← Carolina Clear Tech

Cyber Threat Brief

2026-03-29

Listen to this brief (16:37)

Download MP3
Show Notes

Show Notes - 2026-03-29

Stories Covered

CVEs Referenced

CVE-2023-4966, CVE-2025-5777, CVE-2025-6543, CVE-2025-67030, CVE-2025-7775, CVE-2026-1519, CVE-2026-23399, CVE-2026-25645, CVE-2026-3055, CVE-2026-3104, CVE-2026-3119, CVE-2026-32241, CVE-2026-33416, CVE-2026-33634, CVE-2026-33636, CVE-2026-33671, CVE-2026-33672, CVE-2026-33936, CVE-2026-3591, CVE-2026-4833

Indicators of Compromise

Domains: update-check[.]com, update-check[.]com.

Read the full brief

Get tomorrow's brief in your inbox

Protect Your Business

Need a security assessment? See our cybersecurity packages.

View Services

Daily Cybersecurity Brief - March 29, 2026

Today: Citrix NetScaler CVE-2026-3055 seeing active reconnaissance with CVSS 9.3 memory overread requiring SAML IDP configuration. TeamPCP supply chain campaign hits first 48-hour pause after week-long spree, CISA KEV deadline now 11 days out. Iran-linked Handala breached FBI Director Kash Patel's personal email and hit Stryker with wiper attack in first confirmed Fortune 500 destructive operation.

Critical Alerts

Citrix NetScaler CVE-2026-3055 (CVSS 9.3) Under Active Reconnaissance

Citrix NetScaler ADC and NetScaler Gateway are experiencing active reconnaissance targeting CVE-2026-3055, a memory overread vulnerability requiring SAML Identity Provider configuration. Attackers are probing /cgi/GetAuthMethods to fingerprint authentication flows in honeypots. The vulnerability affects NetScaler ADC and Gateway versions 14.1 before 14.1-66.59, 13.1 before 13.1-62.23, and NetScaler ADC 13.1-FIPS and 13.1-NDcPP before 13.1-37.262. EPSS scoring is low (0.000, 5th percentile) but NetScaler has a track record of rapid weaponization. CVE-2023-4966 (Citrix Bleed), CVE-2025-5777 (Citrix Bleed 2), CVE-2025-6543, and CVE-2025-7775 were all added to CISA KEV and exploited by ransomware groups. Defused Cyber and watchTowr report this reconnaissance activity precedes exploitation windows measured in days, not weeks.

TeamPCP Supply Chain Campaign Pauses After 48 Hours Without New Compromise

TeamPCP supply chain attacks have entered their first 48-hour pause since March 19, with no new package compromises confirmed since the Telnyx PyPI disclosure on March 27. Prior operational tempo was aggressive: Trivy (March 19), CanisterWorm (March 20-22), Checkmarx (March 23), LiteLLM (March 24), Telnyx (March 27). The pause coincides with TeamPCP announcing a Vect ransomware affiliate partnership, suggesting a shift from supply chain expansion to monetizing the estimated 300 GB credential trove. CISA KEV remediation deadline for CVE-2026-33634 is April 8, 2026 (11 days). EPSS is 0.266 (96th percentile). Palo Alto Networks published behavioral detection rules targeting CI/CD pipeline attacks that focus on anomalous runner behavior: credential directory enumeration, bulk secret reads from /proc/pid/mem, encrypted archive creation (tpcp.tar.gz), and outbound transfers to newly registered domains. PyPI has quarantined two TeamPCP campaigns in quick succession, which may be raising operational costs.

