CVE-2025-46817, CVE-2025-46818, CVE-2025-49844, CVE-2026-0716, CVE-2026-0819, CVE-2026-1005, CVE-2026-2369, CVE-2026-2417, CVE-2026-2443, CVE-2026-25075, CVE-2026-2645, CVE-2026-27623, CVE-2026-3099, CVE-2026-3229, CVE-2026-3230, CVE-2026-33055, CVE-2026-33056, CVE-2026-33634, CVE-2026-3549, CVE-2026-3650, CVE-2026-4159, CVE-2026-4395, CVE-2026-4424, CVE-2026-4426
Domains:
checkmarx[.]zone, bringetax[.]com, paloaltonetworks-careers[.]com
Get tomorrow's brief in your inbox
March 25, 2026
Today: Two Russian cybercriminals sentenced to prison for ransomware enabling, a massive supply chain attack weaponizes Trivy and Checkmarx security tools, and tax-themed malvertising delivers EDR-killing malware using a Huawei driver. Plus, Microsoft 365 identities under sustained phishing assault via Railway.com infrastructure, and the FCC bans all foreign-made routers over supply chain risks.
Trivy and Checkmarx GitHub Actions Supply Chain Compromise (CVE-2026-33634)
TeamPCP threat actors compromised Aqua Security's Trivy vulnerability scanner and Checkmarx security tools through stolen CI/CD credentials. The attackers force-pushed 76 of 77 version tags in trivy-action and all 7 tags in setup-trivy to malicious commits containing credential-stealing malware. A weaponized Trivy binary (v0.69.4) was published to GitHub Releases and container registries. The malware harvests SSH keys, cloud credentials (AWS, Azure, GCP), Kubernetes configs, database credentials, and cryptocurrency wallets from CI runner memory. Stolen data is exfiltrated to vendor-specific typosquat domains (checkmarx[.]zone) as encrypted archives. CVE-2026-33634 has a CVSS score of 9.4. The attack also compromised two Checkmarx GitHub Actions and VS Code extensions via the "cx-plugins-releases" service account. The malware checks for cloud provider credentials before fetching a next-stage payload and installing persistence via systemd or launchd.
Russian Access Broker Sentenced for Yanluowang Ransomware
Aleksey Volkov, 26, was sentenced to 81 months in federal prison for operating as an initial access broker for the Yanluowang ransomware group. Between July 2021 and November 2022, Volkov breached at least eight U.S. companies and sold network access to ransomware operators. Victims paid ransoms ranging from $300,000 to $15 million. Volkov received compensation through flat fees or percentage cuts of ransom payments, earning approximately $1.5 million. The FBI recovered chat logs, stolen data, and network credentials from a seized server, and traced Volkov through Apple iCloud data, cryptocurrency exchanges, and social media accounts linked to his Russian passport. Evidence suggests potential ties to the LockBit ransomware operation through recovered screenshots. The attacks resulted in over $9 million in confirmed losses and more than $24 million in intended losses. Volkov must pay full restitution to victims and forfeit equipment used in the crimes.
Russian Botnet Manager Sentenced for BitPaymer Ransomware Attacks
Ilya Angelov, 40, received a two-year prison sentence for managing a phishing botnet used in BitPaymer ransomware attacks against 72 U.S. companies. Angelov was a co-leader of the Mario Kart cybercrime gang (also tracked as TA551, Shathak, GOLD CABIN), which operated between 2017 and 2021. The operation sent 700,000 spam emails daily and infected approximately 3,000 computers per day at peak activity. The gang sold access to infected devices to ransomware-as-a-service operations, resulting in over $14 million in extortion payments from BitPaymer attacks between August 2018 and December 2019. The IcedID cybercrime gang paid the group another $1 million for bot access between late 2019 and August 2021. TA551 also collaborated with the TrickBot gang to deploy Conti ransomware and partnered in the Lockean ransomware operation, helping affiliates drop ProLock, Egregor, and DoppelPaymer ransomware on Qbot-infected devices.
Tax-Themed Malvertising Campaign Delivers EDR-Killing Malware
A large-scale malvertising campaign active since January 2026 targets users searching for tax forms like "W2 tax form" or "W-9 Tax Forms 2026" through Google Ads. Malicious sponsored results direct victims to fake sites protected by Adspect and JustCloakIt cloaking services to evade detection. The campaign delivers weaponized ConnectWise ScreenConnect installers that drop HwAudKiller, an EDR-killing tool using the bring your own vulnerable driver (BYOVD) technique with a legitimate Huawei audio driver (HWAuidoOs2Ec.sys). The malware terminates processes for Microsoft Defender, Kaspersky, and SentinelOne from kernel mode. Attackers also deploy FleetDeck Agent RMM for redundant access. The multi-stage crypter evades detection by allocating 2GB of memory filled with zeros to exhaust antivirus engines. Huntress identified over 60 malicious ScreenConnect sessions tied to the campaign. Post-compromise activity includes credential dumping from LSASS and network reconnaissance with NetExec, consistent with pre-ransomware or initial access broker tactics.
