← Carolina Clear Tech

Cyber Threat Brief

2026-03-31

Listen to this brief (21:37)

Download MP3
Show Notes

Show Notes - 2026-03-31

Stories Covered

CVEs Referenced

CVE-2025-53521, CVE-2026-0964, CVE-2026-0965, CVE-2026-0966, CVE-2026-0967, CVE-2026-3055, CVE-2026-33542, CVE-2026-33750, CVE-2026-33891, CVE-2026-33895, CVE-2026-33896, CVE-2026-33916, CVE-2026-33938, CVE-2026-33939, CVE-2026-33941, CVE-2026-4676

Read the full brief

Get tomorrow's brief in your inbox

Protect Your Business

Need a security assessment? See our cybersecurity packages.

View Services

Cyber Threat Brief - March 31, 2026

Today: CISA orders federal agencies to patch actively exploited Citrix NetScaler CVE-2026-3055 by Thursday. F5 reclassifies BIG-IP flaw as critical RCE after in-the-wild exploitation. Axios supply chain attack delivers cross-platform RAT through compromised npm credentials.

Critical Alerts

Citrix NetScaler CVE-2026-3055 Under Active Exploitation (CISA KEV)

CISA added CVE-2026-3055 to its Known Exploited Vulnerabilities catalog on March 30, giving federal agencies until Thursday, April 2 to patch. The critical vulnerability (CVSS 9.3) allows unauthenticated remote attackers to steal sensitive information from Citrix ADC and Gateway appliances configured as SAML identity providers. Watchtowr observed active exploitation since March 27, with attackers extracting admin session IDs to enable full appliance takeover. The flaw resembles CitrixBleed and CitrixBleed2, both previously exploited as zero-days. Shadowserver tracks nearly 30,000 NetScaler ADC and 2,300 Gateway instances exposed online, though the number of vulnerable configurations is unknown. EPSS score is 0.000 (7th percentile), likely because the vulnerability is very recent.

F5 BIG-IP CVE-2025-53521 Reclassified as RCE After Webshell Deployment

F5 Networks reclassified CVE-2025-53521 from a denial-of-service vulnerability to critical-severity remote code execution after learning attackers are exploiting it to deploy webshells on unpatched BIG-IP APM systems. The flaw affects systems with access policies configured on a virtual server and can be exploited by unauthenticated attackers. CISA added it to the KEV catalog on Friday with a deadline of March 30 for federal agencies. EPSS score is 0.192 (95th percentile), indicating very high likelihood of exploitation. Shadowserver tracks over 240,000 BIG-IP instances exposed online. F5 published IOCs and advised defenders to check disks, logs, and terminal history for signs of compromise. BIG-IP vulnerabilities have been exploited by nation-state and cybercrime groups to breach networks, deploy wipers, and steal documents.

Ransomware Claims (Last 48h)

7 claims tracked across 2 groups in the last 48 hours. These are unverified claims from ransomware leak sites, not confirmed breaches.

Group Victim Sector Country
Securotrop Jones Haber Law Legal Services Unknown
XP95 Statistics South Africa Government South Africa
XP95 Eholo Health Healthcare Spain
Qilin (see narrative below) Manufacturing Multiple
Akira (see narrative below) Multiple Multiple
Play (see narrative below) Multiple Multiple
TeamPCP/CipherForce (see narrative below) Multiple Multiple

Ransomware & Extortion

TeamPCP Supply Chain Campaign Escalates to Dual Ransomware Operations

New intelligence reveals TeamPCP operates two simultaneous ransomware tracks: their proprietary CipherForce program for high-value direct operations, and mass Vect affiliate distribution via BreachForums for volume operations. TeamPCP's 300 GB credential trove from the security tool supply chain campaign (Aqua, Checkmarx, BerriAI, Telnyx) feeds both tracks. Databricks is investigating an alleged compromise linked to TeamPCP's credential harvest, with screenshots showing AWS artifacts and STS tokens matching TeamPCP's playbook. Databricks stated they "thoroughly investigated this information in our internal systems and found nothing" but requested more details. If confirmed, this would be the first major cloud platform identified as a downstream victim of TeamPCP's monetization phase, distinct from the tool vendors directly compromised. AstraZeneca data was released as part of the campaign.

