Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks
Daily Cybersecurity Briefing (13 March 2026)
Published: Loading…
At a Glance
- Void Manticore's Handala Hack expanded destructive wiper attacks to US targets, hitting medical technology firm Stryker and deploying four simultaneous wiping techniques.
- CISA added CVE-2025-68613, a max-severity n8n expression injection flaw enabling unauthenticated RCE, to its Known Exploited Vulnerabilities catalogue with 24,700 instances exposed.
- Apple backported patches for four Coruna exploit kit CVEs to iOS 15.8.7 and 16.7.15, addressing WebKit use-after-free and type confusion flaws enabling arbitrary code execution.
- Storm-2561 deployed digitally signed Hyrax infostealer trojans via SEO-poisoned VPN software pages, targeting Pulse Secure, Fortinet, and Ivanti users since May 2025.
- US and European law enforcement dismantled SocksEscort, a residential proxy network that compromised approximately 369,000 routers to facilitate fraud and account takeovers.
- Six malicious Packagist themes bundled trojanised jQuery files linked to OFAC-sanctioned FUNNULL infrastructure, exfiltrating URLs and redirecting mobile users to gambling sites.
Summary
Multiple critical vulnerabilities in workflow and AI serving platforms entered active exploitation or remained unpatched. CISA added CVE-2025-68613, a CVSS 9.9 expression injection flaw in n8n, to its Known Exploited Vulnerabilities catalogue, with over 24,700 instances exposed and a separate zero-click unauthenticated RCE (CVE-2026-27493) also disclosed. Three unpatched RCE vulnerabilities in the SGLang LLM serving framework — two rated CVSS 9.8 — remained without an official fix after maintainers did not respond to coordinated disclosure through CERT/CC.
Iran-linked Void Manticore, operating under the Handala Hack persona, conducted a destructive attack against US medical technology firm Stryker, deploying four simultaneous wiping techniques — including a custom MBR wiper, AI-assisted PowerShell file deletion, VeraCrypt disk encryption, and manual deletion — distributed via Group Policy. Stryker confirmed in an SEC Form 8-K filing that the attack caused a global disruption to its Microsoft environment, with the recovery timeline remaining unknown.
Apple issued backported security updates for older iPhones, iPads, and iPod touch models, patching four CVEs linked to the Coruna exploit kit across iOS 15.8.7 and 16.7.15. The Coruna kit, featuring 23 exploits across five chains targeting iOS 13.0 through 17.2.1, has been observed in targeted espionage campaigns, watering hole attacks against Ukrainian users, and more recently against fake Chinese financial websites.
Supply chain threats surfaced across multiple package ecosystems. Six malicious Composer packages on Packagist bundled trojanised jQuery files that exfiltrated visitor URLs and redirected mobile users through infrastructure operated by OFAC-sanctioned FUNNULL, with the payload confirmed active as recently as 10 March 2026. Separately, the 2024 Polyfill.io supply chain attack affecting over 100,000 sites, initially attributed to Chinese actors, has been linked to North Korean involvement following an infostealer infection.
Credential theft operations expanded through multiple vectors. Storm-2561 used SEO poisoning to distribute digitally signed trojanised installers impersonating Pulse Secure, Fortinet, and Ivanti VPN clients, deploying the Hyrax infostealer to exfiltrate VPN credentials before redirecting victims to legitimate vendor sites. Phishing-as-a-service platforms Tycoon2FA and Sneaky2FA operationalised multi-layered URL rewriting chains across up to five security vendors — including Cisco, Sophos, and Barracuda — to bypass email controls and conduct adversary-in-the-middle credential interception.
A coordinated international law enforcement operation led by the US Department of Justice dismantled SocksEscort, a residential proxy network that had compromised approximately 369,000 routers since 2020 to facilitate bank account takeovers, cryptocurrency theft, and fraudulent unemployment claims. In parallel, Cisco patched high-severity vulnerabilities in IOS XR, and CISA issued an emergency directive over actively exploited flaws in Cisco SD-WAN Manager, with CVE-2026-20127 and several related vulnerabilities seeing in-the-wild exploitation.
Highlights of the Day
Global Law Enforcement Operation Takes Down Malicious Proxy Network SocksEscort
A coordinated international law enforcement action led by the US Department of Justice has dismantled SocksEscort, a residential proxy service that infected home and small business routers with malware to route criminal internet traffic. Since 2020, the service offered access to approximately 369,000 compromised IP addresses, with around 8,000 active at the time of the operation. Cybercriminals used the network to mask their locations whilst conducting bank account takeovers, cryptocurrency theft, and fraudulent unemployment claims, causing millions of dollars in losses across the United States.
Apple Backports WebKit Patches to Older Devices Amid Coruna Exploit Kit Findings
Apple has issued security updates for older iPhone, iPad, and iPod touch models, backporting fixes for several WebKit and kernel vulnerabilities linked to the Coruna exploit kit. The updates — iOS 15.8.7, iPadOS 15.8.7, iOS 16.7.15, and iPadOS 16.7.15 — address four CVEs, including use-after-free and type confusion flaws capable of enabling arbitrary code execution. Coruna, which features 23 exploits across five chains targeting iOS 13.0 through 17.2.1, has attracted scrutiny over its origins, with speculation around links to US military contractor L3Harris, though attribution remains unconfirmed.
