Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks
Daily Cybersecurity Briefing (6 March 2026)
Published: Loading…
At a Glance
- Cisco confirmed active exploitation of CVE-2026-20122 and CVE-2026-20128 in Catalyst SD-WAN Manager, with CISA issuing Emergency Directive 26-03.
- Tycoon 2FA, a subscription PhaaS kit linked to 64,000 AiTM attacks, was dismantled by Europol and private sector partners.
- LeakBase, a stolen-credential forum with 142,000 users, was seized by Europol across 14 countries with approximately 100 enforcement actions.
- UAT-9244, a China-nexus APT, deployed three new malware implants — TernDoor, PeerTime, and BruteEntry — against South American telecoms since 2024.
- CVE-2025-61915 in CUPS allows an unprivileged user to trigger a stack underflow via a malicious IPv6 address, enabling root code execution.
- 48% of 90 zero-days exploited in 2025 targeted enterprise technologies, with commercial surveillance vendors attributed more zero-days than state actors for the first time.
Summary
Cisco Catalyst SD-WAN Manager vulnerabilities continued to attract active exploitation, with CVE-2026-20122 (arbitrary file overwrite) and CVE-2026-20128 (information disclosure) confirmed as exploited in the wild. These follow the earlier confirmation of CVE-2026-20127, a critical authentication bypass exploited in zero-day attacks since at least 2023. Cisco also released patches for 48 separate vulnerabilities across Firewall ASA, Secure FMC, and Secure FTD product lines, including two maximum-severity flaws in Secure Firewall Management Center, while CISA issued Emergency Directive 26-03 requiring federal agencies to inventory affected SD-WAN systems and investigate potential compromise.
Two major cybercriminal platforms were dismantled in coordinated international operations. Tycoon 2FA, a subscription-based phishing-as-a-service kit active since August 2023 and responsible for approximately 62% of phishing attempts blocked by Microsoft at its peak, was taken down by Europol alongside law enforcement and private sector partners including Microsoft, Cloudflare, and Coinbase. Separately, LeakBase, an open-web stolen-credential forum with over 142,000 registered users and 215,000 private messages, was seized across 14 countries during approximately 100 enforcement actions on 3–4 March, with investigators deanonymising multiple users through analysis of the forum's seized database.
Nation-state actors expanded targeting of network infrastructure on multiple fronts. UAT-9244, assessed with high confidence as a China-nexus APT closely associated with Famous Sparrow, deployed three previously undocumented implants — TernDoor, PeerTime, and BruteEntry — against South American telecommunications providers since 2024, converting compromised edge devices into mass-scanning proxy nodes. An APT28-linked campaign simultaneously targeted Ukrainian entities with two undocumented malware families, BadPaw and MeowMeow, initiated via phishing emails containing ZIP-archived HTA lure documents written in Ukrainian.
Following US strikes on 28 February 2026, over 60 Iranian-aligned hacktivist groups activated within hours, intensifying documented threats against US ICS/OT infrastructure. Over 78,000 US ICS devices respond to unauthenticated Modbus commands from the internet, while MOIS-linked MuddyWater has been embedded in multiple US networks — including a bank, software firm, and airport — since early February. CyberAv3ngers, operating under IRGC-CEC direction, previously compromised over 75 US ICS devices in a single campaign using default credentials, and was confirmed to have used ChatGPT to generate Shodan queries for target selection.
Cryptocurrency users faced converging threats through malicious browser extensions and clipboard-hijacking malware. A fake imToken Chrome extension posing as a colour visualiser automatically redirected victims to a phishing domain using Cyrillic and Greek homoglyphs, capturing seed phrases and private keys before handing victims off to the legitimate site as a decoy. Separately, ClipXDaemon, a C2-less Linux malware delivered via a bincrypter-obfuscated loader, silently replaced cryptocurrency wallet addresses in X11 clipboard sessions for Bitcoin, Ethereum, Monero, and five other currencies, with hardcoded attacker wallet addresses encrypted using ChaCha20 and no network communication detectable during execution.
Highlights of the Day
Global Law Enforcement Dismantles LeakBase Stolen Data Forum
LeakBase, an English-language cybercrime forum specialising in stolen credentials and breached databases, has been taken offline following a coordinated international operation led by Europol. Active since 2021, the platform had amassed over 142,000 registered users and served as a marketplace for credential pairs, stealer logs, and compromised account data used to facilitate fraud and account takeover attacks. During enforcement actions on 3–4 March, authorities conducted approximately 100 operations across 14 countries — including arrests and property searches — before seizing the forum's domain and replacing it with a law enforcement splash page. Investigators were also able to deanonymise multiple users through analysis of the forum's seized database.
