CVE-2023-52676, CVE-2024-35839, CVE-2024-41013, CVE-2025-49010, CVE-2025-55182, CVE-2025-66037, CVE-2025-66038, CVE-2026-1579, CVE-2026-20929, CVE-2026-3356, CVE-2026-34043, CVE-2026-34714, CVE-2026-3502, CVE-2026-4176
IP Addresses:
142.11.206.73, 47.237.15.197
Get tomorrow's brief in your inbox
Today: TeamPCP's multi-stage supply chain attack on Trivy, LiteLLM, and KICS has spawned two major downstream breaches: Cisco lost 300+ repositories including customer source code, and North Korean group UNC1069 hijacked the Axios npm package with 100 million weekly downloads to deploy cross-platform RATs. Iranian threat actors launched password spraying campaigns against 300+ Middle Eastern organizations, targeting municipalities that later received missile strikes. Microsoft released emergency update KB5086672 to fix broken March preview updates, and CrowdStrike detailed CVE-2026-20929, a Kerberos relay vulnerability enabling AD CS certificate theft for persistent access.
TeamPCP Supply Chain Attack: Trivy, LiteLLM, KICS Compromised (CVE-2025-55182)
TeamPCP conducted a coordinated supply chain attack between February and March 2026, compromising widely used security tools including Trivy vulnerability scanner, LiteLLM AI gateway, and Checkmarx KICS. The group injected credential-stealing malware into GitHub Actions and PyPI packages, exfiltrating over 300 GB of data and 500,000 credentials including cloud tokens, SSH keys, and Kubernetes secrets. CVE-2025-55182 (React2Shell vulnerability) has EPSS score of 0.651 (98th percentile) and is on CISA KEV list with remediation due date of December 12, 2025. The attack weaponizes security infrastructure that requires elevated privileges, granting unimpeded access to production secrets. Affected software includes BerriAI LiteLLM (95 million monthly downloads), Aqua Security Trivy, Checkmarx KICS, and Telnyx Python SDK. TeamPCP leveraged harvested tokens to infect 48 additional packages and published 16 victim organizations on leak sites. The group's CanisterWorm malware includes decentralized C2 architecture and targeted wiper components focused on cloud-native operations.
Cisco Source Code Stolen via Trivy Supply Chain Attack
Cisco's development environment was breached after threat actors used credentials stolen from the Trivy supply chain attack. Attackers used a malicious GitHub Action plugin to steal credentials from Cisco's build environment, impacting dozens of devices. Multiple AWS keys were stolen and used for unauthorized activities across Cisco AWS accounts. Over 300 GitHub repositories were cloned, including source code for AI-powered products (AI Assistants, AI Defense) and unreleased products. A portion of stolen repositories belongs to corporate customers including banks, BPOs, and US government agencies. Multiple threat actors were involved in the CI/CD and AWS account breaches. Cisco's Unified Intelligence Center, CSIRT, and EOC teams contained the breach, isolated affected systems, began reimaging, and are performing wide-scale credential rotation. The company expects continued fallout from follow-on LiteLLM and Checkmarx supply chain attacks.
Axios npm Package Compromised by North Korean Threat Actor UNC1069
North Korean threat actor UNC1069 compromised the Axios npm package maintainer account and published two malicious versions (1.14.1 and 0.30.4) containing cross-platform remote access trojans. Axios has over 100 million weekly downloads, making this one of the most impactful npm supply chain attacks on record. The attacker hijacked the npm account of lead maintainer "jasonsaayman," changed the email to an anonymous ProtonMail address ([email protected]), and pushed infected packages via npm CLI, bypassing GitHub Actions CI/CD safeguards. The malicious versions injected a fake dependency "[email protected]" that acts as a dropper (SILKBELL) for the WAVESHAPER.V2 backdoor. The postinstall script deploys platform-specific payloads: PowerShell script via copied wt.exe on Windows (hidden execution, policy bypass), native Mach-O binary on macOS deployed as system daemon, and Python backdoor on Linux. Malware deletes itself and reverts package.json to hide forensic traces. The malicious dependency was staged 18 hours in advance, and both versions were poisoned within 39 minutes. Packages were live for just over three hours, potentially resulting in 600,000 compromised downloads. WAVESHAPER.V2 beacons to C2 (sfrclak.com, 142.11.206.73) at 60-second intervals and supports four commands: kill, rundir (enumerate directories), runscript (execute AppleScript/PowerShell/shell), and peinject (execute arbitrary binaries). Google Threat Intelligence Group attributed the attack to UNC1069, a financially motivated North Korean actor active since 2018 with deep experience in supply chain attacks historically used to steal cryptocurrency.
