← Carolina Clear Tech

Cyber Threat Brief

2026-03-23

Listen to this brief (17:52)

Download MP3
Show Notes

Show Notes - 2026-03-23

Stories Covered

CVEs Referenced

CVE-2025-14174, CVE-2025-31277, CVE-2025-32975, CVE-2025-43510, CVE-2025-43520, CVE-2025-43529, CVE-2026-20700, CVE-2026-21992, CVE-2026-4451, CVE-2026-4456, CVE-2026-4457, CVE-2026-4461, CVE-2026-4462, CVE-2026-4464

Indicators of Compromise

Domains: 225[.]156, handala-redwanted[.]to, handala-hack[.]to, justicehomeland[.]org, karmabelow80[.]org

Read the full brief

Get tomorrow's brief in your inbox

Protect Your Business

Need a security assessment? See our cybersecurity packages.

View Services

Daily Cyber Threat Brief

March 23, 2026

Today: CISA orders federal agencies to patch DarkSword iOS exploits by April 3rd, Microsoft releases emergency fix for account sign-in failures, and critical Oracle Identity Manager flaw gets out-of-band patch. Trivy supply chain attack expands with Docker Hub malware, Quest KACE vulnerability under active exploitation, and VoidStealer bypasses Chrome encryption via debugger tricks.

Critical Alerts

DarkSword iOS Exploit Kit (CVE-2025-31277, CVE-2025-43510, CVE-2025-43520)

CISA added three iOS vulnerabilities to the Known Exploited Vulnerabilities catalog after DarkSword exploit kit was used in cryptocurrency theft and espionage campaigns. The exploit chain allows attackers to escape sandboxes, escalate privileges, and execute code remotely on iPhones running iOS 18.4 through 18.7. Threat groups UNC6748 (linked to Turkish surveillance vendor PARS Defense) and UNC6353 (suspected Russian espionage) deployed three malware families: GhostBlade JavaScript infostealer, GhostKnife backdoor, and GhostSaber. UNC6353 used both DarkSword and Coruna exploit kits in watering-hole attacks targeting Ukrainian e-commerce and industrial sites. DarkSword wipes temporary files after data theft to evade detection. Three additional CVEs (CVE-2026-20700, CVE-2025-43529, CVE-2025-14174) are part of the chain but KEV addition focused on the three with April 3 deadline.

Oracle Identity Manager Critical RCE (CVE-2026-21992)

Oracle released emergency out-of-band patch for CVE-2026-21992, a maximum-severity authentication bypass vulnerability in Oracle Identity Manager. The flaw allows remote code execution without authentication and may have been exploited in the wild. EPSS score is 0.000 (7th percentile), indicating this is a very recent disclosure.

Quest KACE SMA Exploitation (CVE-2025-32975)

Arctic Wolf observed active exploitation of CVE-2025-32975 (CVSS 10.0) starting the week of March 9. Attackers use authentication bypass to seize administrative accounts, execute remote commands, drop Base64-encoded payloads from 216.126.225[.]156, create admin accounts via runkbot.exe, harvest credentials with Mimikatz, and obtain RDP access to backup infrastructure (Veeam, Veritas) and domain controllers. Attackers modified Windows Registry via PowerShell for persistence.

Ransomware Claims (Last 48h)

8 claims tracked across 2 groups in the last 48 hours. These are unverified claims from ransomware leak sites.

Group Victim Sector Country
leakeddata W... S... H... Unknown Unknown
leakeddata HEMIC (Hawaii Employers' Mutual Insurance Co) Insurance USA
leakeddata Nations Financial Group Inc Financial Services USA
leakeddata Two River Group Holdings LLC Life Sciences USA
leakeddata Plaza Home Mortgage Financial Services USA
leakeddata Singleton Schreiber Legal USA
leakeddata Wood Smith Henning & Berman LLP Legal USA
leakeddata Phelps Dunbar Legal USA
alp-001 irco.com Unknown USA
alp-001 hikvision.com Technology Unknown

Note: "alp-001" claimed irco.com with revenue $7.7 billion and 5.9 TB of data staged.

Business & Infrastructure Threats

Trivy Supply Chain Attack Expands

Trivy vulnerability scanner compromise extended to Docker Hub with malicious versions 0.69.4, 0.69.5, and 0.69.6 containing TeamPCP infostealer. Last clean release was 0.69.3. Attackers defaced all 44 internal repositories in Aqua Security's "aquasec-com" GitHub organization in a 2-minute scripted burst on March 22 using compromised "Argon-DevOps-Mgt" service account. This account bridges both GitHub organizations, giving attackers write/admin access to both with a single token. TeamPCP deployed CanisterWorm self-propagating worm across dozens of npm packages. New wiper malware spreads via SSH using stolen keys and exploits exposed Docker APIs on port 2375. On Kubernetes clusters in Iran, malware deploys privileged DaemonSets, wipes Iranian nodes via "kamikaze" containers, and installs CanisterWorm backdoor on non-Iranian nodes as systemd service.

