CVE-2023-32434, CVE-2023-38606, CVE-2025-3248, CVE-2025-70614, CVE-2026-33017, CVE-2026-33634, CVE-2026-3587, CVE-2026-4681
Domains:
careerscrews[.]com, careersstaffgrid[.]com., careerstaffer[.]com, careersworkflow[.]com, careerstransform[.]com, careersupskill[.]com, careerssuccess[.]com, careersstaffgrid[.]com, careersprogress[.]com, careersgrower[.]com, careersengage[.]com
IP Addresses:
13.1.3.0, 13.0.3.0
Get tomorrow's brief in your inbox
Today: CISA adds actively exploited Langflow and Trivy vulnerabilities to KEV catalog with April deadlines. TeamPCP supply chain attack compromised all 91 Checkmarx GitHub Action tags, far wider than initially reported. PTC Windchill deserialization flaw enables RCE across critical manufacturing sectors.
Langflow AI Framework Actively Exploited (CVE-2026-33017)
CISA added CVE-2026-33017 to the KEV catalog after confirming active exploitation of the Langflow AI workflow framework. The critical 9.3 CVSS code injection flaw allows unauthenticated remote code execution. EPSS is 0.061 (91st percentile). Sysdig observed exploitation beginning 20 hours after the vulnerability advisory went public on March 19, with automated scanning, Python exploit scripts, and credential harvesting (.env and .db files) following within 24 hours. Langflow has 145,000 GitHub stars and widespread adoption across AI development ecosystems. CVE-2025-3248, another critical Langflow flaw with 0.921 EPSS (100th percentile), is also on the KEV list with CISA due date May 26, 2025.
Trivy Supply Chain Compromise (CVE-2026-33634)
CISA added CVE-2026-33634 to the KEV catalog, confirming active exploitation of embedded malicious code in Aqua Security's Trivy vulnerability scanner. This is part of the broader TeamPCP supply chain campaign. The vulnerability affects Trivy binary versions below 0.69.2, trivy-action below v0.35.0, and setup-trivy below v0.2.6. EPSS is 0.001 (21st percentile). Federal remediation deadline is April 3, 2026.
TeamPCP Supply Chain Campaign Update: All 91 Checkmarx GitHub Action Tags Compromised
SANS ISC published primary evidence that the TeamPCP supply chain attack compromised all 91 published tags of the Checkmarx ast-github-action, not just the single v2.3.28 version initially reported. GitHub activity logs show 91 tag deletions during Checkmarx's March 23 remediation between 19:09 and 19:16 UTC. Each tag received an individually crafted malicious commit with a backdated timestamp and fake commit message. The credential-stealing setup.sh script executed regardless of which tag version was referenced. Organizations that searched CI/CD logs only for v2.3.28 would have missed compromised runs referencing any of the other 90 poisoned tags. The companion kics-github-action received accurate "all 35 tags" reporting from the start.
PTC Windchill Critical RCE Vulnerability (CVE-2026-4681)
CISA published an ICS advisory for CVE-2026-4681, a critical remote code execution vulnerability in PTC Windchill and FlexPLM product lifecycle management software. The flaw is exploitable through deserialization of untrusted data and affects versions spanning 11.0 M030 through 13.1.3.0 for Windchill PDMLink and 11.0 M030 through 13.0.3.0 for FlexPLM. EPSS is 0.004 (59th percentile). The vulnerability targets critical manufacturing sectors deployed worldwide. PTC is developing a patch and recommends urgent workaround steps via Apache or IIS HTTP server configuration updates. German police physically visited organizations to warn about this vulnerability, indicating credible threat intelligence of imminent exploitation.
Coruna iOS Exploit Framework Linked to Operation Triangulation
Kaspersky identified Coruna, an iOS exploit kit that is an evolution of the framework used in the 2023 Operation Triangulation espionage campaign. Coruna targets Apple A17 and M3 chips and iOS versions up to 17.2, containing five full exploit chains leveraging 23 vulnerabilities including CVE-2023-32434 and CVE-2023-38606 (both on CISA KEV). The framework has expanded beyond espionage to financially motivated campaigns targeting cryptocurrency via fake exchange websites. The attack begins in Safari with device fingerprinting, RCE and PAC exploit selection, encrypted payload downloads, ChaCha20 decryption, LZMA decompression, and kernel exploit deployment. Another publicly available iOS exploit kit, DarkSword, was disclosed earlier this month.
