CyberSecBrief

Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks


Daily Cybersecurity Briefing (4 March 2026)

Published: Loading…

At a Glance

  • CVE-2026-21902 in Juniper Junos OS Evolved allows unauthenticated root RCE on PTX routers via the On-Box Anomaly Detection service.
  • Android’s March 2026 update patches CVE-2026-21385, a Qualcomm graphics flaw exploited in targeted attacks alongside 100 additional vulnerabilities.
  • The Coruna exploit kit targets iOS 13.0 through 17.2.1 with 23 exploits across five chains used by espionage and financially motivated groups.
  • FreeScout versions up to 1.8.206 are vulnerable to CVE-2026-28289, enabling zero-click unauthenticated RCE via crafted email attachments.
  • LexisNexis confirmed a breach after 2GB of legacy AWS data was leaked following exploitation of an unpatched React frontend.

Summary

A critical flaw tracked as CVE-2026-21902 affects Juniper Junos OS Evolved on PTX Series routers, enabling unauthenticated root remote code execution through the On-Box Anomaly Detection REST service. CISA also added CVE-2026-22719 in VMware Aria Operations to its Known Exploited Vulnerabilities catalogue, citing active exploitation.

Google released the March 2026 Android security update addressing 129 vulnerabilities, including the actively exploited Qualcomm graphics flaw CVE-2026-21385. The Coruna exploit kit targets iOS versions 13.0 through 17.2.1 using 23 exploits across five chains, deploying modular payloads for data exfiltration.

FreeScout versions up to 1.8.206 are affected by CVE-2026-28289, which enables zero-click unauthenticated remote code execution via crafted emails. Microsoft warned that attackers are abusing OAuth redirection flows to deliver malware to government and public-sector targets without stealing access tokens.

LexisNexis confirmed attackers accessed legacy data from its AWS environment after exploiting an unpatched React frontend, leading to a 2GB leak. The University of Hawaii Cancer Center disclosed a ransomware-related breach affecting nearly 1.2 million individuals and exposing sensitive personal information.

Silver Dragon, a Chinese-nexus group linked to APT41, targeted organisations in Europe and Southeast Asia using GearDoor and custom loaders for persistent access. SloppyLemming conducted dual malware campaigns deploying BurrowShell and a Rust-based payload against government entities in Pakistan and Bangladesh.

Highlights of the Day

Coruna Exploit Kit Targets iOS Devices Across Multiple Threat Actors

Google’s Threat Intelligence Group has uncovered a sophisticated iOS exploit kit, named Coruna, affecting devices from iOS 13.0 through 17.2.1. The kit includes 23 exploits across five full chains, leveraging both WebKit and kernel vulnerabilities, and has been used by government-backed and financially motivated groups. Analysis shows it delivers a modular payload capable of exfiltrating cryptocurrency wallets and other sensitive data.

CyberStrikeAI Emerges as AI-Driven Offensive Security Platform

Team Cymru reports the rise of CyberStrikeAI, an open-source AI-native security tool with potential ties to Chinese state-affiliated actors. The platform integrates over 100 security tools for automated testing and has been observed targeting devices including Fortinet FortiGate appliances, with activity concentrated across China, Singapore, and Hong Kong. Analysis of the developer’s GitHub activity indicates connections to organisations linked to the Chinese Ministry of State Security.

Source: Team Cymru

Iranian Hacktivist Activity Rises Amid U.S.-Israel-Iran Tensions

Sophos reports a surge in Iranian hacktivist campaigns following coordinated U.S. and Israeli strikes on Iranian targets. Groups such as Handala Hack Team and APTIran have been active on Telegram and X, focusing on website defacements, DDoS attacks, and doxxing related to Israeli interests, while pro-Israel personas have also initiated cyber operations. Most observed activity remains low sophistication, though regional tensions increase the risk of broader retaliatory attacks.

Source: Sophos

LexisNexis Confirms Breach After Hackers Leak 2GB of Data

LexisNexis Legal & Professional reported a data breach after FulcrumSec leaked 2GB of files from the company’s AWS infrastructure. The intrusion exploited an unpatched React frontend and exposed mostly legacy data, including customer names, contact information, and survey responses, without sensitive financial or personal identifiers. LexisNexis stated the breach has been contained and involved no disruption to services.

