Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks
Daily Cybersecurity Briefing (14 March 2026)
Published: Loading…
At a Glance
- Nine CrackArmor vulnerabilities in Linux AppArmor allow unprivileged users to escalate to root, crash systems, and break container isolation on Ubuntu, Debian, and SUSE.
- Google patched two actively exploited Chrome zero-days, CVE-2026-3909 in Skia and CVE-2026-3910 in V8, both confirmed exploited in the wild before patching.
- Veeam released fixes for five Backup & Replication vulnerabilities, including CVE-2026-21669 and CVE-2026-21708, both CVSS 9.9, enabling authenticated RCE.
- GlassWorm expanded its Open VSX campaign to 72 malicious extensions, abusing extensionPack and extensionDependencies to distribute malware through transitive dependencies.
- INTERPOL's Operation Synergia III dismantled 45,000 malicious IP addresses and arrested 94 individuals across 72 countries targeting phishing and ransomware infrastructure.
- Starbucks disclosed a breach of 889 employee Partner Central accounts exposing Social Security numbers, dates of birth, and financial account details via credential phishing.
Summary
Multiple critical vulnerabilities across widely deployed software created significant patching pressure. Veeam Backup & Replication received fixes for five flaws including CVE-2026-21669 and CVE-2026-21708, both rated CVSS 9.9. Nine CrackArmor vulnerabilities in the Linux AppArmor module, present since kernel version 4.11, allow unprivileged local users to escalate to root, exhaust kernel stacks, bypass KASLR, and break container isolation on Ubuntu, Debian, and SUSE systems.
Google patched two high-severity Chrome zero-days under active exploitation: CVE-2026-3909, an out-of-bounds write in the Skia graphics library, and CVE-2026-3910, an inappropriate implementation in the V8 JavaScript engine, both confirmed exploited in the wild before patches landed in Chrome 146.0.7680.75/76.
Supply chain threats expanded across developer tooling ecosystems. The GlassWorm campaign escalated to 72 malicious Open VSX extensions, abusing extensionPack and extensionDependencies manifest fields to deliver malware transitively through later updates, with loader infrastructure rotating Solana wallet addresses and shifting decryption material into HTTP response headers. Separately, invisible Unicode character injections linked to the same campaign were identified across more than 150 GitHub repositories as well as npm packages.
Iran-linked Handala conducted a destructive attack against Stryker, disrupting its global Microsoft environment with evidence suggesting Microsoft Intune was used to issue remote wipe commands across connected devices. Stryker, which filed an SEC Form 8-K confirming the disruption, has not confirmed the method of compromise or provided a restoration timeline.
Credential theft and phishing operations produced multiple confirmed breaches. Starbucks disclosed that 889 employees had their Partner Central HR accounts compromised via phishing sites impersonating the portal between 19 January and 11 February 2026, exposing Social Security numbers, dates of birth, and financial account details. Storm-2561 continued distributing digitally signed trojanised VPN installers impersonating Cisco, Fortinet, and Ivanti to harvest enterprise credentials via SEO poisoning.
International law enforcement disrupted criminal infrastructure at scale. INTERPOL's Operation Synergia III sinkholed 45,000 malicious IP addresses and arrested 94 individuals across 72 countries in an operation targeting phishing and ransomware infrastructure. Separately, the SocksEscort residential proxy botnet was dismantled by US and European authorities, with 34 domains and 23 servers seized across seven countries and approximately $3.5 million in cryptocurrency frozen.
Highlights of the Day
Google Patches Two Actively Exploited Zero-Days in Chrome 146
Google has released Chrome 146.0.7680.75/76 for Windows, Mac, and Linux, patching two high-severity zero-days confirmed exploited in the wild: CVE-2026-3910, an inappropriate implementation in the V8 JavaScript engine, and CVE-2026-3909, an out-of-bounds write in the Skia graphics library. Both flaws were reported by Google's Threat Analysis Group and had confirmed in-the-wild exploits prior to patching.
Stryker Discloses Cyberattack as Handala Claims Destructive Wiper Operation
US medical technology firm Stryker confirmed in an SEC Form 8-K filing on 11 March 2026 that a cyberattack disrupted its global internal networks and Microsoft systems, leaving employees unable to access corporate devices with no restoration timeline provided. Open-source reporting suggests the attackers may have used Microsoft Intune to issue remote wipe commands across connected devices, with some login pages defaced with threat actor branding prior to the SEC disclosure. Iran-linked threat persona Handala has claimed responsibility, alleging system wipes and data exfiltration linked to recent geopolitical events, though Stryker has not verified these claims or confirmed the method of compromise.
Veeam Patches Five Critical and High Flaws in Backup & Replication
Veeam has released fixes for five vulnerabilities in its Backup & Replication product, including three rated critical, addressing remote code execution, privilege escalation, and credential theft. The most severe, CVE-2026-21669 and CVE-2026-21708 (both CVSS 9.9), allow authenticated attackers with domain user or Backup Viewer access to execute code on the backup server. Veeam Backup & Replication has historically been a target for ransomware groups including Akira and Fog, which have previously extracted sensitive credentials from vulnerable deployments.
GlassWorm Campaign Escalates with 72 Malicious VS Code Extensions
The GlassWorm supply chain campaign has expanded significantly across Open VSX, with 72 malicious extensions identified exploiting VS Code's extensionPack and extensionDependencies manifest fields to distribute malware transitively. The technique allows an initially benign-appearing extension to silently pull a separate GlassWorm-linked package through a later update, meaning extensions that passed initial review can become malicious delivery vehicles without any visible change to their stated purpose. The loader infrastructure has also evolved, rotating Solana wallet addresses and command-and-control IPs, replacing static AES-based obfuscation with RC4/base64/string-array layering, and moving decryption material into HTTP response headers to reduce exposure within the extension itself.
Starbucks Discloses Breach of 889 Employee Accounts via Phishing Sites
Starbucks has notified 889 employees of a data breach after attackers obtained login credentials through phishing sites impersonating the company's Partner Central HR portal, gaining access to accounts between 19 January and 11 February 2026. The compromised accounts exposed sensitive personal data including names, Social Security numbers, dates of birth, and financial account and routing numbers. Starbucks discovered the incident on 6 February, has notified law enforcement, and confirmed the breach has no impact on customer data.
Nine AppArmor Vulnerabilities Allow Unprivileged Linux Users to Gain Root
Qualys has disclosed nine vulnerabilities in AppArmor, the Linux Security Module enabled by default on Ubuntu, Debian, and SUSE, stemming from a confused-deputy flaw that allows unprivileged local users to load, replace, and remove arbitrary security profiles via world-writable pseudo-files. The vulnerabilities — present since kernel version 4.11 (2017) — enable a range of attacks including local privilege escalation to root, kernel stack exhaustion causing system crashes, KASLR bypass via out-of-bounds kernel memory reads, and container namespace breakout. No CVE identifiers have been assigned at the time of publication, as the upstream Linux kernel CVE assignment process issues identifiers one to two weeks after fixes land in stable releases.
Daily Coverage