CVE-2023-4966, CVE-2025-5777, CVE-2025-6543, CVE-2025-66376, CVE-2026-20131, CVE-2026-22557, CVE-2026-3055, CVE-2026-32746, CVE-2026-33017, CVE-2026-3564, CVE-2026-4368, CVE-2026-4437, CVE-2026-4438
Domains:
smartvault[.]im, irs-doc[.]com, gov-irs216[.]net., ua5v[.]com.
Get tomorrow's brief in your inbox
Today: ConnectWise and Citrix patch critical remote access flaws while attackers weaponize Trivy scanner in supply chain attack stealing CI/CD secrets. Microsoft's Defender stops GPO-based ransomware pre-deployment. Initial access broker sentenced to 81 months for enabling $9M in ransomware damage. IRS phishing campaign hits 29,000 users with RMM malware.
ConnectWise ScreenConnect Cryptographic Flaw (CVE-2026-3564)
ConnectWise patched a critical signature verification flaw in ScreenConnect that lets attackers extract machine keys to authenticate sessions without authorization. The vulnerability affects the remote access platform widely deployed by MSPs and IT teams for remote support. Successful exploitation grants elevated privileges on affected instances.
Citrix NetScaler Memory Leak (CVE-2026-3055)
Citrix warns of a critical unauthenticated memory overread flaw allowing remote attackers to leak sensitive data from NetScaler ADC and Gateway appliances. The vulnerability (CVSS 9.3) affects devices configured as SAML Identity Providers. Exploitation requires no authentication but needs specific SAML IDP configuration. Rapid7 notes the similarity to previous Citrix Bleed attacks that led to widespread compromise. CVE-2026-4368, a race condition causing session mixup, was also patched.
grep "add authentication samlIdPProfile" /nsconfig/ns.conf. Assume active exploitation given Citrix's history (CVE-2023-4966, CVE-2025-5777, CVE-2025-6543 all exploited in wild).Zimbra XSS Under Active Exploitation (CVE-2025-66376)
Zimbra confirms active exploitation of a stored cross-site scripting flaw in Collaboration Suite. Malicious emails execute code when viewed in the Classic UI, exposing session cookies and mailbox data. The vulnerability was added to CISA KEV with deadline April 1. EPSS score of 0.100 (93rd percentile) reflects real-world abuse.
Langflow RCE Exploited Within 20 Hours (CVE-2026-33017)
Attackers weaponized a critical unauthenticated remote code execution flaw in Langflow, an open-source AI agent framework, within 20 hours of disclosure. The vulnerability allows arbitrary Python execution on exposed instances through a single crafted request. Check Point IPS provides protection. EPSS score 0.005 (64th percentile).
Ubiquiti UniFi Path Traversal (CVE-2026-22557)
Ubiquiti addressed a maximum-severity unauthenticated path traversal bug in UniFi Network Application (version 10.1.85 and earlier). The flaw allows attackers to access files, compromise accounts, and potentially seize control of underlying systems managing access points, switches, and gateways.
GNU InetUtils Telnetd RCE (CVE-2026-32746)
GNU InetUtils telnetd is affected by a CVSS 9.8 remote code execution flaw impacting all versions up to 2.7. The vulnerability allows remote attackers to trigger code execution. EPSS score 0.000 (7th percentile).
CISA KEV: CVE-2026-20131
CVE-2026-20131 added to CISA KEV catalog with deadline March 22 (now overdue for federal agencies). The vulnerability is ransomware-linked with EPSS score 0.006 (71st percentile).
Microsoft Defender Blocks GPO-Based Ransomware Pre-Deployment
Microsoft published a case study showing how Defender's predictive shielding stopped a human-operated ransomware attack targeting a large educational institution (2,000+ devices). The attacker weaponized Group Policy Objects to tamper with security controls and distribute ransomware via scheduled tasks. Defender detected the attack before ransomware deployment and proactively hardened 700 devices against malicious GPO propagation. The attack progression: unmanaged device with compromised Domain Admin, AD enumeration on Day 1, credential access and lateral movement on Day 2 (attack disruption initiated), GPO weaponization on Day 5. Defender blocked 97% of encryption activity with zero machines encrypted via GPO path.
