CyberSecBrief

Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks


Daily Cybersecurity Briefing (9 March 2026)

Published: Loading…

At a Glance

  • CVE-2026-20127 in Cisco Catalyst SD-WAN is now widely exploited, with attempts observed from numerous unique IP addresses.
  • Threat actors abuse .arpa reverse DNS domains and IPv6 to host phishing content on infrastructure implicitly trusted by security tools.
  • The 'Digital Lutera' LSPosed module intercepts Android system APIs to spoof phone numbers and bypass UPI SIM-binding on unmodified payment apps.
  • A prompt injection attack against the Cline coding assistant silently installed a rogue OpenClaw agent on thousands of devices via a supply chain compromise.
  • North Korea and other threat actors are using AI agents to automate operational planning and reduce manual effort in cyberattack execution.
  • The EU Advocate General issued an opinion requiring banks to immediately refund unauthorised transactions under PSD2 before assessing customer negligence.

Summary

CVE-2026-20127, affecting Cisco Catalyst SD-WAN, has moved into active widespread exploitation, with attempts recorded from numerous distinct IP addresses. Separately, the FBI is investigating a breach of its own systems reported to have affected infrastructure related to wiretapping and surveillance tools.

Phishing campaigns are exploiting trusted DNS infrastructure to evade detection, with threat actors acquiring IPv6 address space to create A records within .arpa reverse DNS namespaces — domains implicitly trusted by security tooling. The same campaigns also abused over 100 hijacked dangling CNAMEs belonging to government agencies, universities, and retailers, with some subdomain abuses traced back to 2020.

Financial fraud targeting India's UPI ecosystem has advanced through the "Digital Lutera" LSPosed module, which hooks Android system-level APIs to spoof phone numbers, intercept registration SMS messages, and inject forged records — all without modifying the target payment application. The tooling is operated as a fraud-as-a-service model, with a single Telegram channel logging over 500 intercepted UPI authentication messages.

AI agents are functioning as an expanding attack surface and an enabler for threat actors. A supply chain compromise against the Cline coding assistant used prompt injection via a GitHub issue to install a rogue OpenClaw agent on thousands of devices, while a Russian-speaking actor used commercial AI services to compromise over 600 FortiGate appliances across 55 countries with limited technical skill. North Korea and other nation-state actors are also reported to be using AI agents to automate planning and execution tasks.

On the regulatory front, the EU Advocate General issued a formal opinion under PSD2 stating that banks must immediately refund customers for unauthorised transactions regardless of customer negligence, with recovery from negligent customers permitted only as a subsequent step. The opinion arose from a Polish phishing case and, if adopted by the CJEU, would be binding across all EU member states.

Highlights of the Day

Phishing Campaigns Exploit .arpa DNS Infrastructure to Evade Detection

Threat actors have been abusing the .arpa top-level domain — reserved for internet infrastructure functions such as reverse DNS lookups — to host phishing content on domains that security tools implicitly trust. By acquiring IPv6 address space and exploiting misconfigured DNS providers, including Hurricane Electric and Cloudflare, attackers create A records within reverse DNS namespaces, enabling malicious domains to resolve to IP addresses despite this being outside their intended purpose. Infoblox also identified over 100 instances of hijacked dangling CNAMEs belonging to government agencies, universities, and major retailers being used in the same campaigns, with some subdomain abuses dating back to 2020.

The Advocate General of the Court of Justice of the European Union has issued a formal opinion stating that banks must immediately refund customers for unauthorised transactions under the EU Payment Services Directive (PSD2), regardless of whether the customer was negligent. The opinion, arising from a Polish phishing case in which a customer was deceived into entering credentials on a fraudulent banking site, clarifies that gross negligence cannot be used as an initial grounds for refusal — though banks may subsequently pursue recovery from customers found to have been grossly negligent or deliberately complicit. The opinion is not yet binding, as the CJEU's judges must still deliberate and issue a final ruling, which will then apply across all EU member states.

AI Agents Introduce New Attack Surfaces as Adoption Accelerates

Autonomous AI assistants, which can access files, credentials, and online services on a user's behalf, are introducing significant new security risks as they gain traction in corporate and developer environments. Researchers have demonstrated that misconfigured installations of the open-source agent OpenClaw can expose full configuration files — including API keys, OAuth secrets, and months of private message history — to anyone on the internet, while a separate supply chain attack against the Cline coding assistant used prompt injection to silently install a rogue agent on thousands of devices. A documented case from Amazon AWS further illustrated how a low-skilled, Russian-speaking threat actor leveraged multiple commercial AI services to compromise over 600 FortiGate appliances across 55 countries, automating attack planning and lateral movement at scale.

Android Hooking Framework Weaponised to Bypass UPI Banking Security

Threat actors have adapted the LSPosed Android framework to conduct real-time financial fraud against India's Unified Payments Interface (UPI), moving away from modified APK files towards runtime manipulation that leaves legitimate payment applications entirely untouched. A malicious module named "Digital Lutera" intercepts system-level APIs to spoof phone numbers, silently redirect registration SMS messages to a Telegram bot, and inject forged SMS records into the device's sent folder — collectively tricking bank servers into binding a victim's account to an attacker-controlled device. CloudSEK attributed the activity to a threat actor operating as "Berlin," who appears to sell the tooling as a fraud-as-a-service offering within Indian cybercrime communities, with one Telegram channel showing over 500 intercepted UPI login messages.

Source: CloudSEK

Daily Coverage

Developments
Cisco Sd-Wan Exploitation.Arpa Phishing AbuseDigital Lutera / Upi FraudCline Supply Chain Attack
Vulnerabilities
CVE-2026-2833CVE-2026-2835CVE-2026-2836CVE-2026-20127A Vulnerability In The Peering Authentication In Cisco Catalyst Sd-Wan Controller, Formerly Sd-Wan Vsmart, And Cisco Catalyst Sd-Wan Manager, Formerly Sd-Wan Vmanage, Could Allow An Unauthenticated, Remote Attacker To Bypass Authentication And Obtain Administrative Privileges On An Affected System. This Vulnerability Exists Because The Peering Authentication Mechanism In An Affected System Is Not Working Properly. An Attacker Could Exploit This Vulnerability By Sending Crafted Requests To An …
Threat Groups
SilenceSilence is a financially motivated threat actor targeting financial institutions in different countries. The group was first seen in June 2016. Their main targets reside in Russia, Ukraine, Belarus, Azerbaijan, Poland and Kazakhstan. They compromised various banking systems, including the Russian Central Bank's Automated Workstation Client, ATMs, and card processing.INC RansomINC Ransom is a ransomware and data extortion threat group associated with the deployment of INC Ransomware that has been active since at least July 2023. INC Ransom has targeted organizations worldwide most commonly in the industrial, healthcare, and education sectors in the US and Europe.