CyberSecBrief

Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks


Daily Cybersecurity Briefing (12 March 2026)

Published: Loading…

At a Glance

  • Handala, an Iran-linked hacktivist group, claimed a wiper attack on Stryker erasing data from over 200,000 devices across 79 countries.
  • Six state-aligned threat actors — including TA453, UNC6426, and TA473 — launched conflict-themed espionage campaigns against Middle East governments after Operation Epic Fury.
  • CISA ordered federal agencies to patch CVE-2026-27493 and CVE-2026-27577, two critical n8n RCE flaws under active exploitation.
  • UNC6426 used keys stolen via the nx npm supply chain compromise to fully breach a victim's cloud environment within 72 hours.
  • Microsoft's March 2026 Patch Tuesday addressed 84 vulnerabilities including CVE-2026-21262, a network-exploitable SQL Server privilege escalation to sysadmin.
  • Meta disabled 150,000 accounts linked to Southeast Asian scam centres and removed 10.9 million Facebook and Instagram accounts in 2025.

Summary

Handala (Handala Hack Team), an Iran-linked hacktivist group, claimed responsibility for a destructive wiper attack against medical technology company Stryker, asserting that data was erased from more than 200,000 systems, servers, and mobile devices across 79 countries. Stryker confirmed the cyberattack and disruption to operations, with more than 5,000 workers sent home from its Irish facilities. Iran also designated Amazon, Google, Microsoft, Oracle, and other US technology companies as potential targets for retaliatory strikes following Operation Epic Fury.

The US–Israel military operation against Iran triggered a surge in state-aligned cyber espionage, with at least six threat actor groups — including TA453 (Charming Kitten), TA402, TA473 (Winter Vivern), and newly identified clusters UNK_InnerAmbush, UNK_RobotDreams, and UNK_NightOwl — conducting conflict-themed phishing campaigns against Middle Eastern and European government organisations. Iran-linked hackers separately claimed a cyberattack on Albania's parliamentary email systems. TA453 continued credential phishing operations against US thinktanks that had commenced before the conflict began.

CISA added two critical n8n workflow automation vulnerabilities — CVE-2026-27493 (CVSS 9.5, unauthenticated access) and CVE-2026-27577 (CVSS 9.4, sandbox escape to RCE) — to its Known Exploited Vulnerabilities catalogue, ordering federal agencies to patch. Microsoft's March 2026 Patch Tuesday addressed 84 vulnerabilities, including CVE-2026-21262, a network-exploitable SQL Server privilege escalation to sysadmin, and CVE-2026-26144, an Excel cross-site scripting flaw capable of triggering zero-click data exfiltration via Copilot Agent mode. ICS vendors Siemens, Schneider Electric, Mitsubishi Electric, and Moxa also published Patch Tuesday advisories.

Developer supply chains continued to be targeted across multiple ecosystems. UNC6426 exploited credentials stolen via the nx npm package supply chain compromise to fully breach a cloud environment within 72 hours, beginning with a stolen GitHub token. Five malicious Rust crates on crates.io — posing as time utilities — exfiltrated .env files to attacker-controlled infrastructure, while 88 new PhantomRaven npm packages using Remote Dynamic Dependencies continued to harvest CI/CD tokens and developer credentials.

BlackSanta malware, deployed via fake CV submissions targeting HR departments, disables endpoint detection and response tools at the kernel level before conducting credential theft and system reconnaissance. The RondoDox botnet has deployed 174 distinct exploits against internet-exposed devices since May 2025, peaking at 15,000 exploitation attempts per day and adding CVE-2025-55182 just three days after its public disclosure. The Medusa ransomware group's February 2025 attack on Bell Ambulance in Wisconsin resulted in the theft of sensitive data belonging to 237,830 individuals.

Meta disabled over 150,000 accounts linked to Southeast Asian scam centres in a coordinated action involving law enforcement from eleven countries, resulting in 21 arrests by Thai police. The company separately removed 10.9 million Facebook and Instagram accounts linked to criminal scam operations in 2025 and took down 159 million scam advertisements. An AI-powered vishing-as-a-service platform abusing ElevenLabs text-to-speech capabilities was identified facilitating automated "press 1" phone fraud campaigns.

Highlights of the Day

Microsoft March 2026 Patch Tuesday Fixes 84 Flaws, Including AI-Discovered RCE

Microsoft's March 2026 Patch Tuesday addresses 84 vulnerabilities, with 46 relating to privilege escalation — six of which are rated "exploitation more likely" across Windows Graphics Component, Accessibility Infrastructure, Kernel, SMB Server, and Winlogon. Two publicly disclosed flaws are included: CVE-2026-21262, a network-exploitable SQL Server privilege escalation to sysadmin (CVSS 8.8), and CVE-2026-26127, a .NET denial-of-service vulnerability. Notably, CVE-2026-21536, a critical CVSS 9.8 remote code execution flaw in the Microsoft Devices Pricing Program, was discovered by XBOW — a fully autonomous AI penetration testing agent — and had already been mitigated by Microsoft prior to public disclosure.

BlackSanta EDR Killer Targets HR Teams via Fake Job Applications

A Russian-speaking threat actor has been running a sustained campaign against corporate HR departments and recruiters, delivering malware through fake CV submissions that ultimately install an EDR-killing component named BlackSanta. The malware employs DLL sideloading for initial execution, conducts extensive environment checks — including anti-VM, anti-debugging, and locale verification — before proceeding, and downloads additional payloads once it confirms a genuine target environment. BlackSanta's primary function is to disable endpoint detection and response tools, clearing the way for unimpeded data theft and further compromise of the host system.