Russian Initial Access Broker Sentenced to 81 Months
Aleksei Volkov, 26, of St. Petersburg, Russia, was sentenced to 81 months in prison for enabling Yanluowang ransomware attacks causing $9M in actual losses and $24M in intended losses. Volkov operated as an initial access broker, finding vulnerabilities in corporate networks and selling access to ransomware groups. Co-conspirators deployed malware, encrypted victim data, and demanded ransoms (sometimes tens of millions) in cryptocurrency. Volkov received a share of ransom payments. He agreed to pay $9.16M restitution and forfeit equipment. Arrested in Rome in January 2024, extradited to U.S., and pleaded guilty in November 2025.
Third BlackCat Negotiator Charged
U.S. prosecutors charged Angelo Martino, 41, as a third ransomware negotiator for BlackCat (ALPHV), helping extort higher payouts from at least 10 victims. Martino worked as a negotiator for DigitalMint. Authorities seized $9.2M in cryptocurrency (Bitcoin, Monero, Ripple, Solana, Stellar) from 21 wallets, plus luxury vehicles and properties. He faces up to 20 years in prison. Two other incident responders, Ryan Clifford Goldberg and Kevin Tyler Martin, pleaded guilty in December 2025. DigitalMint terminated both Martino and Martin, stating the actions violated company policy and ethical standards.
Australian Council Obtains Injunction Against Ransomware Actors
Fairfield Council (western Sydney) obtained a court injunction prohibiting publication of stolen data following an October 2025 ransomware incident. The council's servers containing personal, financial, and property information about councillors, ratepayers, residents, and staff were illegally accessed. Attackers left a ransom note threatening to publish data if the council didn't communicate via a specified chatroom. The council communicated with anonymous hackers by sending Dropbox links into the chatroom. The court issued interim orders restraining the defendants from placing information at any internet location (including dark web), transmitting or disclosing data, or promoting download links. The injunction follows a similar approach used by Qantas in 2025.
Trio-Tech International Reverses Materiality Assessment
California-based semiconductor testing firm Trio-Tech initially shrugged off a March 11 ransomware attack at its Singapore subsidiary as immaterial. The company reversed course March 18 after stolen data was disclosed publicly. The incident affected "certain files" on the network. Trio-Tech detected the incident, took systems offline, and called in cybersecurity help. Singapore law enforcement was notified. The company claims business operations remain largely unscathed and expects no significant impact to Q1 financial results ending March 31.
3.7 Million Telehealth Patients Affected by Two Breaches
Threat actor "Stuckin2019" listed patient data from OpenLoop Health (1.6M patients) and Zealthy (2.1M patients) for sale on hacking forums. OpenLoop data included names, email addresses, postal addresses, heights, weights, medical information, and biometric data. Zealthy data included full names, email addresses, phone numbers, addresses, driver's licenses, and patient information. OpenLoop notified Texas AG (68,160 affected) and California AG, stating breach occurred January 7-8. According to Stuckin2019, OpenLoop agreed to pay and the data were deleted (only 2 proof samples remain). Zealthy reportedly locked the attacker out but did not reply to emails. Zealthy listing remains active on forums with driver's license images and PHI.
Woundtech Breach Exposes 928K Wound Care Patients
Florida-based Wound Technology Network was breached December 6-9, 2025, by FulcrumSec threat actors. The attack exposed 928,073 unique patient IDs from Snowflake database exports spanning 4+ years of wound care operations. Exfiltrated data includes clinical wound assessment notes, wound photographs (JPEG/PNG), PDF referral/intake documents, 86,377 named patients with full demographics, and approximately 300 SSNs. FulcrumSec provided extensive forensic analysis showing they extracted 335 GB from a 6.7 TB S3 bucket. Entry vector was a vulnerable React host with plaintext AWS/database credentials. Woundtech detected the intrusion and patched within 24 hours, making this "the first time any company, ever, has rotated AWS credentials before we completed exfiltration," but FulcrumSec had already exfiltrated over 100 GB. FulcrumSec offered Woundtech the opportunity to redact patient data before publication. Notifications to regulators and patients occurred more than three months after discovery.