WAGO Industrial Switches CLI Escape Vulnerability (CVE-2026-3587)
CISA published an ICS advisory for CVE-2026-3587, a vulnerability allowing unauthenticated remote attackers to exploit a hidden CLI function and escape the restricted interface on WAGO industrial managed switches, leading to full device compromise. EPSS is 0.001 (26th percentile). The vulnerability affects dozens of hardware models across commercial facilities, critical manufacturing, energy, and transportation sectors deployed worldwide. Patches are available for affected firmware versions.
OpenCode Systems SMS Gateway Access Control Flaw (CVE-2025-70614)
CISA published an ICS advisory for CVE-2025-70614, a web access vulnerability in OpenCode Systems OC Messaging and USSD Gateway 6.32.2 that allows authenticated low-privileged users to access SMS messages outside their authorized tenant scope via crafted company or tenant identifier parameters. EPSS is 0.000 (9th percentile). The vulnerability affects communications sector infrastructure deployed worldwide. OpenCode identified and remediated the issue on January 6, 2026, with release of version 6.33.11.
Cisco IOS Software Multiple Vulnerabilities
Cisco published patches for multiple high and medium severity vulnerabilities in IOS software that could lead to denial of service, secure boot bypass, information disclosure, and privilege escalation. Specific CVE details and affected versions were not disclosed in the article summary.
Windows 11 KB5079391 Smart App Control Improvements
Microsoft released KB5079391 preview cumulative update for Windows 11 24H2 and 25H2 with 29 changes including Smart App Control toggle without reinstallation. Users can now enable or disable Smart App Control via Settings > Windows Security > App & Browser Control > Smart App Control settings. The update includes display reliability improvements (support for monitors above 1000 Hz refresh rates, native USB4 monitor connections, improved HDR), Windows Recovery Environment stability for x64 apps on ARM64 devices, and Windows Hello fingerprint reliability improvements. This is an optional non-security preview update that does not include security fixes. No known issues are reported.
TikTok for Business Phishing Campaign
Push Security identified a phishing campaign targeting TikTok for Business accounts using Cloudflare Turnstile to block bot analysis and reverse proxy pages to capture credentials and session cookies. The campaign uses domains registered March 24 via NiceNIC and hosted on Google Storage buckets, with names like welcome.careerscrews[.]com and welcome.careersstaffgrid[.]com. Phishing pages impersonate TikTok for Business and Google Careers "Schedule a Call" forms. The reverse proxy design bypasses two-factor authentication by acting as an intermediary between the user and legitimate service. Business account holders using Google SSO to log into TikTok accounts face compromise of both services. Push Security links this campaign to activity documented last year targeting Google Ad Manager accounts.
Dutch National Police Phishing Attack
The Dutch National Police disclosed a security breach from a phishing attack with limited impact. The Security Operations Center detected and blocked attacker access quickly. No citizens' data or investigative information was exposed. A criminal investigation is underway. The agency has not disclosed affected systems or accounts, breach detection date, or whether employee data was stolen. This follows a September 2024 data breach linked to a state actor that stole work-related contact information for multiple officers.
Ajax Football Club System Breach
Dutch professional football club Ajax Amsterdam disclosed that a hacker exploited vulnerabilities in its IT systems and accessed data for a few hundred people, including email addresses and personal information for fewer than 20 individuals with stadium bans. RTL journalists independently verified the vulnerabilities and demonstrated the ability to transfer 42,000 season tickets, manipulate 538 supporter stadium bans, and view details on over 300,000 accounts via API flaws and shared keys. Ajax patched all identified vulnerabilities and engaged external experts for forensic analysis. The Dutch Data Protection authority and police were notified.
