Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks
Daily Cybersecurity Briefing (3 March 2026)
Published: Loading…
At a Glance
- SloppyLemming targeted government and critical infrastructure in Pakistan and Bangladesh using BurrowShell implants, Rust keyloggers, and 112 Cloudflare Workers domains for C2.
- Two unauthorised Aqua Trivy VS Code extensions on OpenVSX triggered local AI coding assistants to conduct system reconnaissance and attempted GitHub data exfiltration.
- CVE-2026-0628 in Chrome Gemini allowed malicious extensions to escalate privileges, access local files, and spy on users before Google issued a patch.
- A joint Israeli–U.S. strike on Iran triggered hybrid cyber operations, internet disruptions, and over 150 hacktivist incidents across Israel, Gulf, and allied networks.
- Ransomware attacks increased 50% in 2025 while total on-chain payments fell 8%, median ransom payouts rose to nearly $60,000 despite declining victim compliance.
- CVE-2026-3102 in ExifTool allows malicious image metadata to execute shell commands and download payloads on macOS systems running versions before 13.50.
Summary
Espionage campaigns remained active in South Asia, with SloppyLemming targeting Pakistani and Bangladeshi government agencies using BurrowShell implants, Rust-based keyloggers, and 112 Cloudflare Workers domains for command-and-control. The operation leveraged PDF lures and macro-enabled Excel files for initial compromise.
Software supply-chain risks emerged as unauthorised Aqua Trivy VS Code extensions briefly triggered local AI coding assistants to perform extensive system reconnaissance and attempted GitHub-based data exfiltration. The affected versions were quickly removed, with no confirmed exfiltration.
Web browser vulnerabilities were also exploited, with CVE-2026-0628 in Chrome’s Gemini allowing extensions to escalate privileges, access local files, and spy on users. Google issued a patch to mitigate the privilege escalation and local file access risks.
Ransomware activity rose sharply, with attacks increasing 50% in 2025 while total on-chain payments declined 8%. Median ransom payouts surged to nearly $60,000, reflecting higher-value, targeted incidents despite reduced overall compliance.
Malware and vulnerability exploitation continued across multiple platforms, with CVE-2026-3102 in ExifTool enabling shell command execution via image metadata on macOS systems. The flaw affects versions prior to 13.50 and can facilitate payload downloads and data theft in automated image-processing workflows.
Highlights of the Day
Chrome Tests Quantum-Safe HTTPS with Merkle Tree Certificates
Google’s Chrome team has launched a programme to develop quantum-resistant HTTPS using Merkle Tree Certificates (MTCs), an alternative to traditional X.509 certificates designed to reduce the performance and bandwidth impact of post-quantum cryptography. Developed within the IETF’s PLANTS working group, MTCs replace conventional certificate chains with compact inclusion proofs, embedding transparency by default. Chrome is piloting the approach with Cloudflare and plans a phased rollout through 2027, including the creation of a dedicated quantum-resistant root store operating alongside its existing trust programme.
Middle East Escalation Spurs Record Cyber Operations
A joint Israeli–U.S. strike on Iran in late February 2026 triggered a hybrid conflict combining kinetic attacks and unprecedented cyber operations. Iran experienced near-total internet disruption, while retaliatory missile and cyber activity spread across Israel, the Gulf, and second-order countries, affecting energy, finance, and critical infrastructure. Over 150 hacktivist incidents were recorded, highlighting the convergence of state-aligned, proxy, and hacktivist campaigns in the region.
Ransomware Payments Stall Despite Record Attack Surge
Ransomware attacks rose 50% in 2025 while total on-chain payments fell 8% to $820 million, reflecting a fragmented market and increased defensive measures. Median ransom payouts surged 368% to nearly $60,000, highlighting higher-value, targeted incidents even as overall victim compliance declined. Analysts note growing convergence of criminal and state-linked infrastructure, with law enforcement and private sector actions increasingly disrupting the shared platforms that enable extortion campaigns.
SloppyLemming Deploys Advanced RATs Against Pakistan and Bangladesh
Arctic Wolf has identified a cyber-espionage campaign attributed to SloppyLemming targeting government and critical infrastructure in Pakistan and Bangladesh. The operation uses two primary vectors: PDF lures with ClickOnce manifests delivering the BurrowShell shellcode implant, and macro-enabled Excel files deploying a Rust-based keylogger. The threat actor leverages 112 Cloudflare Workers domains for C2 and payload delivery, combining DLL sideloading, encrypted shellcode, and SOCKS proxy capabilities to maintain persistent, stealthy access.
Malicious Trivy Extension Triggers AI Tools to Exfiltrate Data
Two unauthorised versions of the Aqua Trivy VS Code extension were briefly published to OpenVSX with hidden code designed to invoke local AI coding assistants in highly permissive modes. The injected prompts instructed tools such as Claude, Codex and GitHub Copilot CLI to conduct extensive system reconnaissance and, in one version, attempt to create a GitHub repository to store collected data. The affected releases were removed within a day, and no confirmed cases of successful data exfiltration have been reported.
A critical vulnerability in ExifTool (CVE-2026-3102) allows malicious shell commands embedded in image metadata to execute on macOS systems. The flaw affects versions prior to 13.50 and can be triggered when processing images with certain flags, potentially enabling payload download and data theft without visible signs. ExifTool is widely integrated into photo management and forensic applications, making the risk relevant to any workflow using the library on macOS.
Daily Coverage