GCVE Launches Federated Vulnerability Publishing Ecosystem to Rival CVE
Luxembourg's CIRCL has launched a decentralised vulnerability publishing ecosystem under GCVE, alongside the release of Vulnerability-Lookup 4.1.0, offering an alternative to the centralised CVE model. The system introduces GCVE Numbering Authorities (GNAs), allowing eligible organisations — including existing CVE CNAs, registered CSIRTs, and software vendors — to issue their own vulnerability identifiers and synchronise records across a federated network with no single point of control. The platform now aggregates over one million vulnerability records from more than 25 sources, with version 4.1.0 adding full-text search capabilities and eight new advisory feeds.
Critical Unpatched RCE Flaws Found in SGLang AI Serving Framework
Researchers at Orca Security have disclosed three vulnerabilities in SGLang, an open-source framework widely used for serving large language models, with two rated critical at CVSS 9.8. CVE-2026-3059 and CVE-2026-3060 allow unauthenticated remote code execution via Python's pickle deserialisation on exposed ZeroMQ sockets, affecting deployments with multimodal generation or disaggregation features enabled; CVE-2026-3989 introduces a local code execution risk through an unsafe crash dump replay utility. Despite coordinated disclosure through CERT/CC beginning in February 2026 — including outreach to CISA — SGLang maintainers have not responded, and no official patch has been released.
Zero-Click RCE in n8n Workflow Platform Exposed Over 50,000 Public Forms
Pillar Security has disclosed two critical vulnerabilities in n8n, a workflow automation platform used by over 230,000 organisations, affecting both self-hosted and cloud deployments. CVE-2026-27493 (CVSS 9.5) is an unauthenticated, zero-click remote code execution flaw in the Form node, where a double-evaluation bug allows attackers to inject and execute expressions via public-facing form submissions — no account or authentication required. CVE-2026-27577 (CVSS 9.4) is a sandbox escape in n8n's expression compiler, exploiting an unhandled SpreadElement AST node to access Node.js globals and achieve full RCE. Patches are available in versions 2.10.1, 2.9.3, and 1.123.22.
Six Malicious Packagist Themes Deliver FUNNULL Payloads via Trojanised jQuery
Socket's Threat Research Team has identified six malicious Composer packages published under the ophimcms namespace on Packagist, designed to impersonate themes for the Vietnamese Laravel CMS OphimCMS. The packages bundle trojanised jQuery files carrying payloads that exfiltrate visitor URLs, inject advertisements, hijack clicks, and — in the most severe case — redirect mobile users to gambling and adult content sites via infrastructure operated by FUNNULL Technology Inc., a Philippines-based CDN sanctioned by OFAC in May 2025 for facilitating over $200 million in cryptocurrency fraud. The FUNNULL-linked payload was confirmed still active as recently as 10 March 2026, with the six packages collectively accumulating approximately 2,750 installs at the time of analysis.
Storm-2561 Uses Fake VPN Installers to Harvest Enterprise Credentials
Microsoft Threat Intelligence has detailed a campaign by cybercriminal group Storm-2561, active since May 2025, which uses SEO poisoning to push spoofed VPN vendor websites to the top of search results, tricking users into downloading trojanised installers for products including Pulse Secure, Fortinet, and Ivanti. The malicious MSI files, hosted on now-removed GitHub repositories and signed with a legitimate but since-revoked certificate, side-load the Hyrax infostealer to capture VPN credentials and configuration data before exfiltrating them to attacker-controlled infrastructure. After credential theft, the fake client displays an error message and redirects victims to the legitimate software vendor's site, leaving no obvious signs of compromise.
Iran-Linked Handala Hack Expands Destructive Wiper Attacks to US Targets
Check Point Research has published a detailed analysis of Handala Hack, an online persona operated by Void Manticore, an Iranian threat actor affiliated with the Ministry of Intelligence and Security (MOIS), known for destructive wiper attacks combined with hack-and-leak operations. Previously focused on Israel and Albania, the group has recently expanded its targeting to US organisations, including medical technology firm Stryker, whilst adopting new tactics such as deploying NetBird for internal network tunnelling and an AI-assisted PowerShell wiper for file destruction. During intrusions, the group deploys up to four simultaneous wiping techniques — including a custom MBR wiper, PowerShell-based file deletion, VeraCrypt disk encryption, and manual deletion — distributed via Group Policy across compromised networks.
Phishing Campaigns Chain Multiple Trusted URL Services to Evade Detection
LevelBlue SpiderLabs has documented a significant escalation in phishing tactics between Q2 and Q4 2025, with threat actors deliberately stacking multiple layers of URL rewriting from separate security vendors — including Cisco, Sophos, Barracuda, and others — to obscure final malicious destinations and bypass email security controls. The technique, operationalised through phishing-as-a-service platforms Tycoon2FA and Sneaky2FA, chains up to six consecutive rewrites across as many as five vendors, with the outermost links appearing to originate from trusted security provider domains. Both frameworks employ adversary-in-the-middle architecture to intercept credentials and session cookies in real time, enabling account takeover and follow-on attacks including business email compromise and ransomware deployment.
Daily Coverage