CyberSecBrief

Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks


Daily Cybersecurity Briefing (6 March 2026)

Published: Loading…

At a Glance

  • Cisco confirmed active exploitation of CVE-2026-20122 and CVE-2026-20128 in Catalyst SD-WAN Manager, with CISA issuing Emergency Directive 26-03.
  • Tycoon 2FA, a subscription PhaaS kit linked to 64,000 AiTM attacks, was dismantled by Europol and private sector partners.
  • LeakBase, a stolen-credential forum with 142,000 users, was seized by Europol across 14 countries with approximately 100 enforcement actions.
  • UAT-9244, a China-nexus APT, deployed three new malware implants — TernDoor, PeerTime, and BruteEntry — against South American telecoms since 2024.
  • CVE-2025-61915 in CUPS allows an unprivileged user to trigger a stack underflow via a malicious IPv6 address, enabling root code execution.
  • 48% of 90 zero-days exploited in 2025 targeted enterprise technologies, with commercial surveillance vendors attributed more zero-days than state actors for the first time.

Summary

Cisco Catalyst SD-WAN Manager vulnerabilities continued to attract active exploitation, with CVE-2026-20122 (arbitrary file overwrite) and CVE-2026-20128 (information disclosure) confirmed as exploited in the wild. These follow the earlier confirmation of CVE-2026-20127, a critical authentication bypass exploited in zero-day attacks since at least 2023. Cisco also released patches for 48 separate vulnerabilities across Firewall ASA, Secure FMC, and Secure FTD product lines, including two maximum-severity flaws in Secure Firewall Management Center, while CISA issued Emergency Directive 26-03 requiring federal agencies to inventory affected SD-WAN systems and investigate potential compromise.

Two major cybercriminal platforms were dismantled in coordinated international operations. Tycoon 2FA, a subscription-based phishing-as-a-service kit active since August 2023 and responsible for approximately 62% of phishing attempts blocked by Microsoft at its peak, was taken down by Europol alongside law enforcement and private sector partners including Microsoft, Cloudflare, and Coinbase. Separately, LeakBase, an open-web stolen-credential forum with over 142,000 registered users and 215,000 private messages, was seized across 14 countries during approximately 100 enforcement actions on 3–4 March, with investigators deanonymising multiple users through analysis of the forum's seized database.

Nation-state actors expanded targeting of network infrastructure on multiple fronts. UAT-9244, assessed with high confidence as a China-nexus APT closely associated with Famous Sparrow, deployed three previously undocumented implants — TernDoor, PeerTime, and BruteEntry — against South American telecommunications providers since 2024, converting compromised edge devices into mass-scanning proxy nodes. An APT28-linked campaign simultaneously targeted Ukrainian entities with two undocumented malware families, BadPaw and MeowMeow, initiated via phishing emails containing ZIP-archived HTA lure documents written in Ukrainian.

Following US strikes on 28 February 2026, over 60 Iranian-aligned hacktivist groups activated within hours, intensifying documented threats against US ICS/OT infrastructure. Over 78,000 US ICS devices respond to unauthenticated Modbus commands from the internet, while MOIS-linked MuddyWater has been embedded in multiple US networks — including a bank, software firm, and airport — since early February. CyberAv3ngers, operating under IRGC-CEC direction, previously compromised over 75 US ICS devices in a single campaign using default credentials, and was confirmed to have used ChatGPT to generate Shodan queries for target selection.

Cryptocurrency users faced converging threats through malicious browser extensions and clipboard-hijacking malware. A fake imToken Chrome extension posing as a colour visualiser automatically redirected victims to a phishing domain using Cyrillic and Greek homoglyphs, capturing seed phrases and private keys before handing victims off to the legitimate site as a decoy. Separately, ClipXDaemon, a C2-less Linux malware delivered via a bincrypter-obfuscated loader, silently replaced cryptocurrency wallet addresses in X11 clipboard sessions for Bitcoin, Ethereum, Monero, and five other currencies, with hardcoded attacker wallet addresses encrypted using ChaCha20 and no network communication detectable during execution.

Highlights of the Day

Global Law Enforcement Dismantles LeakBase Stolen Data Forum

LeakBase, an English-language cybercrime forum specialising in stolen credentials and breached databases, has been taken offline following a coordinated international operation led by Europol. Active since 2021, the platform had amassed over 142,000 registered users and served as a marketplace for credential pairs, stealer logs, and compromised account data used to facilitate fraud and account takeover attacks. During enforcement actions on 3–4 March, authorities conducted approximately 100 operations across 14 countries — including arrests and property searches — before seizing the forum's domain and replacing it with a law enforcement splash page. Investigators were also able to deanonymise multiple users through analysis of the forum's seized database.