Kerberos Relay Attack via DNS CNAME Abuse (CVE-2026-20929)
CVE-2026-20929 is a Kerberos authentication relay vulnerability with CVSS 7.5, patched in January 2026 Patch Tuesday. The vulnerability enables attackers to exploit Kerberos authentication relay through DNS CNAME record abuse, particularly impactful when relaying to Active Directory Certificate Services (AD CS) to enroll certificates for user accounts. This is a Kerberos-based variant of the ESC8 attack that works even in environments with NTLM disabled. Attackers manipulate DNS CNAME records to control which Service Principal Name (SPN) the client requests, then relay the authentication to AD CS web enrollment endpoints (/certsrv). Successfully relayed authentication results in AD CS issuing a certificate in the victim's name, providing persistent access lasting months or years. The attack requires the attacker to control CNAME records, coerce victim authentication, and find AD CS web enrollment without Channel Binding Token (CBT) protection. EPSS score is 0.000 (14th percentile). CrowdStrike developed a correlation-based detection monitoring for anomalous certificate-based authentication combined with unusual AD CS service access within a short time window.
TrueConf Zero-Day Exploited Against Southeast Asian Government Networks (CVE-2026-3502)
CVE-2026-3502 is a zero-day vulnerability in TrueConf client video conferencing software with CVSS 7.8, exploited in-the-wild as part of Operation TrueChaos targeting government entities in Southeast Asia. The flaw affects the application's updater validation mechanism, allowing an attacker controlling an on-premises TrueConf server to distribute and execute arbitrary files across connected endpoints. TrueConf is used by over 100,000 organizations globally, particularly in government, defense, and critical infrastructure sectors. The attack exploited the implicit trust the client places in the update mechanism by pushing a rogue installer that leverages DLL side-loading to launch a DLL backdoor (7z-x64.dll). The backdoor performs reconnaissance, establishes persistence, and retrieves additional payloads (iscsiexe.dll) from FTP server 47.237.15.197. The end goal is deployment of the Havoc C2 framework implant. Check Point attributes the activity with moderate confidence to a Chinese-nexus threat actor based on TTPs (DLL side-loading, Alibaba Cloud/Tencent infrastructure) and targeting overlap with ShadowPad. TrueConf patched the vulnerability in version 8.5.3 released March 2026. EPSS score is 0.000 (1st percentile).
Iranian Pseudo-Ransomware and Pay2Key Revival
Iranian APT groups are blurring the lines between state-sponsored and cybercriminal activities by deploying pseudo-ransomware operations and reviving Pay2Key operations. The campaigns target high-impact US organizations, combining traditional espionage objectives with extortion tactics. This represents an evolution in Iranian threat actor TTPs, moving beyond pure intelligence collection to include financial motivation and disruptive effects. The pseudo-ransomware appears designed for maximum impact and disruption rather than genuine ransom collection, suggesting hybrid warfare objectives.
Iranian Password Spraying Campaign Targets Middle Eastern Municipalities
Suspected Iranian APT group conducted wide-ranging password spray attacks against Microsoft 365 accounts of over 300 organizations in Israel and 25+ in UAE, with limited targeting in US, Europe, and Saudi Arabia. The campaign occurred in three waves (March 3, 13, 23) and primarily targeted municipalities that play critical roles in responding to missile-related physical damage. Check Point researchers identified correlation between password spraying targets and cities hit by Iranian drone and missile strikes in March, suggesting the campaign supported kinetic operations and Bombing Damage Assessment (BDA) efforts. The attacks also targeted technology (63 attempts), transportation/logistics (32), healthcare (28), and manufacturing (28) sectors. Attackers used frequently changed Tor exit nodes with IE10 User-Agent string (Mozilla/5.0 compatible; MSIE 10.0; Windows NT 6.1; Trident/6.0) for initial password spraying. After finding valid credentials, they logged in from commercial VPN IPs (Windscribe 185.191.204.X, NordVPN 169.150.227.X) geolocated in Israel to evade geographic restrictions. The activity shows similarities to Gray Sandstorm (Iranian APT known for password spraying since 2021) and uses infrastructure at AS35758 (Rachamim Aviel Twito) previously observed in Iran-linked operations.