Source: Aryaka

Medusa Ransomware Breach at Wisconsin Ambulance Service Hits 235,000

Bell Ambulance, Wisconsin's largest ambulance provider, has confirmed that a February 2025 ransomware attack attributed to the Medusa gang resulted in the theft of sensitive data belonging to 237,830 individuals, including Social Security numbers, financial account details, medical information, and health insurance records. The Medusa group demanded a $400,000 ransom for 219 GB of stolen data, and notifications to victims continued through autumn 2025 as additional affected individuals were identified. Medusa, a ransomware-as-a-service operation active since June 2021, has been linked to more than 300 attacks on critical infrastructure organisations and was the subject of an FBI advisory issued one month after the Bell Ambulance incident.

Source: The Record

Telegram Bots Increasingly Abused for Credential Theft and Malware C2

Threat actors are systematically abusing the Telegram Bot API to exfiltrate stolen credentials and host data, with 3.8% of malware-based active threat reports and 2.3% of credential phishing campaigns between Q1 2024 and Q2 2025 using Telegram as a command-and-control channel. Agent Tesla Keylogger accounts for 77.7% of all Telegram-based C2 activity observed in 2024, using the API's file upload functionality to transmit archives of credentials harvested from browsers, email clients, and FTP clients. The Telegram Bot API's design inadvertently aids investigators: authentication tokens and chat room IDs are transmitted in plaintext within API requests, allowing analysts who obtain them to query and forward historical bot messages for threat intelligence purposes.

Source: Cofense

RondoDox Botnet Exploits 174 Vulnerabilities, Targets IoT at Scale

The RondoDox botnet, first observed in May 2025, has deployed 174 distinct exploits against internet-exposed devices — including 148 mapped CVEs — peaking at 15,000 exploitation attempts in a single day and supporting 18 processor architectures. Operating from 32 identified IP addresses, the botnet's infrastructure likely includes compromised residential devices used as payload-hosting servers, whilst dedicated hosting providers accepting cryptocurrency payments handle the active scanning activity. Operators have demonstrated rapid vulnerability adoption, adding CVE-2025-55182 (React2Shell) just three days after its December 2025 disclosure, though analysis of implemented exploits reveals recurring implementation errors that reduce their effectiveness.

Source: Bitsight

US–Iran Conflict Triggers Multi-Actor Espionage Wave Against Middle East Targets

Following US and Israeli strikes against Iranian assets on 28 February 2026 (Operation Epic Fury), at least six state-aligned threat actor groups launched conflict-themed phishing campaigns targeting Middle Eastern government and diplomatic organisations, with suspected attribution spanning China, Pakistan, Belarus, Hamas, and Iran. China-linked UNK_InnerAmbush deployed Cobalt Strike via DLL sideloading within LNK files disguised as conflict imagery; Pakistan-suspected UNK_RobotDreams delivered a Rust backdoor via a geofenced fake Adobe Reader installer; and Belarus-aligned TA473 (Winter Vivern) extended its targeting to Middle Eastern governments for the first time. Iran's TA453 (Charming Kitten) continued credential phishing operations against US thinktanks that had begun before the conflict, indicating sustained intelligence collection priorities irrespective of the military escalation.

Source: Proofpoint

Daily Coverage

Developments
Stryker Wiper AttackOperation Epic Fury EspionageN8N Rce ExploitationNx Npm / Unc6426
Vulnerabilities
CVE-2025-68613N8N >= 0.211.0, < 1.120.4 (Critical)CVE-2023-43010CVE-2026-26123CVE-2026-20435CVE-2023-43000CVE-2024-23222CVE-2026-20127A Vulnerability In The Peering Authentication In Cisco Catalyst Sd-Wan Controller, Formerly Sd-Wan Vsmart, And Cisco Catalyst Sd-Wan Manager, Formerly Sd-Wan Vmanage, Could Allow An Unauthenticated, Remote Attacker To Bypass Authentication And Obtain Administrative Privileges On An Affected System. This Vulnerability Exists Because The Peering Authentication Mechanism In An Affected System Is Not Working Properly. An Attacker Could Exploit This Vulnerability By Sending Crafted Requests To An …CVE-2026-26127CVE-2026-27577N8N < 1.123.22 (Critical)CVE-2026-21536
Threat Groups
TA473[Also known as: Winter Vivern] Winter Vivern is a group linked to Russian and Belorussian interests active since at least 2020 targeting various European government and NGO entities, along with sporadic targeting of Indian and US victims. The group leverages a combination of documentbased phishing activity and serverside exploitation for initial access, leveraging adversarycontrolled and created infrastructure for followon command and control.Charming Kitten[Also known as: TA453] Magic Hound is an Iraniansponsored threat group that conducts long term, resourceintensive cyber espionage operations, likely on behalf of the Islamic Revolutionary Guard Corps. They have targeted European, U. S., and Middle Eastern government and military personnel, academics, journalists, and organizations such as the World Health Organization (WHO), via complex social engineering campaigns since at least 2014.Medusa GroupMedusa Group has been active since at least 2021 and was initially operated as a closed ransomware group before evolving into a RansomwareasaService (RaaS) operation. Some reporting indicates that certain attacks may still be conducted directly by the ransomware’s core developers. Public sources have also referred to the group as “Spearwing” or “Medusa Actors.” Medusa Group employs livingofftheland techniques, frequently leveraging publicly available tools and common remote management software to conduct operations. The group engages in double extortion tactics, exfiltrating data prior to encryption and threatening to publish stolen information if ransom demands are not met. For initial access, Medusa Group has exploited publicly known vulnerabilities, conducted phishing campaigns, and used credentials or access purchased from Initial Access Brokers (IABs). The group is opportunistic and has targeted a wide range of sectors globally.