Source: Europol

Cisco SD-WAN Flaws Confirmed as Actively Exploited in the Wild

Cisco has confirmed active exploitation of two vulnerabilities in its Catalyst SD-WAN Manager software — CVE-2026-20122, a high-severity arbitrary file overwrite flaw requiring remote attackers to hold valid read-only API credentials, and CVE-2026-20128, a medium-severity information disclosure vulnerability requiring local access. These disclosures follow last week's confirmation that a separate critical authentication bypass flaw (CVE-2026-20127) had been exploited in zero-day attacks since at least 2023, enabling sophisticated threat actors to introduce rogue peers into targeted networks. CISA has issued Emergency Directive 26-03 requiring federal agencies to inventory affected systems, gather forensic evidence, and investigate potential compromise linked to CVE-2026-20127.

New Linux Malware Hijacks Cryptocurrency Clipboard Addresses Without C2

Cyble Research & Intelligence Labs has identified ClipXDaemon, a Linux malware strain that silently replaces cryptocurrency wallet addresses copied to the clipboard with attacker-controlled alternatives, targeting Bitcoin, Ethereum, Monero, and five other currencies. Delivered via a bincrypter-obfuscated loader, the malware operates exclusively in X11 sessions — deliberately avoiding Wayland environments — and uses double-fork daemonisation and kernel process name spoofing to evade casual detection. Notably, ClipXDaemon contains no command-and-control infrastructure whatsoever; it functions entirely on the local host, with hardcoded replacement wallet addresses encrypted using ChaCha20, making network-based detection strategies ineffective against it.

Source: Cyble

Google Tracks 90 Zero-Days in 2025 as Enterprise Targeting Hits Record High

Google Threat Intelligence Group tracked 90 zero-day vulnerabilities exploited in the wild during 2025 — up from 78 in 2024, though below the 2023 record of 100 — with enterprise technologies accounting for 48% of all exploited flaws, a new high. PRC-linked espionage groups remained the most prolific state-sponsored exploiters, targeting edge and networking devices, whilst commercial surveillance vendors (CSVs) were attributed with more zero-days than traditional state actors for the first time on record. Financially motivated groups also saw a near-record year, with nine attributed zero-days including two linked to ransomware deployments, and a CL0P-affiliated campaign exploiting Oracle E-Business Suite vulnerabilities weeks before patches became available.

Iran-US Conflict Accelerates Cyber Threat to Industrial Control Systems

Following US strikes on 28 February 2026, more than 60 Iranian-aligned hacktivist groups were activated within hours, intensifying an already-documented threat to US critical infrastructure that includes nation-state actors such as APT33, MuddyWater, and CyberAv3ngers. CloudSEK's assessment maps three primary attack paths used by these groups: direct exploitation of internet-exposed ICS devices — over 78,000 of which respond to unauthenticated Modbus commands in the US alone — phishing campaigns targeting OT-adjacent personnel, and long-dwell IT infiltration with lateral movement into OT environments, exemplified by Volt Typhoon's confirmed presence of at least five years in some US victim networks. The report also notes that AI-assisted tooling has reduced target identification time significantly, with CyberAv3ngers confirmed to have used ChatGPT to generate Shodan queries when selecting ICS targets.

Source: CloudSEK

BoryptGrab Stealer Spreads via Fake GitHub Repositories and SEO Tricks

Trend Micro has identified BoryptGrab, a newly discovered Windows information-stealing malware distributed through over a hundred SEO-optimised GitHub repositories masquerading as free software tools, gaming cheats, and productivity applications. The malware harvests browser credentials, cryptocurrency wallet data, screenshots, Telegram files, and Discord tokens, and in some variants deploys a PyInstaller backdoor called TunnesshClient that establishes a reverse SSH tunnel, enabling the attacker to issue commands and proxy traffic through the victim's machine. Russian-language comments in the code and IP addresses associated with campaign infrastructure suggest a possible Russian origin for the threat actor, who has been operating since at least April 2025.

