldwide. MuddyWater uses a custom-built web-based orchestration platform to automate mass email delivery while maintaining granular control over sender identities and target lists. The group hijacks official government and corporate accounts for spear-phishing and abuses trusted relationships to evade reputation-based blocking. In a sustained campaign against a UAE national marine and energy company (August 16, 2025 to February 11, 2026), the group conducted four attack waves deploying various malware families. The group has been linked to exploitation of CVE-2025-54068 (Laravel Livewire) and previously deployed AI-enhanced malware implants with anti-analysis techniques.
DarkSword iOS Exploit Targeting iOS 18.4 to 18.7
DarkSword iOS exploit chain delivers GHOSTBLADE (data miner), GHOSTKNIFE (backdoor), and GHOSTSABER (JavaScript backdoor) malware to iPhones running iOS 18.4 to 18.7. The toolkit is linked to Russian-aligned UNC6353, PARS Defense (Turkish surveillance firm), and other actors. DarkSword exploits six documented Apple vulnerabilities now patched. Delivery begins via Safari exploits gaining kernel access and executing an orchestrator (pe_main.js) that injects modules into privileged iOS services including App Access, Wi-Fi, Keychain, and iCloud. Collected data includes passwords, messages, contacts, call history, location, browser history, Apple Health, and cryptocurrency wallets. The malware removes traces after exfiltration, focusing on rapid theft rather than persistent surveillance. Code shows signs of LLM-assisted development with professional design, maintainability, and modularity. Targets identified in Saudi Arabia, Malaysia, and Ukraine.
CISA KEV Additions (Due April 3, 2026)
Five vulnerabilities added to CISA's Known Exploited Vulnerabilities catalog on March 20, 2026. Federal agencies must patch by April 3, 2026. CVE-2025-32432 (Craft CMS, CVSS 10.0, EPSS 99th percentile) enables code injection and has been exploited since February 2025 by unknown actors and Mimo cryptocurrency mining group. CVE-2025-54068 (Laravel Livewire, CVSS 9.8, EPSS 95th percentile) is a code injection flaw exploited by Iranian MuddyWater group. Three Apple CVEs (CVE-2025-31277, CVE-2025-43510, CVE-2025-43520) are part of the DarkSword iOS exploit kit with EPSS scores ranging from 3rd to 32nd percentile, but confirmed exploitation against multiple countries.
Microsoft Security Update Guide Publications
Microsoft published informational CVE entries for multiple Linux kernel components (CVE-2026-23204, CVE-2026-23274, CVE-2026-23278, CVE-2026-23272, CVE-2026-23276, CVE-2026-23277, CVE-2026-23271), libsoup vulnerabilities (CVE-2026-3634 HTTP header injection/response splitting, CVE-2026-3632 HTTP smuggling/SSRF, CVE-2026-3633 CRLF injection), Python pkgutil security bypass (CVE-2026-3479), pyasn1 DoS (CVE-2026-30922), and astral-tokio-tar PAX validation issue (CVE-2026-32766). All entries show EPSS scores below 1st percentile except CVE-2026-3632 (26th percentile).
Five actively exploited vulnerabilities added to CISA KEV in a single day underscores the velocity of threat actor weaponization. Langflow going from advisory to exploitation in 20 hours sets a new record for adversary responsiveness. The Interlock gang's month-long zero-day window on Cisco CVE-2026-20131 demonstrates advanced capabilities and intelligence gathering. Supply chain attacks continue to evolve with CanisterWorm's abuse of decentralized infrastructure (ICP canisters) for takedown resistance, showing adversaries learning from previous disruptions. The Hamilton ransomware case highlights a critical gap where partial security control implementation voids cyber insurance, leaving organizations fully exposed to recovery costs.