VoidStealer Bypasses Chrome Encryption

VoidStealer infostealer uses hardware breakpoints to extract Chrome's v20_master_key directly from browser memory, bypassing Application-Bound Encryption (ABE) without privilege escalation or code injection. This is the first observed in-the-wild use of this debugger-based technique. VoidStealer starts a suspended hidden browser process, attaches as debugger, waits for chrome.dll or msedge.dll to load, scans for specific LEA instruction, sets hardware breakpoint, and reads the register holding plaintext master key during browser startup when ABE-protected cookies are decrypted. Gen Digital notes VoidStealer likely adopted this from the open-source ElevationKatz project (part of ChromeKatz toolset), which has been available for over a year. VoidStealer is a MaaS platform advertised on dark web forums since mid-December 2025, with version 2.0 introducing the ABE bypass.

Iranian Handala Hackers Using Telegram C2

FBI warns Iranian MOIS-linked Handala hacktivist group is using Telegram as C2 infrastructure for malware targeting journalists, Iranian dissidents, and opposition groups worldwide. The group uses social engineering to deliver Windows malware for screenshot and file exfiltration. FBI seized four domains on March 21: handala-redwanted[.]to, handala-hack[.]to, justicehomeland[.]org, and karmabelow80[.]org used by Handala, Homeland Justice (IRGC-linked), and Karma Below for data leaks and stolen document publication. Handala previously attacked Stryker with Microsoft Intune wipe command, factory resetting 80,000 devices after compromising Windows domain admin and creating Global Administrator account.

GitHub Malware Distribution Epidemic

GitHub malware distribution campaigns have escalated from occasional sightings in early 2024 to widespread abuse. Threat actors clone legitimate repositories, add infostealers or RATs, and use black-hat SEO, malvertising, fake GitHub stars, and meaningless commits to keep malicious repos at top of search results. Users assume they landed on legitimate software developer pages. Campaigns target gaming cheats, license cracks, system tools, and macOS users. Security vendors report campaigns ranging from hundreds to thousands of repos, with some using AI to automate mass-publishing. Notable reports include Apiiro (100,000+ repos, Feb 2024), Kaspersky (gaming mods, Feb 2025), Microsoft, Trend Micro (SmartLoader dropping LummaStealer, Mar 2025), Sophos (Jun 2025), Prodaft (CastleLoader, Jul 2025), DataDog (ClickFix tricks, Feb 2026).

Windows / AD Security

Microsoft Account Sign-In Emergency Fix (KB5085516)

Microsoft released emergency out-of-band update KB5085516 to fix sign-in failures with Microsoft accounts across Teams, OneDrive, Edge, Microsoft 365 Copilot, Excel, and Word. Issue triggered by KB5079473 cumulative update from March Patch Tuesday. Affected apps display "You'll need the Internet for this" error despite active internet connection. Only impacts Microsoft account sign-ins (Teams Free users), not Entra ID business authentication. Microsoft initially recommended restarting PCs as workaround. KB5085516 rolled out over the weekend and includes all Patch Tuesday security updates.

Russian Intelligence Targeting Signal and WhatsApp

FBI and CISA warn Russian intelligence-affiliated actors are posing as customer support on Signal and WhatsApp to conduct phishing attacks. Attackers target high-value individuals (current and former government officials, military, politicians, journalists). Thousands of accounts compromised. Attackers send messages about "suspicious activity" with verification links. Victims clicking links have their accounts connected to attacker accounts, or submit credentials/2FA codes for full takeover. Signal encryption remains secure, but social engineering bypasses technical protections.

General Security News

Microsoft Promises Windows 11 Quality Improvements

Microsoft acknowledged Windows 11 quality issues and outlined improvement plans. Changes include more taskbar customization (vertical and top positions, a feature from Windows 95), reduced Copilot entry points (removing from Snipping Tool, Photos, Widgets, Notepad), faster File Explorer with reduced flicker and lower search latency, lower baseline memory footprint (commercial necessity as RAM now accounts for over a third of PC price), improved Bluetooth and wake-from-sleep reliability, less intrusive widgets, and one-reboot-a-month option for Windows Update. Windows Subsystem for Linux getting faster file performance, improved networking, streamlined setup, and better enterprise management. Changes coming to Insider preview builds in March and April, unclear when they reach general releases.

Patch Priority

Vulnerability Disclosures

Microsoft Edge Chromium Updates

Microsoft Edge ingested Chromium updates addressing six CVEs: CVE-2026-4464 (integer overflow in ANGLE), CVE-2026-4462 (out of bounds read in Blink), CVE-2026-4461 (inappropriate implementation in V8), CVE-2026-4456 (use after free in Digital Credentials API), CVE-2026-4457 (type confusion in V8), CVE-2026-4451 (insufficient validation in Navigation). All have low EPSS scores (0.001, 22-28th percentile). See Google Chrome Releases for details.

Trends & Context

DarkSword and VoidStealer represent continued evolution in bypassing mobile and browser security protections. The Trivy supply chain attack demonstrates credential harvesting has long-tail impacts, with tokens stolen months ago now weaponized for infrastructure attacks. GitHub's transformation into a malware distribution platform shows attackers exploiting user trust in legitimate software hosting. Iranian and Russian intelligence groups maintain aggressive phishing and infrastructure attacks despite law enforcement domain seizures.