Trivy Supply Chain Attack Spreads to Docker and GitHub
TeamPCP hackers backdoored Trivy, a widely used open-source vulnerability scanner with 33,800+ GitHub stars and 100M+ Docker Hub downloads, injecting credential-stealing malware into official releases and GitHub Actions. The breach has triggered cascading supply-chain compromises as impacted projects failed to rotate secrets, resulting in a self-propagating worm dubbed CanisterWorm. Attackers pushed malicious Docker images (tags 0.69.5 and 0.69.6) on March 22 without corresponding GitHub releases. TeamPCP gained access by compromising Aqua Security's GitHub organization due to incomplete containment of a previous incident. On March 22, attackers re-established access to Aqua's aquasec-com GitHub organization (proprietary code, separate from public aquasecurity org), adding prefix "tpcp-docs-" to all 44 repositories and changing descriptions to "TeamPCP Owns Aqua Security." The compromise stemmed from a service account (Argon-DevOps-Mgt) using a long-lived Personal Access Token without MFA protection. Researchers believe hackers obtained the PAT using TeamPCP Cloud stealer, which collects GitHub tokens, SSH keys, and cloud credentials.
IRS Phishing Campaign Deploys RMM Malware to 29,000 Users
Microsoft reports fresh tax-themed phishing campaigns capitalizing on U.S. tax season to harvest credentials and deploy RMM malware. A large-scale campaign on February 10 affected 29,000 users across 10,000 organizations (95% in U.S.). Emails impersonated IRS claiming irregular tax returns were filed under recipient's EFIN, instructing users to download "IRS Transcript Viewer." Emails sent via Amazon SES contained a button redirecting to smartvault[.]im (masquerading as SmartVault document platform). The site used Cloudflare to block bots and serve malicious ScreenConnect payloads to human users. Other campaigns delivered ConnectWise ScreenConnect, Datto, and SimpleHelp RMM tools for persistent access. Campaigns used CPA lures, QR codes, W2 forms, and tax-themed domains. PhaaS platforms Energy365 (hundreds of thousands of daily emails) and SneakyLog/Kratos were used for credential harvesting. Targets spanned financial services (19%), technology (18%), retail (15%), manufacturing, and healthcare.
Railway PaaS Abused for AI-Powered Phishing
An AI-powered phishing campaign tied to Railway cloud-hosting service has compromised hundreds of organizations in the past few weeks. Huntress researchers report the campaign exploited Microsoft's device authentication flow (smart TVs, printers, terminals) to obtain valid OAuth tokens lasting up to 90 days without passwords or MFA. The campaign uses unique email templates and domains (no duplicates), suggesting AI generation. Starting March 3, compromise tempo surged from dozens per day to hundreds. Huntress issued a conditional access policy update to 60,000 Microsoft cloud tenants blocking Railway domains. Victims span 344 entities: construction, law firms, nonprofits, real estate, manufacturing, finance, healthcare, government, and public safety. Attackers weaponized Railway's Platform as a Service to spin up credential harvesting infrastructure. Railway banned associated accounts and blocked domains after Huntress notification on March 6, but Huntress continued observing 50+ daily compromises tied to Railway domains.
DoJ Takes Down DDoS Botnets
Law enforcement wiped AISURU, Kimwolf, JackSkid, and Mossad botnets behind some of the largest DDoS attacks ever recorded. The botnets amassed 3M+ infected devices (routers, IP cameras, DVRs with weak credentials and rare patching). Authorities removed command-and-control servers. Operators sold botnet access to other criminals who targeted victims including U.S. DoD systems. Some DDoS attacks caused hundreds of thousands of dollars in losses through remediation expenses or ransom demands. No arrests announced, but two suspects associated with AISURU/Kimwolf are based in Canada and Germany. All four botnets are Mirai variants (source code leaked in 2016).
Mazda Discloses Breach Exposing 692 Records
Mazda Motor Corporation announced a breach after attackers exploited a vulnerability in a warehouse management system for parts from Thailand. The breach exposed 692 records including user IDs, full names, email addresses, company names, and business partner IDs. No customer data was affected. Mazda notified Japan's Personal Information Protection Commission and implemented additional security measures: reduced internet exposure, applied security patches, increased monitoring, and stricter access policies. No misuse detected. Clop ransomware group listed Mazda.com and MazdaUSA.com on leak site in November 2025, though Mazda never officially confirmed that incident.
Navia Benefit Solutions Breach Affects 2.6M
U.S.-based employee benefits administrator disclosed a breach affecting 2.6M+ individuals after unauthorized access and potential data exfiltration occurred December 22, 2025 - January 15, 2026. Exposed information may include personal, health, and benefits data.