Talos 2025 Ransomware Trends: Qilin Tops List After LockBit Takedown

Cisco Talos 2025 Year in Review shows Qilin ransomware group as most prolific after LockBit fell to 35th following law enforcement disruption. Qilin uses double-extortion and targeted over 40 victims monthly except January 2025, signaling continued threat in 2026. Akira and Play rank second and third, likely due to absorbing LockBit affiliates and evolving tactics. Manufacturing remains the most targeted sector due to mixed systems, limited monitoring tolerance, and disruption sensitivity. Initial access is 40% phishing, with attackers blending into legitimate activity using RDP, PowerShell, and PsExec for lateral movement. Valid accounts appear across nearly every ransomware attack stage. January sees lower activity due to holidays and Eastern European public holidays, presenting an opportunity for defenders to test ransomware defenses during quieter periods.

XP95 Group Hits South African Government, Spanish Healthcare Provider

XP95 ransomware group breached Statistics South Africa, claiming 453,362 files totaling 154 GB, demanding $100,000 USD. The breach impacted an HR system used for job applications. Government issued a statement acknowledging the breach and plans to notify the data protection regulator. XP95 also leaked 165 GB of data from Eholo Health, a Spanish psychological practice management software provider, including 1,146,700 medical notes and personal information of 601,308 users. XP95 originally demanded $300,000 USD but leaked the data for free after Eholo offered only $80,000, stating "This leak is not just about money. It is about exposing hypocrisy." Eholo claims GDPR compliance and patient data security as a "top priority" but took almost a week to patch the vulnerability after exfiltration and never properly notified patients. XP95 stated they are not a ransomware group and do not encrypt systems, only exfiltrate and sell data.

IOCs & Detection

China-Linked Red Menshen Deploys BPFDoor as Telecom Sleeper Cells

Red Menshen state-sponsored threat actor deployed BPFdoor kernel implants and passive backdoors in telecom backbone infrastructure worldwide for long-term persistence. BPFdoor acts as a sleeper cell, lying dormant and blending into target environments, then activating upon receiving a magic packet by monitoring network traffic instead of opening visible connections. Initial access gained through edge networking device and VPN vulnerabilities or compromised accounts. Some BPFdoor samples mimic bare-metal infrastructure, posing as legitimate enterprise platforms. Others spoof core containerization components. Embedding the implant below traditional visibility layers complicates detection. Rapid7 released a scanning script to detect known BPFdoor variants across Linux environments.

Business & Infrastructure Threats

Axios npm Supply Chain Attack Delivers Cross-Platform RAT

Axios versions 1.14.1 and 0.30.4 were published with a malicious dependency (plain-crypto-js 4.2.1) after attackers compromised the npm credentials of the primary Axios maintainer. The attack bypassed GitHub Actions CI/CD pipeline by using compromised npm credentials directly. The malicious package executes a postinstall script acting as a cross-platform RAT dropper targeting macOS, Windows, and Linux. The dropper contacts a live C2 server (sfrclak.com:8000), delivers platform-specific payloads, deletes itself, and replaces its package.json with a clean version to evade forensic detection. The malicious dependency was staged 18 hours in advance with pre-built payloads for three operating systems. Both release branches were compromised within 39 minutes. Axios has over 83 million weekly downloads, making this a significant supply chain event. The attacker changed the maintainer's registered email to a Proton Mail address ([email protected]) and used a long-lived classic npm access token.

Telnyx Targeted in Growing TeamPCP Supply Chain Attack

Two malicious versions of the Telnyx SDK were uploaded to the PyPI registry, targeting Windows, macOS, and Linux. This expands the TeamPCP supply chain campaign beyond previously identified targets (Aqua, Checkmarx, BerriAI). Details on the specific malicious versions and indicators of compromise were not provided in the available data.