CUPS Printing Stack Flaw Enables Root Code Execution on Unix Systems

A stack-based out-of-bounds write vulnerability (CVE-2025-61915) in CUPS, the Common Unix Printing System, allows an unprivileged user to inject a malicious IPv6 address into cupsd.conf, triggering a stack underflow in the IP address parser that runs as root. Researchers at LevelBlue demonstrated successful privilege escalation to root in a controlled environment using a return-oriented programming (ROP) chain, bypassing stack canary protections as a result of the underflow's memory layout. The vulnerability affects all CUPS versions prior to 2.4.15, and in environments where remote administration is enabled, it is exploitable as an unauthenticated remote code execution flaw.

Source: LevelBlue

Fake imToken Chrome Extension Redirects Users to Wallet-Draining Phishing Pages

A malicious Chrome extension posing as a colour visualisation tool has been found impersonating the imToken cryptocurrency wallet, automatically redirecting victims to a threat actor-controlled phishing site upon installation. The extension fetches its destination URL from a remote configuration endpoint, allowing the attacker to retarget victims without modifying the extension itself, whilst the landing page employs Cyrillic and Greek homoglyphs to evade text-based detection and mimic imToken's branding. Victims are funnelled through a convincing wallet-import flow designed to capture either a 12 or 24-word seed phrase or a plaintext private key, before being handed off to the legitimate imToken site as a decoy once the credentials have been submitted.

Source: Socket

Daily Coverage

Developments
Tycoon 2Fa TakedownLeakbase DismantledCisco Sd-Wan ExploitationUat-9244 Telco Attacks
Vulnerabilities
CVE-2017-7921CVE-2026-20079Cisco Secure Firewall Management Center (Fmc) 7.0.0 (Critical)CVE-2026-20131CVE-2026-29000Pac4J-Jwt 4.0 (Critical)CVE-2026-20127A Vulnerability In The Peering Authentication In Cisco Catalyst Sd-Wan Controller, Formerly Sd-Wan Vsmart, And Cisco Catalyst Sd-Wan Manager, Formerly Sd-Wan Vmanage, Could Allow An Unauthenticated, Remote Attacker To Bypass Authentication And Obtain Administrative Privileges On An Affected System. This Vulnerability Exists Because The Peering Authentication Mechanism In An Affected System Is Not Working Properly. An Attacker Could Exploit This Vulnerability By Sending Crafted Requests To An …CVE-2025-61915CVE-2026-20128CVE-2026-20122CVE-2026-23865Freetype 2.13.2 (Medium)CVE-2026-3086
Threat Groups
MuddyWater[Also known as: Seedworm] MuddyWater is a cyber espionage group assessed to be a subordinate element within Iran's Ministry of Intelligence and Security (MOIS). Since at least 2017, MuddyWater has targeted a range of government and private organizations across sectors, including telecommunications, local government, defense, and oil and natural gas organizations, in the Middle East, Asia, Africa, Europe, and North America.Transparent TribeTransparent Tribe is a suspected Pakistanbased threat group that has been active since at least 2013, primarily targeting diplomatic, defense, and research organizations in India and Afghanistan.APT28APT28 is a threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) 85th Main Special Service Center (GTsSS) military unit 26165. This group has been active since at least 2004. APT28 reportedly compromised the Hillary Clinton campaign, the Democratic National Committee, and the Democratic Congressional Campaign Committee in 2016 in an attempt to interfere with the U. S. presidential election. In 2018, the US indicted five GRU Unit 26165 officers associated with APT28 for cyber operations (including closeaccess operations) conducted between 2014 and 2018 against the World AntiDoping Agency (WADA), the US AntiDoping Agency, a US nuclear facility, the Organization for the Prohibition of Chemical Weapons (OPCW), the Spiez Swiss Chemicals Laboratory, and other organizations. Some of these were conducted with the assistance of GRU Unit 74455, which is also referred to as Sandworm Team.APT33APT33 is a suspected Iranian threat group that has carried out operations since at least 2013. The group has targeted organizations across multiple industries in the United States, Saudi Arabia, and South Korea, with a particular interest in the aviation and energy sectors.Volt TyphoonVolt Typhoon is a People's Republic of China (PRC) statesponsored actor that has been active since at least 2021 primarily targeting critical infrastructure organizations in the US and its territories including Guam. Volt Typhoon's targeting and pattern of behavior have been assessed as prepositioning to enable lateral movement to operational technology (OT) assets for potential destructive or disruptive attacks. Volt Typhoon has emphasized stealth in operations using web shells, livingofftheland (LOTL) binaries, hands on keyboard activities, and stolen credentials.