UK Manufacturers Report 80% Cyberattack Rate
ESET research shows 78% of UK manufacturers suffered at least one cyber incident in the past 12 months, with more than half reporting lost revenue. In over half of the worst incidents, losses surpassed £250,000. Almost all respondents reported direct operational impact, with supply chain disruption and missed commitments near the top. Most outages stretch into days, sometimes close to a week, with knock-on effects lingering well after systems return. One in five manufacturers have limited or no insight into cybersecurity threats that could knock production offline. Nearly half of respondents see AI-assisted attacks as the top threat over the next year, ahead of phishing and ransomware. Jaguar Land Rover's 2025 cyberattack forced weeks of production halts with estimated £1.9 billion economic impact across suppliers and output. Only 22% of firms put cybersecurity at executive level, and more than a fifth lean toward reactive rather than proactive approaches. The research highlights that many organizations treat cybersecurity as an IT issue rather than a strategic business decision.
Google Drive Ransomware Detection Now Default for Paying Users
Google Drive's AI-powered ransomware detection has reached general availability and is now enabled by default for all paying users (business, enterprise, education, frontline licenses). The feature pauses file syncing when it detects ransomware attacks, notifying users and IT admins to minimize impact. The latest AI model detects 14x more infections compared to beta, providing faster and more comprehensive protection. When ransomware-encrypted files are found, desktop sync is paused, affected users receive email alerts and Drive notifications, and alerts are created in Google Admin console. While this does not prevent files on compromised computers from being encrypted, documents stored in Google Drive are protected and can be quickly restored. The feature requires Google Drive for desktop version 114 or later for detection alerts, though file syncing will pause on older versions. Admins can disable the feature at Apps > Google Workspace > Settings for Drive and Docs > Malware and Ransomware. File restoration is available to all Google Workspace customers, Workspace individual subscribers, and personal Google account users.
WhatsApp Malware Campaign Delivers VBScript and MSI Backdoors
Microsoft Defender Experts observed a campaign beginning late February 2026 using WhatsApp messages to deliver malicious VBS files. The campaign combines social engineering, living-off-the-land techniques, and cloud-based payload hosting to establish persistence and remote access. Stage 1: VBS files delivered via WhatsApp create hidden folders in C:\ProgramData and drop renamed legitimate Windows utilities (curl.exe as netapi.dll, bitsadmin.exe as sc.exe) with downloader flags. Stage 2: The renamed binaries download secondary VBS droppers (auxs.vbs, WinUpdate_KB5034231.vbs) from trusted cloud platforms (AWS S3, Tencent Cloud, Backblaze B2) to mask malicious activity as legitimate traffic. Stage 3: The malware tampers with UAC settings, continuously attempts cmd.exe elevation retries, modifies registry entries under HKLM\Software\Microsoft\Win, and embeds persistence mechanisms. The renamed binaries retain original PE metadata (OriginalFileName field still identifies them as curl.exe and bitsadmin.exe), allowing Microsoft Defender to detect discrepancies between file names and embedded metadata. For environments without PE metadata inspection, defenders need command line flags and network telemetry for hunting.
Venom Stealer: Continuous Credential Harvesting
Venom Stealer is licensed malware with built-in persistence and automation enabling attackers to continuously siphon credentials, session data, and cryptocurrency assets. The stealer raises the stakes beyond traditional one-time theft by implementing continuous credential harvesting, allowing persistent access to refreshed credentials and session tokens. This represents an evolution in infostealer capabilities, moving from point-in-time theft to ongoing surveillance of credential stores and authentication tokens.
Stolen Logins Fuel Ransomware and Nation-State Attacks
SecurityWeek report shows how industrialized credential theft underpins ransomware, SaaS breaches, and geopolitical attacks, shifting security focus from prevention to detecting misuse of legitimate access. The credential theft ecosystem has matured into a supply chain feeding multiple attack types, from financially motivated ransomware to state-sponsored espionage. This highlights the critical need for detecting anomalous use of valid credentials rather than relying solely on preventing initial credential theft.