Railway.com PaaS Abused for Microsoft 365 Token Replay Attacks
Huntress reports an active device code phishing campaign targeting Microsoft 365 identities across more than 340 organizations in the US, Canada, Australia, New Zealand, and Germany. The campaign began February 19, 2026, and accelerated dramatically starting March 2. Attackers are attributed to the EvilTokens Phishing-as-a-Service platform, first advertised February 16, 2026. The platform provides AI-powered tools for bypassing email filtering, tailoring phishing lures, and wire fraud targeting. No two phishing lures are identical, with unprecedented variance that evades email filtering through personalization at scale. Threat actors weaponize Railway, a Platform-as-a-Service built for rapid deployment, to spin up on-demand credential-harvesting infrastructure. EvilTokens offers three products: B2B Sender, Office 365 Capture Link, and SMTP Sender, with features including AI workflows, Open Redirect links to vulnerable domains, and CloudFlare workers for credential theft. The platform has spun up 24/7 support and customer feedback channels. Huntress blocked 113 attempted compromises as of March 23 in addition to approximately 350 earlier compromises.
FCC Bans All Foreign-Made Routers Over Supply Chain Risks
The Federal Communications Commission issued a sweeping ban on all new foreign-manufactured consumer routers citing unacceptable cyber and national security risks. The ban applies to all consumer-grade routers produced in foreign countries unless granted Conditional Approval by the Department of War or Department of Homeland Security. The approved list currently includes only drone systems and software-defined radios from SiFly Aviation, Mobilicom, ScoutDI, and Verge Aero. Starlink routers are exempt as they are manufactured in Texas. The FCC cited exploitation of router vulnerabilities by state and non-state actors including Volt Typhoon, Flax Typhoon, Salt Typhoon, and CovertNetwork-1658 (Quad7) botnets used by Chinese threat actor Storm-0940. Routers have been used for network surveillance, data exfiltration, malware delivery, password spraying, and as proxies for espionage against critical infrastructure in energy, transportation, and water sectors. The ban does not affect previously purchased routers or retailer inventory of already-approved models. Critics warn the rule creates supply chain uncertainty and does not address fundamental router security weaknesses exploited in campaigns like Salt Typhoon, which succeeded through vulnerabilities in U.S. and Western products.
Palo Alto Networks Recruiting Scam Targets Senior Professionals
Unit 42 tracked sophisticated phishing campaigns since August 2025 where attackers impersonate Palo Alto Networks talent acquisition staff. The scams target senior-level professionals using scraped LinkedIn data for highly personalized lures. Attackers claim the victim's resume failed applicant tracking system (ATS) requirements and offer paid "executive ATS alignment" services ($400-$800). The scam uses flattering language, specific LinkedIn profile details, and legitimate company logos in email signatures to establish credibility. The "recruiter" manufactures urgency by claiming a review panel has already begun and hands off to a purported expert who can deliver results within hours. Attackers use look-alike domains instead of official @paloaltonetworks.com addresses and may include malware in fake ATS diagnostic reports or resume templates.
Microsoft Fixes Classic Outlook Gmail Sync Issues
Microsoft resolved a bug causing Gmail and Yahoo email synchronization problems for classic Outlook users. The issue triggered 0x800CCC0F and 0x80070057 error codes starting February 26, 2026. Affected accounts stopped syncing and users were not prompted to sign in when synchronization failed. Although Microsoft fixed the issue in the Microsoft 365 service on March 21, some customers may experience sync issues until their OAuth token expires, typically within one hour. Customers can force a sign-in prompt by changing their password or deleting registry entries under HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Identity\Identities. Microsoft is also investigating a bug causing "Can't connect to the server" errors when creating groups in classic Outlook with Exchange Web Services enabled, and addressing a mouse pointer disappearing issue in classic Outlook, OneNote, and other Microsoft 365 apps.
Huntress Managed ITDR Expands to Google Workspace
Huntress launched Managed Identity Threat Detection and Response for Google Workspace, extending SOC-led identity protection beyond Microsoft 365. The service now protects over 10 million identities with a 3-minute mean time to respond and under 5% false positive rate. Google Workspace has become a high-value target as it functions as root identity infrastructure for cloud environments, enabling password resets, MFA verification, OAuth permissions, and SaaS platform access. Attackers use business email compromise, phishing through trusted Google services (Drive, Slides), OAuth consent phishing, identity token theft, and Workspace subdomain abuse for password resets. In 2025, 79% of all Huntress critical/high incident reports were identity-related rather than endpoint or malware incidents. Modern BEC campaigns unfold as multi-stage identity attacks involving initial access, discovery through mailbox reconnaissance, and stealth tactics like Gmail filter rules to hide security notifications.