RedAlert Trojan Exploits SMS to Deploy Malicious Android App

CloudSEK reports a campaign distributing a trojanised version of Israel’s Red Alert emergency app via SMS spoofing. The malware mimics the official interface while harvesting contacts, SMS messages, and GPS data, exfiltrating it to attacker-controlled servers. By leveraging real-time civilian panic during the conflict, the campaign poses both digital and physical security risks.

Source: CloudSEK

Hybrid Cyber-Kinetic Conflict Escalates in Middle East

Cyble reports that the Iran-US-Israel confrontation has combined missile strikes, cyberattacks, and hacktivist campaigns. Over the first 72 hours, kinetic assaults coincided with widespread digital disruptions, including internet outages in Iran and distribution of malicious apps mimicking official alert systems. The conflict highlights the integration of cyber operations alongside conventional warfare and the rapid mobilisation of regional hacktivist networks.

Source: Cyble

Juniper Junos Evolved Vulnerability Enables Pre-Auth RCE

WatchTowr Labs reports that CVE-2026-21902 affects Juniper PTX Series running Junos OS Evolved, allowing unauthenticated attackers to execute code as root via the On-Box Anomaly Detection Framework. The service, listening on TCP port 8160 by default, exposes a REST API intended for internal monitoring, enabling attackers to define commands, DAGs, and scheduled tasks to achieve remote code execution. The flaw is present in Junos OS Evolved versions prior to 25.4R1-S1-EVO and 25.4R2-EVO.

Silver Dragon APT Targets Europe and Southeast Asia

Check Point Research is tracking Silver Dragon, a Chinese‑nexus threat group linked to APT41, targeting government and high‑profile organisations across Southeast Asia and Europe since mid‑2024. The group uses exploitation of public‑facing servers and phishing campaigns to deliver Cobalt Strike beacons through custom loaders, including MonikerLoader and BamboLoader, while hijacking legitimate Windows services for persistence. Researchers also identified GearDoor, a new backdoor that uses Google Drive for command‑and‑control, alongside additional tools for screen capture and SSH‑based remote access.

Malicious Laravel Packages Deliver Remote Access Trojan

Socket’s Threat Research Team identified three Packagist packages posing as Laravel utilities that secretly deploy a remote access trojan. Two packages, lara-helper and simple-queue, contain an obfuscated PHP payload that establishes encrypted communication with a command-and-control server, enabling remote shell access, file transfer, and screen capture across Windows, macOS, and Linux systems. A third package, lara-swagger, includes no malicious code but automatically installs the infected dependency, extending the campaign through Composer’s dependency chain.

Source: Socket

FreeScout Patch Bypass Enables Zero-Click Remote Code Execution

OX Security researchers discovered that a recent patch for FreeScout’s authenticated RCE can be bypassed, escalating the flaw to an unauthenticated, zero-click remote code execution (CVE‑2026‑28289). Exploitation requires only sending a crafted email to a configured mailbox, allowing full server compromise and access to stored helpdesk data. The vulnerability affects all versions up to 1.8.206 and is addressed in FreeScout v1.8.207.

Daily Coverage

Developments
Junos Ptx RceAndroid Zero-DayCoruna Exploit KitFreescout Email Rce
Vulnerabilities
CVE-2026-22719Aria Operations 8.18.0 (High)CVE-2025-14500Icewarp 14.2.0.5 (Critical)CVE-2026-28289Freescout < 1.8.207 (Critical)CVE-2026-21902Junos Os Evolved 25.4 (Critical)CVE-2026-21385Snapdragon 5G Fixed Wireless Access Platform (High)
Threat Groups
APT41APT41 is a threat group that researchers have assessed as Chinese statesponsored espionage group that also conducts financiallymotivated operations. Active since at least 2012, APT41 has been observed targeting various industries, including but not limited to healthcare, telecom, technology, finance, education, retail and video game industries in 14 countries. Notable behaviors include using a wide range of malware and tools to complete mission objectives. APT41 overlaps at least partially with public reporting on groups including BARIUM and Winnti Group.PlayPlay is a ransomware group that has been active since at least 2022 deploying Playcrypt ransomware against the business, government, critical infrastructure, healthcare, and media sectors in North America, South America, and Europe. Play actors employ a doubleextortion model, encrypting systems after exfiltrating data, and are presumed by security researchers to operate as a closed group.