Aura Breach Exposes 900K Records
Identity protection firm Aura was breached after a phone phishing attack let an intruder access an employee account and marketing platform. The actor obtained 900,000 records (mostly names and emails). Core systems and identity protection services were not compromised.
Puerto Rico Water Authority Confirms Cyberattack
Puerto Rico Aqueduct and Sewer Authority, which manages the territory's water supply, confirmed a cyberattack exposing customer and employee information. Network segmentation limited the incident to business data and administrative environments. Critical infrastructure was unaffected.
Intuitive Robotic Surgery Breach
U.S.-based robotic surgery company Intuitive suffered a data breach after a targeted phishing incident led to a compromised employee account. Exposed information includes customer contact details, employee data, and corporate records. The company says da Vinci and Ion surgical platforms were unaffected.
Schools Targeted in Rising Cyberattacks
Hackers increasingly target school districts as easy sources of personal data. A nationwide data breach exposed millions of K-12 students' information in Cranford and Millburn, NJ. Check Point reports U.S. schools now see 3,000+ attack attempts weekly. New Jersey signed on as a statewide member of Multi-State Information Sharing and Analysis Center (MS-ISAC) in November 2025, paying $795K annually covering 1,354 eligible organizations, but only 177 have signed up. Nearly 60% of IT and security professionals have been told to keep breaches confidential (38% increase since 2023), creating a "culture of silence" that allows cyberthreats to proliferate. Recent Texas incidents (Valley View ISD, Eanes ISD, Clarksville ISD) describe operational impacts while withholding technical specifics. Ransomware claims later circulated online but districts never publicly acknowledged them.
GitHub Malware Problem
GitHub is becoming a distribution platform for malware disguised as legitimate software repositories. What started as infrequent sightings in early 2024 is now at the center of increasing infosec reports. Threat actors take legitimate repositories, add malware (typically infostealers or RATs), and upload boobytrapped repos back to GitHub. Attackers share links via social media, forums, black-hat SEO, or malvertising campaigns to lure users to malicious repos.
Copyright Infringement Phishing Campaign
A phishing campaign targets healthcare, government, hospitality, and education sectors across multiple countries using copyright infringement notices to hide infostealers. The campaign uses several evasion techniques to avoid detection.
Microsoft Exchange Online Service Issue
Microsoft is addressing an ongoing service issue (EX1256020) that has intermittently prevented users from accessing Exchange Online mailboxes via Outlook mobile and Mac clients since Thursday. The root cause was a newly introduced virtual account. Microsoft is reverting the change after failing to fix the problem by restarting infrastructure. The company flagged this as an incident (indicating critical user impact). This follows another Exchange Online outage one week ago preventing mailbox and calendar access, and a January incident blocking email via IMAP4.
Windows 11 Promises vs. Reality
Windows boss Pavan Davuluri posted lengthy promises to fix Windows 11's failings but offered no apologies for bugs and unwanted AI. Promises include: movable taskbar returning, reduced Windows Update forced restarts, File Explorer fixes, lower resource usage, and faster performance. Microsoft will reduce "unnecessary Copilot entry points" in Snipping Tool, Photos, Widgets, and Notepad. Davuluri wrote Windows is "evolving into an agentic OS" in November 2025, read negative comments, and acknowledged unhappiness four months later. Changes will unfold over 2026, meaning long waits before users feel impact. Missing from post: "sorry," "apologize," or acknowledgment of QA failures.
Microsoft Fixes Broken Update Days After Promising Fewer Broken Updates
Microsoft released an out-of-band update to resolve bugs introduced by March 2026 security update, days after promising improved reliability. The fix addresses a "no internet" error when signing into Microsoft apps despite working connections (Microsoft Entra ID users unaffected). The out-of-band update includes everything in March 10 security update plus the fix. This comes days after Windows boss promised an era of reliability and stability. Users downloading another out-of-band fix might prefer Microsoft focus on shipping code that works.
CVE-2026-4438 and CVE-2026-4437
Microsoft published advisories for CVE-2026-4438 (gethostbyaddr and gethostbyaddr_r return invalid DNS hostnames) and CVE-2026-4437 (gethostbyaddr and gethostbyaddr_r may incorrectly handle DNS response). Both have low EPSS scores (0.000, 11th and 5th percentiles respectively).
