CVE-2025-14174, CVE-2025-31277, CVE-2025-32975, CVE-2025-43510, CVE-2025-43520, CVE-2025-43529, CVE-2026-20700, CVE-2026-21992, CVE-2026-4451, CVE-2026-4456, CVE-2026-4457, CVE-2026-4461, CVE-2026-4462, CVE-2026-4464
Domains:
225[.]156, handala-redwanted[.]to, handala-hack[.]to, justicehomeland[.]org, karmabelow80[.]org
Get tomorrow's brief in your inbox
March 23, 2026
Today: CISA orders federal agencies to patch DarkSword iOS exploits by April 3rd, Microsoft releases emergency fix for account sign-in failures, and critical Oracle Identity Manager flaw gets out-of-band patch. Trivy supply chain attack expands with Docker Hub malware, Quest KACE vulnerability under active exploitation, and VoidStealer bypasses Chrome encryption via debugger tricks.
DarkSword iOS Exploit Kit (CVE-2025-31277, CVE-2025-43510, CVE-2025-43520)
CISA added three iOS vulnerabilities to the Known Exploited Vulnerabilities catalog after DarkSword exploit kit was used in cryptocurrency theft and espionage campaigns. The exploit chain allows attackers to escape sandboxes, escalate privileges, and execute code remotely on iPhones running iOS 18.4 through 18.7. Threat groups UNC6748 (linked to Turkish surveillance vendor PARS Defense) and UNC6353 (suspected Russian espionage) deployed three malware families: GhostBlade JavaScript infostealer, GhostKnife backdoor, and GhostSaber. UNC6353 used both DarkSword and Coruna exploit kits in watering-hole attacks targeting Ukrainian e-commerce and industrial sites. DarkSword wipes temporary files after data theft to evade detection. Three additional CVEs (CVE-2026-20700, CVE-2025-43529, CVE-2025-14174) are part of the chain but KEV addition focused on the three with April 3 deadline.
Oracle Identity Manager Critical RCE (CVE-2026-21992)
Oracle released emergency out-of-band patch for CVE-2026-21992, a maximum-severity authentication bypass vulnerability in Oracle Identity Manager. The flaw allows remote code execution without authentication and may have been exploited in the wild. EPSS score is 0.000 (7th percentile), indicating this is a very recent disclosure.
Quest KACE SMA Exploitation (CVE-2025-32975)
Arctic Wolf observed active exploitation of CVE-2025-32975 (CVSS 10.0) starting the week of March 9. Attackers use authentication bypass to seize administrative accounts, execute remote commands, drop Base64-encoded payloads from 216.126.225[.]156, create admin accounts via runkbot.exe, harvest credentials with Mimikatz, and obtain RDP access to backup infrastructure (Veeam, Veritas) and domain controllers. Attackers modified Windows Registry via PowerShell for persistence.
8 claims tracked across 2 groups in the last 48 hours. These are unverified claims from ransomware leak sites.
| Group | Victim | Sector | Country |
|---|---|---|---|
| leakeddata | W... S... H... | Unknown | Unknown |
| leakeddata | HEMIC (Hawaii Employers' Mutual Insurance Co) | Insurance | USA |
| leakeddata | Nations Financial Group Inc | Financial Services | USA |
| leakeddata | Two River Group Holdings LLC | Life Sciences | USA |
| leakeddata | Plaza Home Mortgage | Financial Services | USA |
| leakeddata | Singleton Schreiber | Legal | USA |
| leakeddata | Wood Smith Henning & Berman LLP | Legal | USA |
| leakeddata | Phelps Dunbar | Legal | USA |
| alp-001 | irco.com | Unknown | USA |
| alp-001 | hikvision.com | Technology | Unknown |
Note: "alp-001" claimed irco.com with revenue $7.7 billion and 5.9 TB of data staged.
Trivy Supply Chain Attack Expands
Trivy vulnerability scanner compromise extended to Docker Hub with malicious versions 0.69.4, 0.69.5, and 0.69.6 containing TeamPCP infostealer. Last clean release was 0.69.3. Attackers defaced all 44 internal repositories in Aqua Security's "aquasec-com" GitHub organization in a 2-minute scripted burst on March 22 using compromised "Argon-DevOps-Mgt" service account. This account bridges both GitHub organizations, giving attackers write/admin access to both with a single token. TeamPCP deployed CanisterWorm self-propagating worm across dozens of npm packages. New wiper malware spreads via SSH using stolen keys and exploits exposed Docker APIs on port 2375. On Kubernetes clusters in Iran, malware deploys privileged DaemonSets, wipes Iranian nodes via "kamikaze" containers, and installs CanisterWorm backdoor on non-Iranian nodes as systemd service.