Windows 11 Emergency Update Fixes Preview Update Install Issues (KB5086672)
Microsoft released out-of-band update KB5086672 on March 31, 2026, to fix the broken March preview update KB5079391 which was pulled due to installation issues. The optional cumulative update KB5079391 was released March 27 for Windows 11 24H2 and 25H2 with 29 changes including Smart App Control and Display improvements. Users reported errors "Some update files are missing or have problems. We'll try to download the update again later. Error code: (0x80073712)." Microsoft stopped the rollout and confirmed the installation issues. KB5086672 supersedes all previous updates and includes all protections and improvements from March 2026 security and non-security preview updates plus the installation fix. Devices with "Get the latest updates as soon as they're available" turned on may see automatic offer via Windows Update. Manual installation available at Settings > Windows Update > Download & install. This is the second emergency update in less than a week; Microsoft previously released an OOB update addressing sign-in issues with Microsoft accounts across Teams, OneDrive, Edge, and Microsoft 365 Copilot triggered by March Patch Tuesday. Since early March, Microsoft pushed two additional OOB updates for hotpatch-enabled Windows 11 Enterprise targeting Bluetooth device visibility bug and RRAS management tool security vulnerabilities.
Microsoft Outlook Classic Crashes Fixed (Teams Meeting Add-in)
Microsoft resolved a bug rendering classic Outlook unusable for users with Microsoft Teams Meeting Add-in enabled. The issue started March 12, 2026, causing Outlook crashes and safe mode prompts. Microsoft acknowledged the problem March 19 in incident report EX1254044, blaming older Outlook builds for crashes. The issue occurs when older classic Outlook builds use newest Teams Meeting Add-In build 1.26.02603 (for example, Current Channel Outlook Version 2402 Build 17328.20142 or lower). The fix is rolling out with Microsoft Teams version 26058.712.4527.9297. Microsoft advises updating classic Outlook to latest build or performing Online Repair for click-to-run installs (reinstalls all Office applications). Users needing to stay on older Office builds can disable the Teams Meeting Add-in temporarily: Open Outlook in Safe Mode (hold Ctrl when starting), select File > Options > Add-ins > Go, uncheck Microsoft Teams Meeting Add-in for Microsoft Office, click OK, restart Outlook. Microsoft also fixed a classic Outlook bug causing 0x800CCC0F and 0x80070057 errors when synchronizing Gmail and Yahoo accounts since February 26, and an issue preventing Microsoft 365 customers from opening encrypted emails caused by December 2025 updates. Additional ongoing issues include "Can't connect to the server" errors when creating groups with EWS enabled, and disappearing mouse pointer in classic Outlook, OneNote, and other Microsoft 365 apps.
Claude AI Finds RCE Bugs in Vim and Emacs
Vulnerabilities in Vim and GNU Emacs text editors discovered using Claude assistant allow remote code execution by opening a file. Vim flaw affects all versions 9.2.0271 and earlier. The vulnerability stems from missing security checks in modeline handling and sandbox bypass, allowing code embedded in a file to execute upon opening. A victim only needs to open a specially crafted file to trigger arbitrary command execution with user privileges. The issue has no CVE ID. Vim maintainers released patch in version 9.2.0272. GNU Emacs vulnerability remains unpatched as maintainers consider it Git's responsibility to address. The problem stems from vc-git integration where opening a file triggers Git operations via vc-refresh-state, causing Git to read .git/config and run user-defined core.fsmonitor program. An attack involves creating an archive with hidden .git/ directory containing config file pointing to executable script. When victim extracts archive and opens text file, payload executes without visible indicators. GNU Emacs maintainers argue the environment merely triggers the dangerous action executed by Git (reading attacker-controlled config and executing program). While technically correct, the risk exists since GNU Emacs automatically runs Git on untrusted directories without neutralizing dangerous options, without user consent, and without sandbox protections. The researcher suggested GNU Emacs modify Git calls to block core.fsmonitor.