Mandiant M-Trends 2026: Diverging Adversary Timelines
Google's Mandiant released M-Trends 2026 based on 500,000+ hours of incident investigations in 2025. Key findings: global median dwell time rose to 14 days from 11 days (cyber espionage and North Korean IT worker incidents had 122-day median). Exploits remained top initial infection vector (32%, sixth consecutive year). Voice phishing surged to 11% (second-most common), becoming No. 1 tactic for cloud break-ins. Email phishing dropped to 6%. Organizations detected 52% of intrusions internally (up from 43% in 2024). High tech sector (17%) became most-targeted industry, displacing financial sector (14.6%). The "hand-off" window collapsed from 8+ hours in 2022 to 22 seconds in 2025, as initial access partners pre-stage secondary group's tools during initial infection. Prior compromise ranked third initial infection vector (10%) globally and top in ransomware (30%, doubling from 15% in 2024). Adversaries optimize for extremes: cybercriminals optimize for speed and recovery denial; espionage groups optimize for extreme persistence using unmonitored edge devices.
Talos Year in Review: Lightning-Fast Exploits
Cisco Talos published its 2025 review describing a year of pace and scale that put pressure on security teams, partly due to attackers' use of AI. Talos was shocked by how quickly criminals weaponized vulnerabilities, pointing to December's React2Shell becoming the most-targeted vuln of the year despite December disclosure. "Near-instant weaponization" is driven by automated tooling and widespread internet exposure, leaving defenders little to no time between disclosure and active abuse. Attackers settled on identity control points as primary targets. Compromising VPNs or ADCs means easy lateral movement, enhanced access, MFA bypass, and persistence. Network management software (vCenter, Cisco Security Manager, Aria Operations) is less tightly monitored than edge appliances. Phishing began 40% of intrusion cases in 2025. Modern phishing lures are more sophisticated (AI helps overcome language barriers). Messages came from spoofed or compromised accounts 75% of the time. AI primarily improved elements of existing attacks in 2025, but Talos predicts AI will soon become fundamental back-end cybercrime infrastructure.
CrowdStrike Falcon Next-Gen SIEM Supports Third-Party EDR
CrowdStrike is expanding Falcon Next-Gen SIEM to support third-party EDR solutions starting with Microsoft Defender, with no Falcon sensor required. This enables organizations to modernize SOC without replacing existing endpoint agents. New enhancements include Falcon Onum (real-time data control delivering up to 5x faster streaming and 50% storage cost reduction), federated search (investigate everywhere, ingest what matters), and third-party intelligence integration.
Google Unleashes Gemini AI on Dark Web
Google's Gemini AI agents crawl the dark web analyzing 8-10 million posts daily to find threats relevant to specific organizations. Available now in public preview, the dark web intelligence service built into Google Threat Intelligence uses Gemini to build organization profiles and scour the dark web for security risks. Internal tests show 98% accuracy. Traditional dark-web monitoring tools mostly scrape for key terms using regex, generating 80-90% false positives. Gemini builds customer profiles within minutes, returns alerts going back seven days, and performs vector comparison to detect stolen data or malicious activity. The service tracks initial access broker activity, data leaks, insider threats, and other intel. Gemini also pulls in knowledge from Google Threat Intelligence Group's 627 tracked threat groups.
AWS Bedrock Attack Vectors
XM Cyber threat research team identified eight attack vectors in AWS Bedrock environments spanning log manipulation, knowledge base compromise, agent hijacking, flow injection, guardrail degradation, and prompt poisoning. Vectors include: (1) Model invocation log attacks redirecting logs to attacker-controlled buckets or scrubbing evidence, (2) Knowledge Base data source attacks bypassing models to pull raw data or stealing SaaS credentials for lateral movement, (3) Knowledge Base data store attacks intercepting credentials for vector databases (Pinecone, Redis) or AWS-native stores (Aurora, Redshift), (4) Direct agent attacks rewriting base prompts or attaching malicious executors, (5) Indirect agent attacks via Lambda function code updates. Each vector starts with low-level permissions and ends at critical assets.