Palo Alto App-ID Bypass Allows Data Exfiltration

SANS ISC research demonstrates that Palo Alto Networks App-ID (and similar next-generation firewall application control features like Checkpoint App Control and Fortinet Application Control) can be bypassed for data exfiltration by sending data in small chunks below the classification threshold. App-ID requires at least 1-5 KB of payload to classify traffic reliably, allowing initial traffic through before blocking. An attacker can exploit this by sending data in 3 KB chunks, reconnecting after each chunk is blocked. Each chunk gets through before App-ID identifies it as malicious, enabling full exfiltration by automating the chunking and reconnection process. The researcher successfully exfiltrated a full file by splitting it into 3 KB chunks and sending each to a netcat listener in an infinite loop.

DeepLoad Malware Uses ClickFix, WMI Persistence, and Browser Credential Theft

DeepLoad malware campaign leverages ClickFix social engineering to trick users into running PowerShell commands. The loader uses AI-assisted obfuscation to evade static scanning, hides payloads in LockAppHost.exe (a legitimate Windows lock screen process), disables PowerShell command history, and invokes native Windows core functions directly to bypass monitoring hooks. DeepLoad compiles a temporary DLL with randomized file names using PowerShell's Add-Type feature, then uses asynchronous procedure call (APC) injection to run the payload inside trusted Windows processes. The malware extracts browser passwords and drops malicious browser extensions that intercept credentials on login pages. It automatically copies itself to removable media using names like "ChromeSetup.lnk" and "Firefox Installer.lnk." DeepLoad uses WMI event subscriptions to reinfect clean hosts three days later with no user action, breaking parent-child process chains that most detection rules rely on.

GitGuardian: 29 Million Secrets Leaked in 2025, 64% from 2022 Still Valid

GitGuardian's State of Secrets Sprawl 2026 report found 29 million new hardcoded secrets leaked in 2025, a 34% year-over-year increase. AI services drove 81% more leaks than 2024, with eight of the ten fastest-growing leak categories AI-related (Brave Search up 1,255%, Firecrawl up 796%, Supabase up 992%). Internal repositories are 6x more likely to leak than public repos (32.2% vs 5.6%), and internal leaks are higher-value credentials like CI/CD tokens, cloud access credentials, and database passwords. 28% of leaks happen entirely outside code in Slack, Jira, and Confluence, with 56.7% of collaboration tool leaks rated critical vs 43.7% for code-only incidents. Self-hosted GitLab and Docker registries expose secrets at 3-4x the rate of public GitHub. 64% of secrets confirmed valid in 2022 remain exploitable today, demonstrating that rotation and revocation are not routine or automated.

Windows / AD Security

Microsoft Pulls Windows 11 KB5079391 Preview Update After Install Failures

Microsoft temporarily halted rollout of Windows 11 preview update KB5079391 after installation failures on some devices with error 0x80073712. The update affects Windows 11 24H2 and 25H2. The problem message stated "Some update files are missing or have problems. We'll try to download the update again later." Microsoft said it temporarily limited availability while investigating. The update is not mandatory and includes new features like Settings fixes and support for monitors reporting refresh rates higher than 1,000 Hz. The update failed at the installation stage and did not break any devices. This follows an out-of-band update to fix Microsoft account problems introduced in the March 2026 update. Microsoft recently committed to improving Windows reliability but continues to release problematic updates.

General Security News

OpenAI Patches ChatGPT DNS Data Exfiltration Flaw

Check Point discovered a ChatGPT vulnerability allowing data exfiltration via a DNS side channel originating from the code execution container. A single malicious prompt could activate a hidden exfiltration channel, leaking user messages, uploaded files, and sensitive content without user knowledge or consent. The flaw bypassed OpenAI's safeguards by exploiting DNS resolution, which was not blocked despite restrictions on direct outbound network requests. ChatGPT assumed the Linux runtime was isolated and did not recognize DNS-based data transfers as requiring user mediation. A backdoored GPT could abuse the same weakness to obtain user data without awareness. The flaw also enabled remote shell access inside the Linux runtime. OpenAI fixed the issue on February 20, 2026. No evidence of exploitation in the wild. The vulnerability has serious implications for GDPR, HIPAA, and financial compliance in regulated industries deploying AI services.