Enterprise PCs Lag Behind Macs in Patching and Reliability
Omnissa's State of Digital Workspace report found macOS devices update 1.5 times faster than Windows hardware, while iOS machines update 8.1 times faster than Android. Industries housing sensitive data lag furthest behind in OS patching, with healthcare, pharmaceutical, and retail organizations among the worst offenders. Windows users experience 3.1 times more forced shutdowns than Mac owners, 2.2 times more app crashes, and 7.5 times more app hangs. While 90% of Windows machines are under three years old, only 65% of Macs fall into that category, with 11.5% of Macs remaining in use six years after purchase compared to just 2% of Windows machines. Intel processors power 93% of observed PCs with AMD holding 6% market share. The report noted 36% year-over-year growth in virtual desktops, likely driven by Windows 10 end-of-life and hardware upgrade requirements. Microsoft Edge browser share reached 41% in enterprise environments, just two points behind Chrome.
Manufacturing Cybersecurity Trends for 2026
Manufacturing accounted for 17% of cyber attacks in 2025, nearly double the 9% reported in 2024. Ransomware operators now target operational technology (OT) systems and uptime rather than just data, recognizing that production downtime creates immediate financial pressure. The convergence of OT, industrial control systems (ICS), and Industrial Internet of Things (IIoT) has eliminated air gaps between corporate networks and shop floors. Remote access for maintenance, IIoT sensors, and cloud-based dashboards provide attack paths from corporate endpoints to manufacturing systems. Threat actors compromise corporate networks through phishing and use credentials to hop into OT environments, potentially reaching manufacturing execution systems, human-machine interfaces, and programmable logic controllers. Zero Trust architectures are expanding to factory floors to prevent breaches in office networks from leading to production shutdowns.
Schneider Electric Plant iT/Brewmaxx Multiple Redis Vulnerabilities
Schneider Electric disclosed four critical vulnerabilities in Plant iT/Brewmaxx version 9.60 and above affecting Energy, Critical Manufacturing, and Commercial Facilities sectors. CVE-2025-49844 (EPSS 90th percentile) allows authenticated users to execute specially crafted Lua scripts that manipulate the garbage collector, trigger use-after-free conditions, and potentially achieve remote code execution. CVE-2025-46817 (EPSS 94th percentile) permits authenticated users to cause integer overflows via Lua scripts leading to RCE. CVE-2025-49844 and CVE-2025-46818 also present privilege escalation risks. All vulnerabilities affect Redis versions 8.2.1 and below used by the platform.
Pharos Controls Mosaic Show Controller Unauthenticated RCE (CVE-2026-2417)
A missing authentication vulnerability in Pharos Controls Mosaic Show Controller firmware version 2.15.3 allows unauthenticated attackers to bypass authentication and execute arbitrary commands with root privileges. The vulnerability affects commercial facilities worldwide and presents critical risk to lighting control systems used in entertainment venues.
Grassroots DICOM (GDCM) Memory Leak Denial of Service (CVE-2026-3650)
A memory leak vulnerability in Grassroots DICOM library version 3.2.2 affects healthcare and public health sectors worldwide. The bug occurs when parsing malformed DICOM files with non-standard VR types in file meta information, leading to vast memory allocations and resource depletion. A maliciously crafted file can fill the heap in a single read operation without proper memory release, triggering a denial-of-service condition. The GDCM maintainer has not responded to CISA requests to address the vulnerability.
Microsoft Security Update Guide CVE Disclosures
Microsoft published information for multiple CVEs affecting various components. Notable disclosures include CVE-2026-2645 (TLS 1.2 CertificateVerify acceptance flaw, EPSS 7th percentile), CVE-2026-25075 (strongSwan EAP-TTLS integer underflow), CVE-2026-3229 and CVE-2026-3230 (certificate chain and TLS 1.3 key validation issues), CVE-2026-4426 (Libarchive DoS via malformed ISO files, EPSS 30th percentile), CVE-2026-4424 (Libarchive heap out-of-bounds read in RAR processing, EPSS 35th percentile), and multiple Libsoup vulnerabilities (CVE-2026-2443, CVE-2026-0716, CVE-2026-3099, CVE-2026-2369) affecting digest authentication and WebSocket processing. Additional disclosures cover wolfSSL vulnerabilities (CVE-2026-4395, CVE-2026-1005, CVE-2026-3549, CVE-2026-0819, CVE-2026-4159), tar-rs issues (CVE-2026-33056, CVE-2026-33055), and Valkey DoS (CVE-2026-27623).
Today's brief highlights a continued shift toward specialization in the ransomware economy, with initial access brokers like Aleksey Volkov operating independently from encryption and extortion crews. The Trivy and Checkmarx supply chain compromises demonstrate that security tools themselves have become high-value targets, with attackers weaponizing trusted CI/CD infrastructure to harvest credentials at scale. The Railway.com campaign shows how legitimate Platform-as-a-Service offerings enable adversaries to spin up attack infrastructure at machine speed with AI-assisted personalization that evades traditional email filtering. The FCC's sweeping router ban reflects growing government concern about supply chain integrity, though critics note that router security weaknesses transcend country of origin, as evidenced by successful exploitation of U.S. and Western products in campaigns like Salt Typhoon.