Passwordless Authentication Research
Palo Alto Networks Unit 42 published Part 2 of passkey security research examining Google Authenticator and synced passkeys. The research explores hidden mechanisms behind synced passkeys and their implementation within the Google ecosystem. Whenever users authenticate with passkeys backed by Google Password Manager across desktop platforms, a connection is made to enclave.ua5v[.]com. As of January 2026, searching for this domain yields little public information despite powering logins worldwide. The research deliberately thinks like attackers, asking where passkeys live, how they move, how they sync, and which components handle sensitive operations. This revealed a surprisingly broad and largely unexplored attack surface.
OpenAI ChatGPT Library Feature
OpenAI rolled out a new feature called Library for ChatGPT allowing users to store personal files or images on OpenAI's cloud storage. The feature requires Plus, Pro, and Business tiers and is rolling out globally except EEA, Switzerland, and UK. ChatGPT automatically saves uploaded and created files in a dedicated, secure location so they can be accessed later. By default, GPT saves uploaded files including documents, spreadsheets, presentations, and images. Deleting a chat containing a file does not delete files saved to Library. Users must manually delete files. OpenAI removes files from servers within 30 days of deletion.
EU Broadcasters Warn on Smart TV Gatekeepers
Europe's broadcasters say smart TVs and voice assistants are becoming the next Big Tech gatekeepers with little sign of Brussels intervention. An open letter to European Commission executive vice-president Teresa Ribera urges bringing connected TV operating systems and virtual assistants within Digital Markets Act scope. The concern is the software layer deciding what gets shown (recommendations, search, app visibility) now controls access in the same way app stores and search engines do, but without the same regulatory scrutiny. No connected TV platforms or virtual assistants have been designated as gatekeepers. Broadcasters fear being quietly edged out of view on devices audiences use to access TV and radio.
CVE-2026-3564 (ConnectWise ScreenConnect) - Critical cryptographic signature verification flaw allowing session authentication without authorization and privilege escalation. Widely deployed by MSPs.
CVE-2026-3055 (Citrix NetScaler) - CVSS 9.3 unauthenticated memory overread allowing sensitive data leaks from ADC/Gateway appliances configured as SAML IDPs. Similar to Citrix Bleed attacks. Patch to 14.1-66.59 or 13.1-62.23.
CVE-2026-4368 (Citrix NetScaler) - CVSS 7.7 race condition leading to user session mixup on Gateway/AAA configurations. Patch to 14.1-66.59 or 13.1-62.23.
CVE-2025-66376 (Zimbra) - Stored XSS under active exploitation, CISA KEV deadline April 1, EPSS 0.100 (93rd percentile). Patch to 10.1.13 or 10.0.18.
CVE-2026-33017 (Langflow) - Critical unauthenticated RCE in AI agent framework, weaponized within 20 hours of disclosure, EPSS 0.005 (64th percentile). Check Point IPS provides protection.
CVE-2026-22557 (Ubiquiti UniFi) - Maximum-severity unauthenticated path traversal in UniFi Network Application 10.1.85 and earlier allowing file access, account compromise, and system control.
CVE-2026-32746 (GNU InetUtils) - CVSS 9.8 RCE in telnetd affecting all versions up to 2.7, EPSS 0.000 (7th percentile). Disable telnetd immediately.
CVE-2026-20131 - Added to CISA KEV with deadline March 22, ransomware-linked, EPSS 0.006 (71st percentile).
CVE-2026-4438 - gethostbyaddr and gethostbyaddr_r return invalid DNS hostnames, EPSS 0.000 (11th percentile).
CVE-2026-4437 - gethostbyaddr and gethostbyaddr_r may incorrectly handle DNS response, EPSS 0.000 (5th percentile).
Voice phishing surged in 2025 to become the second-most common initial access method across all incidents and the top tactic for cloud break-ins, while email phishing dropped to just 6% as AI helps attackers overcome language barriers and mimic business communications. The "hand-off" window between initial access and ransomware deployment collapsed from 8+ hours in 2022 to 22 seconds in 2025, as attackers pre-stage secondary payloads during initial infection. Supply-chain attacks targeting developer infrastructure (Trivy) and tax-themed phishing deploying RMM tools demonstrate how attackers blend legitimate services and social engineering at scale, forcing defenders to balance patching speed against increasingly sophisticated threats that weaponize vulnerabilities within hours of disclosure.