← Carolina Clear Tech

Cyber Threat Brief

2026-03-26

Listen to this brief (17:08)

Download MP3
Show Notes

Show Notes - 2026-03-26

Stories Covered

CVEs Referenced

CVE-2023-32434, CVE-2023-38606, CVE-2023-4966, CVE-2025-66413, CVE-2025-68357, CVE-2026-2297, CVE-2026-23298, CVE-2026-23303, CVE-2026-23306, CVE-2026-23307, CVE-2026-23313, CVE-2026-23319, CVE-2026-23325, CVE-2026-23340, CVE-2026-23348, CVE-2026-23351, CVE-2026-23352, CVE-2026-23359, CVE-2026-23364, CVE-2026-23370, CVE-2026-23371, CVE-2026-23377, CVE-2026-23378, CVE-2026-23382, CVE-2026-23383, CVE-2026-23391, CVE-2026-29111, CVE-2026-3055, CVE-2026-33017, CVE-2026-4368

Indicators of Compromise

IP Addresses: 162.220.234.41, 162.220.234.66, 162.220.232.57

Read the full brief

Get tomorrow's brief in your inbox

Protect Your Business

Need a security assessment? See our cybersecurity packages.

View Services

Daily Cyber Threat Brief - 2026-03-26

Today: Citrix warns of a critical NetScaler vulnerability similar to CitrixBleed with 30,000+ instances exposed online. CISA adds Langflow code injection to the KEV catalog. TeamPCP compromises major security tools Trivy, Checkmarx, and LiteLLM to steal credentials.

Critical Alerts

Citrix NetScaler Memory Overread (CVE-2026-3055)

Citrix patched CVE-2026-3055, a critical memory overread flaw affecting NetScaler ADC and Gateway appliances configured as SAML identity providers. The vulnerability allows unauthenticated remote attackers to steal sensitive data including session tokens. Multiple security firms warn this resembles the widely exploited CitrixBleed (CVE-2023-4966, CISA KEV, ransomware-linked, EPSS 94.3%) and CitrixBleed2 vulnerabilities that were leveraged in zero-day attacks. Over 30,000 NetScaler ADC instances and 2,300 Gateway instances are exposed online, though it's unclear how many use vulnerable configurations. Citrix discovered the flaw internally but researchers expect threat actors to reverse engineer the patch.

Langflow Code Injection (CVE-2026-33017)

CISA added CVE-2026-33017 to the Known Exploited Vulnerabilities catalog based on evidence of active exploitation. The vulnerability is a code injection flaw in Langflow. CISA requires federal agencies to remediate by April 8, 2026 (EPSS 0.6%, 69th percentile).

Ransomware & Extortion

Russian TA551 Botnet Operator Sentenced

Russian national Ilya Angelov (40, known as "milan" and "okart") was sentenced to 2 years in prison and fined $100,000 for managing the TA551 botnet between 2017 and 2021. TA551 distributed spam emails with malware-infected files to build a network of compromised computers, then sold access to criminal groups. The botnet gave BitPaymer ransomware operators access to 72 U.S. corporations between August 2018 and December 2019, resulting in over $14.17 million in extortion payments. TA551 also sold botnet access to IcedID malware operators for over $1 million in late 2019 or early 2020, and later partnered with TrickBot to distribute Conti ransomware and Lockean ransomware. The group used a macro downloader (MOUSEISLAND) and secondary payload (PHOTOLOADER) to deploy IcedID and other malware.

Blackbaud Breach Subrogation Case Reversal

Delaware Supreme Court reversed a lower court decision and held that cyber insurers sufficiently pled a collective subrogation claim against Blackbaud resulting from its ransomware breach. The insurers provided cyber insurance to education and non-profit organizations using Blackbaud's data hosting services. After the breach, Blackbaud initially claimed no personal information was accessed (filing a Form 10-Q calling the theft hypothetical), then later disclosed that cybercriminals may have accessed bank accounts and social security numbers. The insureds incurred response costs including legal counsel, forensics, and notification obligations. The case creates precedent for aggregated insurer claims against vendors following data breaches.

Business & Infrastructure Threats

TeamPCP Supply Chain Attack Hits Trivy, Checkmarx, and LiteLLM

The hacking group TeamPCP (also known as Shellforce) compromised multiple security and development tools in a credential theft campaign starting March 19, 2026. The attackers injected credential stealers into Trivy (a vulnerability scanner), Checkmarx's KICS automated tools and two code editor plugins, and LiteLLM (an AI application development tool). The poisoned Trivy scanner and GitHub Actions were designed to steal passwords, AWS/Azure/GCP cloud access keys, and cryptocurrency wallet details. On March 23, two Checkmarx plugins were compromised on the OpenVSX marketplace (the official VS Code Marketplace remained safe). On March 24, TeamPCP used stolen credentials to publish malicious LiteLLM versions 1.82.7 and 1.82.8 to PyPI. Version 1.82.8 included a hidden file that runs malware every time Python starts, regardless of whether LiteLLM is used. TeamPCP advertises the CipherForce project to recruit affiliates and begin publishing compromised companies.

AI Context Hub Documentation Poisoning Vulnerability

Security researcher Mickey Shmueli published a proof-of-concept attack demonstrating that Context Hub (a service launched by Andrew Ng for supplying coding agents with API documentation) can be used to poison AI agents with malicious instructions. The service delivers documentation to AI agents through an MCP server, accepting contributions as GitHub pull requests with zero content sanitization. Attackers can submit poisoned documentation that references fake PyPI package dependencies, which coding agents then incorporate into configuration files and generated code. In testing, Anthropic's Haiku model wrote malicious packages into requirements.txt files 100% of the time (40/40 runs) without warning. Sonnet issued warnings in 48% of runs but still wrote the malicious library 53% of the time. The review process prioritizes documentation volume over security, with 58 of 97 closed pull requests merged.