FBI Director Kash Patel's Personal Email Hacked by Iran-Linked Handala

The FBI confirmed threat actors gained access to FBI Director Kash Patel's personal email account, but stated no government information was compromised. Iran-linked hacker group Handala claimed responsibility, releasing files allegedly containing photos, emails, and classified documents from Patel's inbox. Handala wrote "The so-called 'impenetrable' systems of the FBI were brought to their knees within hours by our team." The timing of the hack is unclear. The U.S. government recently took down multiple sites operated by Iranian state actors and is offering up to $10 million for information on groups like Parsian Afzar Rayan Borna and Handala. Parsian Afzar Rayan Borna is an IT company linked to Iran's disinformation and surveillance campaigns and assessed to be linked to Banished Kitten, an Iran-nexus adversary active since at least 2008.

Australian Regulator Moves to Enforcement After Social Media Age Ban Failures

Australia's eSafety Commission is "moving into an enforcement stance" after finding Meta, YouTube, TikTok, and Snapchat have not adequately complied with the social media minimum age ban (under 16). Platforms blocked around 5 million accounts, but a survey of 898 parents found around 70% reported their child still had an account. eSafety observed poor practices including messaging children under 16 to attempt age assurance even when their declared age was under 16, enabling children to repeatedly attempt age assurance methods to eventually obtain a 16+ outcome, and ineffective reporting pathways for parents. One example: a 12-year-old falsely claimed to be 14 two years ago; the platform now thinks they are 16 (but they are 14). The parent requested account closure but the platform demanded a legal letter to prove parental status. The 14-year-old still has access. eSafety is investigating Meta (Facebook, Instagram), TikTok, Snapchat, and YouTube for potential non-compliance, with decisions expected by mid-2026.

Patch Priority

Vulnerability Disclosures

Multiple Microsoft Security Update Guide CVEs Published

Microsoft published multiple CVE entries with minimal details, many related to third-party libraries used in Microsoft products. Notable CVEs include CVE-2026-33896 (Forge certificate chain basicConstraints bypass), CVE-2026-0965, CVE-2026-0967, CVE-2026-0966, CVE-2026-0964 (Libssh vulnerabilities including DoS and improper path sanitation), CVE-2026-33750 (brace-expansion zero-step sequence causing hang and memory exhaustion), CVE-2026-33938, CVE-2026-33939, CVE-2026-33941, CVE-2026-33916 (Handlebars.js JavaScript injection, DoS, and prototype pollution vulnerabilities), CVE-2026-33895 (Forge Ed25519 signature forgery), CVE-2026-33891 (Forge DoS via BigInteger.modInverse() infinite loop), CVE-2026-33542 (Incus fingerprint verification failure), and CVE-2026-4676 (Chromium use-after-free in Dawn). All CVEs have low EPSS scores (0.000-0.001, 2nd-31st percentile). Detailed technical information and affected product versions are available in the Microsoft Security Update Guide.

Estonian Hospital USB Drive Contains Other Patients' Health Data

West Tallinn Central Hospital sold a patient a "new" USB drive for X-ray images that contained personal and health data of several other patients. The patient purchased the drive from the hospital specifically to save their X-ray images for forwarding to a specialist. Upon arriving home, they found not only their own data but also data from multiple other patients. The hospital cannot explain how patient data ended up on a supposedly new USB drive until the patient files a formal complaint and an investigation occurs. This incident highlights risks in healthcare data handling and removable media reuse.

Trends & Context

Two critical themes dominate today's stories. First, supply chain attacks are becoming more sophisticated and impactful. TeamPCP's dual ransomware operation shows how attackers leverage compromised security tools to build massive credential troves, then monetize through both targeted and mass affiliate operations. The Axios compromise demonstrates that even the most widely-used libraries with 83 million weekly downloads can be poisoned when maintainer credentials are compromised. Second, infrastructure appliances remain high-value targets. Citrix NetScaler and F5 BIG-IP, both edge devices handling authentication and access control, are under active exploitation with attackers achieving full device takeover and webshell persistence. These are the third and sixth Citrix and F5 vulnerabilities exploited in the wild in recent years, signaling persistent threat actor focus on network perimeter devices.