Iran-Linked Handala Breaches FBI Director Email, Wipes Stryker in First Fortune 500 Destructive Attack

Handala Hack Team (MOIS-affiliated, also tracked as Banished Kitten, Cobalt Mystique, Red Sandstorm, Void Manticore) breached FBI Director Kash Patel's personal email and leaked photos and documents from 2010 and 2019. FBI confirmed the breach involves historical data with no government information. More concerning is Handala's confirmed wiper attack against Stryker, a Fortune 500 medical device and services provider. This is the first confirmed destructive wiper operation targeting a U.S. Fortune 500 company. The attack deleted large volumes of company data and wiped thousands of employee devices. Stryker reports the incident is contained and persistence mechanisms have been removed. The breach was confined to internal Microsoft environments. Palo Alto Unit 42 assesses the primary vector involves exploitation of identity through phishing and administrative access through Microsoft Intune. Hudson Rock found evidence of compromised credentials associated with Microsoft infrastructure. Handala operations emphasize disruption, psychological impact, and geopolitical signaling, not financial gain. Attacks leverage RDP for lateral movement and deploy Handala Wiper and Handala PowerShell Wiper via Group Policy logon scripts. VeraCrypt disk encryption is used to complicate recovery.

Ransomware & Extortion

Woodfords Family Services Notifying Patients of 2024 Ransomware Attack

Woodfords Family Services in Maine is notifying patients of an April 8, 2024 ransomware attack nearly two years after the incident. The organization discovered suspicious activity on April 8, 2024, and confirmed on January 29, 2026 that personal information and protected health information was involved. Data included names, Social Security numbers, driver's licenses, government IDs, passport numbers, dates of birth, financial account information, medical diagnostic/treatment information, and health insurance details. The breach affected 8,073 people (7,701 Maine residents). Woodfords notified HHS in June 2024 with a placeholder of 500 affected patients, which has not been updated. This is Woodfords' second ransomware attack. In November 2023, a separate attack affected 17,285 people (16,862 Maine residents) and 6,691 patients according to HHS. No ransomware gang has claimed responsibility for either attack, and no data leak has been identified. Woodfords' notices do not mention ransomware and do not disclose whether ransom demands were paid.

Infinite Campus Data Breach Exposed Limited Non-Directory Student Information

Infinite Campus suffered a data breach involving ShinyHunters. Independent analysis of the leaked data tranche found that most files contained proprietary or client information without personal or sensitive personal information. Approximately two dozen support tickets contained students' first and last names in the context of coding issues (attendance, language, race, graduation status). Two support tickets contained more sensitive information: one involved a student with an IEP and discipline records, another involved a student arrest and out-of-school suspension records. The analysis was not exhaustive, but no evidence of compromised student databases was found. Most exposure involved client configuration data and support ticket narratives, not structured databases.

Corewell Health Vendor Breach Affects 19,000 Patients

Corewell Health disclosed that its former health care consulting vendor, Pinnacle Holdings, experienced a 2024 data breach affecting approximately 19,000 Corewell patients. Compromised information included names, contact information, Social Security numbers, medical information, and insurance details.

Business & Infrastructure Threats

New Infinity Stealer Targets macOS via ClickFix Technique

Infinity Stealer is a new Python-based infostealer targeting macOS systems using the ClickFix social engineering technique. The campaign presents a fake Cloudflare CAPTCHA on update-check[.]com, instructing users to paste a base64-obfuscated curl command into Terminal. The command decodes a Bash script that writes a Nuitka loader to /tmp, removes the quarantine flag, and executes it via nohup. The Nuitka loader is an 8.6 MB Mach-O binary containing a 35 MB zstd-compressed archive with the Infinity Stealer payload (UpdateHelper.bin). The malware performs anti-analysis checks for virtualized/sandboxed environments before collecting credentials from Chromium-based browsers and Firefox, macOS Keychain entries, cryptocurrency wallets, and plaintext secrets in developer files like .env files. Data is exfiltrated via HTTP POST to the C2, and threat actors receive Telegram notifications on completion. This is the first documented macOS campaign combining ClickFix delivery with a Python-based infostealer compiled using Nuitka. Nuitka produces native binaries by compiling Python to C, making reverse engineering harder than PyInstaller (which bundles Python with bytecode).