Microsoft CISO Advice: Applying Security Fundamentals to AI
Microsoft Deputy CISOs provide practical advice for securing AI systems: (1) AI is not magic - it's a role-playing engine that continues conversations based on prompts. More professional context yields more professional responses. AI is most helpful working with humans who understand their fields. (2) AI is software - it's a stateless piece of software running in your environment. Unless code explicitly stores data, it doesn't log or use data to train models, doesn't learn dynamically, and doesn't consume data in new ways. Basic security concerns (data leakage, access) are the same as other software. (3) AI agents need identity and permissions following same access control rules. Assign distinct identity (service or user-derived) with least privilege access. Never rely on AI to make access control decisions - use deterministic non-AI mechanisms. (4) Follow "least agency" principle - don't give AI access to capabilities, APIs, or UIs it doesn't need. (5) AI can be confused between data to process and instructions (indirect prompt injection/XPIA). When AI processes untrusted data, use Spotlighting and Prompt Shield to prevent treating data as instructions. Test AI response to malicious inputs, especially if AI can take consequential actions. (6) AI makes data easier to find, which can uncover pre-existing permissioning problems. Novel usage promotes more engagement and queries, further highlighting existing permission issues.
Unified Exposure Management Becoming Boardroom Priority
The cybersecurity landscape is accelerating at unprecedented rate with dramatic increase in speed of attack, exploitation, and change. The defining challenge is weaponization of AI by threat actors automating the entire kill chain. Traditional defensive strategies (periodic assessments, manual triage, human-speed response) are inadequate against AI-enabled adversaries. Adversaries use generative AI for targeted phishing at scale, machine learning to analyze defenses and identify vulnerabilities automatically, and polymorphic malware that rewrites code in real time to evade signature-based detection. Solutions like PlexTrac unify exposure management, remediation, and validation in single operational system. Organizations need convergence of Autonomous Exposure Assessment and Continuous Threat Assessment powered by Agentic AI. PlexTrac ingests data from ecosystem (cloud misconfigurations, identity risks, application flaws, pentest findings) to create unified dynamic risk view. It applies context-aware scoring, visualizes attack paths, and uses automated assessments with predictive insight. Agentic AI represents shift from traditional copilots by providing autonomous continuous validation rather than waiting for human direction.
Microsoft: Critical Infrastructure Threat Landscape Changed
Microsoft Threat Intelligence highlights that governments worldwide are advancing policies requiring critical infrastructure organizations to prioritize continuous readiness and proactive defense. US National Cybersecurity Strategy (March 2023) frames CI cybersecurity as national security imperative. Japan issued basic policy for Active Cyber Defense legislation in 2025. Europe continues implementing NIS2 Directive across essential sectors. Canada advances prescriptive approach via Bill C8. Operation Winter SHIELD (FBI Cyber Division joint initiative) helps CI organizations move from awareness to verified readiness through implementation, not just policy. Water sector findings from Microsoft (March 19, 2026) with Cyber Readiness Institute and Center on Cyber Technology & Innovation show hands-on coaching paired with practical training materially improves cyber readiness in ways that guidance alone does not. Legacy CI systems now operate within hybrid IT-OT environments connected by cloud-based identity, remote access, and complex vendor ecosystems that didn't exist when systems were built. Identity has become the central control layer. Microsoft Threat Intelligence and Incident Response investigations show convergence of identity-driven intrusion, living-off-the-land persistence, and nation-state prepositioning across CI.
Proton Launches Privacy-Focused Meet Conferencing Platform
Proton announced Meet, a video conferencing service positioned as privacy-focused alternative to Google Meet, Zoom, and Microsoft Teams. Meet provides end-to-end encrypted (E2EE) calls and does not require paid plan or Proton account. Free tier offers one-hour meetings with up to 50 participants. Pro plan starts at $7.99/month for longer calls. Proton created Meet in response to need for privacy-first EU-based alternatives for GDPR compliance, addressing US Cloud Act complexities, and overcoming challenges from unstable geopolitical environment. The service addresses the practice of using conversations to train AI models, which creates risk of private data exposure from LLMs. Meet works by creating conference call link and sharing with participants. Fully integrated with Proton Calendar and supports adding scheduled meetings to Google and Microsoft calendars. Calls secured with Messaging Layer Security (MLS), an independently reviewed open source E2E encryption protocol for real-time group messaging. All media and chat encrypted client-side, leaving Proton unable to access cleartext data. Architecture built on WebRTC with Selective Forwarding Units (SFU) for relaying media. Meeting link contains ID and password kept locally on client side, authenticating participants via Secure Remote Password (SRP) protocol. MLS forms cryptographic group sharing epoch key used for encryption, rotated on every join/leave event. Forward secrecy prevents new members from reading past messages, old members can't read future messages. Email and IP addresses kept private between participants. Even in server compromise, traffic cannot be read or modified, and databases contain only meeting IDs. Realistic risk is having meeting link compromised, mitigated by locking entries once all participants joined, removing rogue participants, or rotating link.