VoidStealer Bypasses Chrome Encryption
VoidStealer infostealer uses hardware breakpoints to extract Chrome's v20_master_key directly from browser memory, bypassing Application-Bound Encryption (ABE) without privilege escalation or code injection. This is the first observed in-the-wild use of this debugger-based technique. VoidStealer starts a suspended hidden browser process, attaches as debugger, waits for chrome.dll or msedge.dll to load, scans for specific LEA instruction, sets hardware breakpoint, and reads the register holding plaintext master key during browser startup when ABE-protected cookies are decrypted. Gen Digital notes VoidStealer likely adopted this from the open-source ElevationKatz project (part of ChromeKatz toolset), which has been available for over a year. VoidStealer is a MaaS platform advertised on dark web forums since mid-December 2025, with version 2.0 introducing the ABE bypass.
Iranian Handala Hackers Using Telegram C2
FBI warns Iranian MOIS-linked Handala hacktivist group is using Telegram as C2 infrastructure for malware targeting journalists, Iranian dissidents, and opposition groups worldwide. The group uses social engineering to deliver Windows malware for screenshot and file exfiltration. FBI seized four domains on March 21: handala-redwanted[.]to, handala-hack[.]to, justicehomeland[.]org, and karmabelow80[.]org used by Handala, Homeland Justice (IRGC-linked), and Karma Below for data leaks and stolen document publication. Handala previously attacked Stryker with Microsoft Intune wipe command, factory resetting 80,000 devices after compromising Windows domain admin and creating Global Administrator account.
GitHub Malware Distribution Epidemic
GitHub malware distribution campaigns have escalated from occasional sightings in early 2024 to widespread abuse. Threat actors clone legitimate repositories, add infostealers or RATs, and use black-hat SEO, malvertising, fake GitHub stars, and meaningless commits to keep malicious repos at top of search results. Users assume they landed on legitimate software developer pages. Campaigns target gaming cheats, license cracks, system tools, and macOS users. Security vendors report campaigns ranging from hundreds to thousands of repos, with some using AI to automate mass-publishing. Notable reports include Apiiro (100,000+ repos, Feb 2024), Kaspersky (gaming mods, Feb 2025), Microsoft, Trend Micro (SmartLoader dropping LummaStealer, Mar 2025), Sophos (Jun 2025), Prodaft (CastleLoader, Jul 2025), DataDog (ClickFix tricks, Feb 2026).
Microsoft Account Sign-In Emergency Fix (KB5085516)
Microsoft released emergency out-of-band update KB5085516 to fix sign-in failures with Microsoft accounts across Teams, OneDrive, Edge, Microsoft 365 Copilot, Excel, and Word. Issue triggered by KB5079473 cumulative update from March Patch Tuesday. Affected apps display "You'll need the Internet for this" error despite active internet connection. Only impacts Microsoft account sign-ins (Teams Free users), not Entra ID business authentication. Microsoft initially recommended restarting PCs as workaround. KB5085516 rolled out over the weekend and includes all Patch Tuesday security updates.
Russian Intelligence Targeting Signal and WhatsApp
FBI and CISA warn Russian intelligence-affiliated actors are posing as customer support on Signal and WhatsApp to conduct phishing attacks. Attackers target high-value individuals (current and former government officials, military, politicians, journalists). Thousands of accounts compromised. Attackers send messages about "suspicious activity" with verification links. Victims clicking links have their accounts connected to attacker accounts, or submit credentials/2FA codes for full takeover. Signal encryption remains secure, but social engineering bypasses technical protections.
Microsoft Promises Windows 11 Quality Improvements
Microsoft acknowledged Windows 11 quality issues and outlined improvement plans. Changes include more taskbar customization (vertical and top positions, a feature from Windows 95), reduced Copilot entry points (removing from Snipping Tool, Photos, Widgets, Notepad), faster File Explorer with reduced flicker and lower search latency, lower baseline memory footprint (commercial necessity as RAM now accounts for over a third of PC price), improved Bluetooth and wake-from-sleep reliability, less intrusive widgets, and one-reboot-a-month option for Windows Update. Windows Subsystem for Linux getting faster file performance, improved networking, streamlined setup, and better enterprise management. Changes coming to Insider preview builds in March and April, unclear when they reach general releases.
Microsoft Edge Chromium Updates
Microsoft Edge ingested Chromium updates addressing six CVEs: CVE-2026-4464 (integer overflow in ANGLE), CVE-2026-4462 (out of bounds read in Blink), CVE-2026-4461 (inappropriate implementation in V8), CVE-2026-4456 (use after free in Digital Credentials API), CVE-2026-4457 (type confusion in V8), CVE-2026-4451 (insufficient validation in Navigation). All have low EPSS scores (0.001, 22-28th percentile). See Google Chrome Releases for details.
DarkSword and VoidStealer represent continued evolution in bypassing mobile and browser security protections. The Trivy supply chain attack demonstrates credential harvesting has long-tail impacts, with tokens stolen months ago now weaponized for infrastructure attacks. GitHub's transformation into a malware distribution platform shows attackers exploiting user trust in legitimate software hosting. Iranian and Russian intelligence groups maintain aggressive phishing and infrastructure attacks despite law enforcement domain seizures.