General Security News

Anthropic Claude Mythos Model Leaked via Public Data Lake

Anthropic accidentally leaked details about its upcoming Claude Mythos AI model, along with nearly 3,000 internal assets including PDFs, images, and information about an "exclusive CEO event." The leak was caused by a content management system (CMS) configuration issue. Anthropic uploaded the data to its CMS but failed to mark the items as private, storing them in a publicly accessible data lake. The company has since confirmed the leak to Fortune. No security breach or attacker involvement is indicated; this was an internal access control misconfiguration.

Patch Priority

Vulnerability Disclosures

CVE-2026-32241 - Flannel Remote Code Execution via BackendData Injection

Flannel is vulnerable to cross-node remote code execution via extension backend BackendData injection. EPSS: 0.001 (32nd percentile). No additional details provided in MSRC advisory.

CVE-2026-3104 - BIND Memory Leak in DNSSEC Proof Preparation

Memory leak in code preparing DNSSEC proofs of non-existence. EPSS: 0.000 (8th percentile).

CVE-2026-3591 - BIND Stack Use-After-Return in SIG(0) Handling

A stack use-after-return flaw in SIG(0) handling code may enable ACL bypass. EPSS: 0.000 (1st percentile).

CVE-2026-33636 - LIBPNG Out-of-Bounds Read on AArch64

LIBPNG has ARM NEON palette expansion out-of-bounds read on AArch64. EPSS: 0.000 (9th percentile).

CVE-2026-23399 - nf_tables Memory Leak in Error Path

nf_tables nft_dynset: possible stateful expression memory leak in error path. EPSS: 0.000 (4th percentile).

CVE-2025-67030 - Microsoft Security Update

No details provided in MSRC advisory. EPSS: 0.001 (33rd percentile).

CVE-2026-1519 - BIND NSEC3 CPU Load DoS

Excessive NSEC3 iterations cause high CPU load during insecure delegation validation. EPSS: 0.000 (11th percentile).

CVE-2026-33936 - python-ecdsa Denial of Service

Denial of Service via improper DER length validation in crafted private keys. EPSS: 0.000 (15th percentile).

CVE-2026-3119 - BIND TKEY Record DoS

Authenticated query containing a TKEY record may cause named to terminate unexpectedly. EPSS: 0.000 (2nd percentile).

CVE-2026-33416 - LIBPNG Use-After-Free

LIBPNG has use-after-free via pointer aliasing in png_set_tRNS and png_set_PLTE. EPSS: 0.000 (15th percentile).

CVE-2026-25645 - Python Requests Insecure Temp File Reuse

Requests has insecure temp file reuse in its extract_zipped_paths() utility function. EPSS: 0.000 (0th percentile).

CVE-2026-33671 - Picomatch ReDoS via Extglob Quantifiers

Picomatch has a ReDoS vulnerability via extglob quantifiers. EPSS: 0.000 (12th percentile).

CVE-2026-33672 - Picomatch Method Injection in POSIX Character Classes

Picomatch: Method injection in POSIX character classes causes incorrect glob matching. EPSS: 0.001 (32nd percentile).

CVE-2026-4833 - Orc Discount Markdown Recursion Vulnerability

Orc discount Markdown markdown.c compile recursion. EPSS: 0.000 (2nd percentile).

Trends & Context

Three themes dominate today's briefing: active reconnaissance transitioning to exploitation on high-value targets (Citrix NetScaler), supply chain campaigns entering monetization phases after aggressive expansion (TeamPCP), and state-sponsored actors escalating destructive operations against Western targets (Handala's Stryker wiper attack). The 48-hour pause in TeamPCP activity after eight days of consecutive compromises suggests either operational constraints (PyPI quarantine raising costs) or a deliberate shift to credential monetization. NetScaler's history of rapid weaponization following disclosure makes CVE-2026-3055 an immediate patch priority despite low EPSS scoring.