Cisco SD-WAN Flaws Confirmed as Actively Exploited in the Wild
Cisco has confirmed active exploitation of two vulnerabilities in its Catalyst SD-WAN Manager software — CVE-2026-20122, a high-severity arbitrary file overwrite flaw requiring remote attackers to hold valid read-only API credentials, and CVE-2026-20128, a medium-severity information disclosure vulnerability requiring local access. These disclosures follow last week's confirmation that a separate critical authentication bypass flaw (CVE-2026-20127) had been exploited in zero-day attacks since at least 2023, enabling sophisticated threat actors to introduce rogue peers into targeted networks. CISA has issued Emergency Directive 26-03 requiring federal agencies to inventory affected systems, gather forensic evidence, and investigate potential compromise linked to CVE-2026-20127.
New Linux Malware Hijacks Cryptocurrency Clipboard Addresses Without C2
Cyble Research & Intelligence Labs has identified ClipXDaemon, a Linux malware strain that silently replaces cryptocurrency wallet addresses copied to the clipboard with attacker-controlled alternatives, targeting Bitcoin, Ethereum, Monero, and five other currencies. Delivered via a bincrypter-obfuscated loader, the malware operates exclusively in X11 sessions — deliberately avoiding Wayland environments — and uses double-fork daemonisation and kernel process name spoofing to evade casual detection. Notably, ClipXDaemon contains no command-and-control infrastructure whatsoever; it functions entirely on the local host, with hardcoded replacement wallet addresses encrypted using ChaCha20, making network-based detection strategies ineffective against it.
Google Tracks 90 Zero-Days in 2025 as Enterprise Targeting Hits Record High
Google Threat Intelligence Group tracked 90 zero-day vulnerabilities exploited in the wild during 2025 — up from 78 in 2024, though below the 2023 record of 100 — with enterprise technologies accounting for 48% of all exploited flaws, a new high. PRC-linked espionage groups remained the most prolific state-sponsored exploiters, targeting edge and networking devices, whilst commercial surveillance vendors (CSVs) were attributed with more zero-days than traditional state actors for the first time on record. Financially motivated groups also saw a near-record year, with nine attributed zero-days including two linked to ransomware deployments, and a CL0P-affiliated campaign exploiting Oracle E-Business Suite vulnerabilities weeks before patches became available.
Iran-US Conflict Accelerates Cyber Threat to Industrial Control Systems
Following US strikes on 28 February 2026, more than 60 Iranian-aligned hacktivist groups were activated within hours, intensifying an already-documented threat to US critical infrastructure that includes nation-state actors such as APT33, MuddyWater, and CyberAv3ngers. CloudSEK's assessment maps three primary attack paths used by these groups: direct exploitation of internet-exposed ICS devices — over 78,000 of which respond to unauthenticated Modbus commands in the US alone — phishing campaigns targeting OT-adjacent personnel, and long-dwell IT infiltration with lateral movement into OT environments, exemplified by Volt Typhoon's confirmed presence of at least five years in some US victim networks. The report also notes that AI-assisted tooling has reduced target identification time significantly, with CyberAv3ngers confirmed to have used ChatGPT to generate Shodan queries when selecting ICS targets.
BoryptGrab Stealer Spreads via Fake GitHub Repositories and SEO Tricks
Trend Micro has identified BoryptGrab, a newly discovered Windows information-stealing malware distributed through over a hundred SEO-optimised GitHub repositories masquerading as free software tools, gaming cheats, and productivity applications. The malware harvests browser credentials, cryptocurrency wallet data, screenshots, Telegram files, and Discord tokens, and in some variants deploys a PyInstaller backdoor called TunnesshClient that establishes a reverse SSH tunnel, enabling the attacker to issue commands and proxy traffic through the victim's machine. Russian-language comments in the code and IP addresses associated with campaign infrastructure suggest a possible Russian origin for the threat actor, who has been operating since at least April 2025.
CUPS Printing Stack Flaw Enables Root Code Execution on Unix Systems
A stack-based out-of-bounds write vulnerability (CVE-2025-61915) in CUPS, the Common Unix Printing System, allows an unprivileged user to inject a malicious IPv6 address into cupsd.conf, triggering a stack underflow in the IP address parser that runs as root. Researchers at LevelBlue demonstrated successful privilege escalation to root in a controlled environment using a return-oriented programming (ROP) chain, bypassing stack canary protections as a result of the underflow's memory layout. The vulnerability affects all CUPS versions prior to 2.4.15, and in environments where remote administration is enabled, it is exploitable as an unauthenticated remote code execution flaw.
Fake imToken Chrome Extension Redirects Users to Wallet-Draining Phishing Pages
A malicious Chrome extension posing as a colour visualisation tool has been found impersonating the imToken cryptocurrency wallet, automatically redirecting victims to a threat actor-controlled phishing site upon installation. The extension fetches its destination URL from a remote configuration endpoint, allowing the attacker to retarget victims without modifying the extension itself, whilst the landing page employs Cyrillic and Greek homoglyphs to evade text-based detection and mimic imToken's branding. Victims are funnelled through a convincing wallet-import flow designed to capture either a 12 or 24-word seed phrase or a plaintext private key, before being handed off to the legitimate imToken site as a decoy once the credentials have been submitted.
Daily Coverage