Anritsu Remote Spectrum Monitor Authentication Bypass (CVE-2026-3356)
CVE-2026-3356 affects Anritsu Remote Spectrum Monitor models MS27100A, MS27101A, MS27102A, MS27103A (all versions). The device is vulnerable to authentication bypass allowing unauthorized users to access and manipulate management interface. The issue is inherent to design rather than deployment error, as the device provides no mechanism to enable or configure authentication. Successful exploitation allows attackers with network access to alter operational settings, obtain sensitive signal data, or disrupt device availability. Deployed worldwide in Communications, Defense Industrial Base, Emergency Services, and Transportation Systems sectors. Anritsu has no plans to fix this issue. Anritsu recommends deploying Remote Spectrum Monitor within secure network environments to mitigate potential risks. CISA published advisory ICSA-26-090-01 on March 31, 2026.
PX4 Autopilot MAVLink Authentication Bypass (CVE-2026-1579)
CVE-2026-1579 affects PX4 Autopilot v1.16.0_SITL_latest_stable. The MAVLink communication protocol does not require cryptographic authentication by default. When MAVLink 2.0 message signing is not enabled, any message (including SERIAL_CONTROL providing interactive shell access) can be sent by unauthenticated party with access to MAVLink interface. Successful exploitation allows attacker with access to MAVLink interface to execute arbitrary shell commands without cryptographic authentication. PX4 provides MAVLink 2.0 message signing as the cryptographic authentication mechanism. When signing is enabled, unsigned messages are rejected at protocol level. Deployed worldwide in Transportation Systems, Emergency Services, and Defense Industrial Base sectors. PX4 recommends enabling MAVLink 2.0 message signing for all non-USB communication links. CISA published advisory ICSA-26-090-02 on March 31, 2026.
Microsoft Security Update Guide CVE Disclosures
Microsoft published multiple CVE disclosures on March 31, 2026, in the Security Update Guide with limited details ("Information published"). CVEs include: CVE-2024-41013 (xfs directory data block, EPSS 0.000 3rd percentile), CVE-2023-52676 (bpf stack limits 32bit overflow, EPSS 0.000 3rd percentile), CVE-2024-35839 (netfilter bridge physindev, EPSS 0.000 3rd percentile), CVE-2025-66037 (OpenSC out of bounds, EPSS 0.000 0th percentile), CVE-2026-34714 (EPSS 0.000 6th percentile), CVE-2025-49010 (OpenSC stack buffer overflow in GET RESPONSE, EPSS 0.000 5th percentile), CVE-2025-66038 (OpenSC sc_compacttlv_find_tag out-of-bounds pointers, EPSS 0.000 3rd percentile), CVE-2026-4176 (Perl Compress::Raw::Zlib vulnerability in versions 5.9.4 before 5.40.4-RC1, 5.41.0 before 5.42.2-RC1, 5.43.0 before 5.43.9, EPSS 0.000 6th percentile), CVE-2026-34043 (Serialize JavaScript CPU exhaustion DoS via crafted array-like objects, EPSS 0.000 11th percentile).
Today's threat landscape is dominated by supply chain attacks operating at scale. TeamPCP's coordinated compromise of security infrastructure tools demonstrates how targeting developer tooling creates cascading downstream breaches. The Axios npm package compromise by North Korean actors and the Cisco breach via Trivy show that supply chain attacks are no longer isolated incidents but interconnected campaigns affecting thousands of organizations. Nation-state actors are weaponizing legitimate software distribution channels, trusted cloud platforms, and developer workflows to achieve persistent access at machine speed. The convergence of AI-enabled attacks, industrialized credential theft, and supply chain compromises is forcing a fundamental shift from perimeter defense to continuous validation and behavioral detection. Organizations can no longer trust that legitimate packages, updates, or credentials are safe by default.