UK Sanctions Xinbi Marketplace and Scam Centers
The UK Foreign, Commonwealth and Development Office sanctioned Xinbi, a Chinese-language Telegram-based marketplace selling stolen data and satellite internet equipment to Southeast Asian scam networks. Xinbi processed over $19.9 billion between 2021 and 2025, facilitating OTC crypto trades, money laundering, and sale of stolen personal databases. Xinbi is believed to have helped North Korean threat actors launder cryptocurrency. The UK also sanctioned #8 Park (Cambodia's largest scam compound linked to the Prince Group crime ring, capacity for 20,000 trafficked workers) and Legend Innovation Co (operator of #8 Park). Sanctions aim to isolate Xinbi from legitimate crypto ecosystems by blocking cryptocurrency payments. Scam centers across Myanmar, Cambodia, and Laos coerce people into pig butchering and romance baiting schemes.
Russia Arrests Suspected LeakBase Forum Owner
Russian police arrested a Taganrog resident believed to be the owner and administrator of LeakBase, a cybercrime forum seized by the FBI in March 2026 during Operation Leak. The forum had over 142,000 members and was used to sell stolen databases, data leaks, exploits, and other cybercrime services. The FBI-led international operation involved law enforcement in 14 countries and included around 100 enforcement actions worldwide, arrests, house searches, and knock-and-talk interventions against 37 of the most active users. The forum's database, private messages, and IP logs are being used as evidence in ongoing investigations. LeakBase surfaced in 2021 and grew after BreachForums shut down in March 2023.
RedLine Infostealer Admin Extradited to US
Armenian national Hambardzum Minasyan was extradited to the US to face charges for allegedly managing RedLine infostealer infrastructure. He is accused of registering VPS servers, web domains, and cryptocurrency accounts used in RedLine operations, creating file-sharing repositories for malware distribution, and providing support to affiliates. Minasyan appeared in federal court in Austin on March 25, 2026. He faces access device fraud, CFAA violations, and money laundering conspiracy charges with a maximum 30 years in prison if convicted. Dutch National Police seized RedLine infrastructure in October 2024 during Operation Magnus. The US also charged Russian national Maxim Rudometov as the suspected developer and administrator. The US Department of State offers up to $10 million for information leading to arrests of RedLine-linked government-sponsored hackers.
Linux Kernel AI Bug Reports Shift from Junk to Legitimate Overnight
Linux kernel maintainer Greg Kroah-Hartman reported that AI-generated security reports and bug findings transitioned from low-quality "AI slop" to legitimate, actionable reports about a month ago. The inflection point is unexplained, but all major open source security teams are experiencing the same shift. Kroah-Hartman's experiments with AI-generated patches found that two-thirds were correct (though requiring human cleanup for changelogs and integration), while one-third were wrong but still pointed to real problems. Developers are starting to acknowledge AI contributions using co-develop tags. AI is being used more for code review than full authorship. Smaller open source projects have far less capacity to absorb the flood of AI-generated reports compared to the Linux kernel's distributed team structure.
Unit 42 Uncovers Converging China-Aligned Espionage Campaigns
Unit 42 uncovered three distinct cyberespionage campaigns targeting a government organization in Southeast Asia, all linked to China-aligned threat actors. The campaigns involve Stately Taurus (USB-propagated USBFect/HIUPAN malware deploying PUBLOAD backdoor), CL-STA-1048 (espionage toolkit with EggStremeFuel backdoor, Masol RAT, Gorem RAT with keylogging, and TrackBak stealer), and CL-STA-1049 (Hypnosis loader deploying FluffyGh0st RAT). The convergence of three distinct clusters against a single high-value government target illustrates a complex and well-resourced operation. CL-STA-1048 overlaps with Earth Estries and Crimson Palace Campaign actors. CL-STA-1049 overlaps with Unfading Sea Haze.
Today's brief highlights the maturation of supply chain attacks, with the TeamPCP campaign revealing that initial scope assessments can significantly underestimate compromise extent. The convergence of multiple China-aligned threat groups on a single Southeast Asian government target demonstrates coordinated espionage operations at scale. The sudden shift in AI-generated security reports from junk to legitimate findings signals a new phase in automated vulnerability discovery that will pressure maintainers across the open source ecosystem. CISA's addition of actively exploited AI framework and supply chain vulnerabilities to the KEV catalog underscores the expanding attack surface created by rapid AI tooling adoption.