Device Code Phishing Campaign Hits 340+ Microsoft 365 Organizations

Huntress detected an active device code phishing campaign targeting Microsoft 365 accounts across 340+ organizations in the U.S., Canada, Australia, New Zealand, and Germany. The campaign started February 19, 2026 and accelerated in March. Attackers leverage Cloudflare Workers redirects and infrastructure hosted on Railway (a platform-as-a-service) to harvest credentials. Targeted sectors include construction, non-profits, real estate, manufacturing, financial services, healthcare, legal, and government. The campaign uses multiple lures including construction bids, DocuSign impersonation, voicemail notifications, and Microsoft Forms abuse. Device code phishing exploits the OAuth device authorization flow to obtain persistent access tokens that remain valid even after password resets. Approximately 84% of observed authentication abuse originates from three Railway IP addresses: 162.220.234.41, 162.220.234.66, and 162.220.232.57 (with two additional IPs also involved). Phishing emails wrap malicious URLs in legitimate security vendor redirects from Cisco, Trend Micro, and Mimecast to bypass spam filters.

Coruna Framework Linked to Operation Triangulation

Google and iVerify reported that the Coruna exploit kit targeting Apple iPhones is an updated version of the framework used in Operation Triangulation. Kaspersky analyzed the kit and discovered that the kernel exploit for CVE-2023-32434 and CVE-2023-38606 (both CISA KEV vulnerabilities discovered as zero-days in Operation Triangulation) used in Coruna is an updated version of the same exploit from Triangulation. Coruna includes four additional kernel exploits not seen in Operation Triangulation, two developed after Triangulation's discovery. All exploits share common code and are built on the same kernel exploitation framework. Coruna was first discovered in targeted attacks by an unnamed surveillance vendor's customer, then used in watering-hole attacks in Ukraine and financially motivated attacks in China. The exploit kit relies on Safari vulnerabilities and includes sophisticated iOS spyware implants.

Windows / AD Security

Git for Windows NTLM Hash Leak (CVE-2025-66413)

Microsoft published CVE-2025-66413, a vulnerability in Git for Windows that leaks NTLM credentials when cloning from an attacker-controlled server. EPSS score is 0.000 (10th percentile), indicating low observed exploitation but high potential for targeted attacks against developer workstations.

Microsoft Identity Security Architecture Shift

Microsoft published guidance on modern identity security architecture emphasizing that identity attacks now focus on what an identity can access rather than who is compromised. Research shows 32% of organizations have duplicative access management solutions and 40% have too many vendors, creating fragmentation that enables lateral movement. Microsoft recommends unifying three layers: identity infrastructure (Entra ID, SSO, user management), identity control plane (privileged access management with dynamic risk signals), and end-to-end identity threat protection (posture reduction, real-time detection, rapid containment).

General Security News

Underground Market for Premium AI Account Access

Flare analysts documented a growing underground market for premium AI platform access including ChatGPT, Claude, Microsoft Copilot, and Perplexity. Hundreds of posts in fraud-oriented communities promote discounted subscriptions, bundled access, and usage models claiming to remove platform limitations. Acquisition methods include exposed API keys (found in Docker Hub), credential theft and account takeover (using aged Gmail/Outlook accounts), bulk account creation with virtual phone verification bypass, abuse of trial/promotional programs, shared or resold subscriptions, and API key resale. Buyer motivations include cost (official subscriptions start around $20/month), scale (automation requiring multiple accounts), and sanctions bypass (Russia, Iran, North Korea where access is restricted).

Patch Priority

Vulnerability Disclosures

Linux Kernel CVEs (MSRC)

Microsoft published 19 Linux kernel CVEs affecting Windows Subsystem for Linux (WSL). All show EPSS scores below 1st percentile, indicating minimal observed exploitation. Notable issues include plaintext password logging (CVE-2026-23370 Dell WMI, CVE-2026-23303 SMB client), MAC comparison timing attacks (CVE-2026-23364 ksmbd), use-after-free bugs (CVE-2026-23306 pm8001 SCSI), race conditions (CVE-2026-23348 CXL nvdimm), and various memory safety issues in networking (CVE-2026-23359 BPF devmap, CVE-2026-23391 netfilter, CVE-2026-23340 qdisc) and device drivers.

Citrix NetScaler CVE-2026-4368

Citrix also patched CVE-2026-4368, a race condition affecting NetScaler appliances configured as Gateways or AAA virtual servers. The flaw enables threat actors with low privileges to exploit user session mix-ups in low-complexity attacks (EPSS 0.000, 4th percentile). Fixed in the same versions as CVE-2026-3055.

Trends & Context

Three supply chain attack patterns emerged today: documentation poisoning of AI coding agents (Context Hub), credential theft through compromised security tools (TeamPCP), and OAuth abuse for persistent access (device code phishing). The TeamPCP campaign is particularly concerning because it targets the security tooling developers trust to protect their code. The Citrix NetScaler vulnerability echoes the CitrixBleed pattern where memory-read flaws in widely deployed appliances become high-value exploitation targets for ransomware groups. Organizations should prioritize patching internet-facing infrastructure and reviewing OAuth/device code authentication logs for anomalies.