CyberSecBrief

Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks


Daily Cybersecurity Briefing (14 March 2026)

Published: Loading…

At a Glance

  • Nine CrackArmor vulnerabilities in Linux AppArmor allow unprivileged users to escalate to root, crash systems, and break container isolation on Ubuntu, Debian, and SUSE.
  • Google patched two actively exploited Chrome zero-days, CVE-2026-3909 in Skia and CVE-2026-3910 in V8, both confirmed exploited in the wild before patching.
  • Veeam released fixes for five Backup & Replication vulnerabilities, including CVE-2026-21669 and CVE-2026-21708, both CVSS 9.9, enabling authenticated RCE.
  • GlassWorm expanded its Open VSX campaign to 72 malicious extensions, abusing extensionPack and extensionDependencies to distribute malware through transitive dependencies.
  • INTERPOL's Operation Synergia III dismantled 45,000 malicious IP addresses and arrested 94 individuals across 72 countries targeting phishing and ransomware infrastructure.
  • Starbucks disclosed a breach of 889 employee Partner Central accounts exposing Social Security numbers, dates of birth, and financial account details via credential phishing.

Summary

Multiple critical vulnerabilities across widely deployed software created significant patching pressure. Veeam Backup & Replication received fixes for five flaws including CVE-2026-21669 and CVE-2026-21708, both rated CVSS 9.9. Nine CrackArmor vulnerabilities in the Linux AppArmor module, present since kernel version 4.11, allow unprivileged local users to escalate to root, exhaust kernel stacks, bypass KASLR, and break container isolation on Ubuntu, Debian, and SUSE systems.

Google patched two high-severity Chrome zero-days under active exploitation: CVE-2026-3909, an out-of-bounds write in the Skia graphics library, and CVE-2026-3910, an inappropriate implementation in the V8 JavaScript engine, both confirmed exploited in the wild before patches landed in Chrome 146.0.7680.75/76.

Supply chain threats expanded across developer tooling ecosystems. The GlassWorm campaign escalated to 72 malicious Open VSX extensions, abusing extensionPack and extensionDependencies manifest fields to deliver malware transitively through later updates, with loader infrastructure rotating Solana wallet addresses and shifting decryption material into HTTP response headers. Separately, invisible Unicode character injections linked to the same campaign were identified across more than 150 GitHub repositories as well as npm packages.

Iran-linked Handala conducted a destructive attack against Stryker, disrupting its global Microsoft environment with evidence suggesting Microsoft Intune was used to issue remote wipe commands across connected devices. Stryker, which filed an SEC Form 8-K confirming the disruption, has not confirmed the method of compromise or provided a restoration timeline.

Credential theft and phishing operations produced multiple confirmed breaches. Starbucks disclosed that 889 employees had their Partner Central HR accounts compromised via phishing sites impersonating the portal between 19 January and 11 February 2026, exposing Social Security numbers, dates of birth, and financial account details. Storm-2561 continued distributing digitally signed trojanised VPN installers impersonating Cisco, Fortinet, and Ivanti to harvest enterprise credentials via SEO poisoning.

International law enforcement disrupted criminal infrastructure at scale. INTERPOL's Operation Synergia III sinkholed 45,000 malicious IP addresses and arrested 94 individuals across 72 countries in an operation targeting phishing and ransomware infrastructure. Separately, the SocksEscort residential proxy botnet was dismantled by US and European authorities, with 34 domains and 23 servers seized across seven countries and approximately $3.5 million in cryptocurrency frozen.

Highlights of the Day

Google Patches Two Actively Exploited Zero-Days in Chrome 146

Google has released Chrome 146.0.7680.75/76 for Windows, Mac, and Linux, patching two high-severity zero-days confirmed exploited in the wild: CVE-2026-3910, an inappropriate implementation in the V8 JavaScript engine, and CVE-2026-3909, an out-of-bounds write in the Skia graphics library. Both flaws were reported by Google's Threat Analysis Group and had confirmed in-the-wild exploits prior to patching.

Stryker Discloses Cyberattack as Handala Claims Destructive Wiper Operation

US medical technology firm Stryker confirmed in an SEC Form 8-K filing on 11 March 2026 that a cyberattack disrupted its global internal networks and Microsoft systems, leaving employees unable to access corporate devices with no restoration timeline provided. Open-source reporting suggests the attackers may have used Microsoft Intune to issue remote wipe commands across connected devices, with some login pages defaced with threat actor branding prior to the SEC disclosure. Iran-linked threat persona Handala has claimed responsibility, alleging system wipes and data exfiltration linked to recent geopolitical events, though Stryker has not verified these claims or confirmed the method of compromise.

Veeam Patches Five Critical and High Flaws in Backup & Replication

Veeam has released fixes for five vulnerabilities in its Backup & Replication product, including three rated critical, addressing remote code execution, privilege escalation, and credential theft. The most severe, CVE-2026-21669 and CVE-2026-21708 (both CVSS 9.9), allow authenticated attackers with domain user or Backup Viewer access to execute code on the backup server. Veeam Backup & Replication has historically been a target for ransomware groups including Akira and Fog, which have previously extracted sensitive credentials from vulnerable deployments.

GlassWorm Campaign Escalates with 72 Malicious VS Code Extensions

The GlassWorm supply chain campaign has expanded significantly across Open VSX, with 72 malicious extensions identified exploiting VS Code's extensionPack and extensionDependencies manifest fields to distribute malware transitively. The technique allows an initially benign-appearing extension to silently pull a separate GlassWorm-linked package through a later update, meaning extensions that passed initial review can become malicious delivery vehicles without any visible change to their stated purpose. The loader infrastructure has also evolved, rotating Solana wallet addresses and command-and-control IPs, replacing static AES-based obfuscation with RC4/base64/string-array layering, and moving decryption material into HTTP response headers to reduce exposure within the extension itself.

Source: Socket

Starbucks Discloses Breach of 889 Employee Accounts via Phishing Sites

Starbucks has notified 889 employees of a data breach after attackers obtained login credentials through phishing sites impersonating the company's Partner Central HR portal, gaining access to accounts between 19 January and 11 February 2026. The compromised accounts exposed sensitive personal data including names, Social Security numbers, dates of birth, and financial account and routing numbers. Starbucks discovered the incident on 6 February, has notified law enforcement, and confirmed the breach has no impact on customer data.

Nine AppArmor Vulnerabilities Allow Unprivileged Linux Users to Gain Root

Qualys has disclosed nine vulnerabilities in AppArmor, the Linux Security Module enabled by default on Ubuntu, Debian, and SUSE, stemming from a confused-deputy flaw that allows unprivileged local users to load, replace, and remove arbitrary security profiles via world-writable pseudo-files. The vulnerabilities — present since kernel version 4.11 (2017) — enable a range of attacks including local privilege escalation to root, kernel stack exhaustion causing system crashes, KASLR bypass via out-of-bounds kernel memory reads, and container namespace breakout. No CVE identifiers have been assigned at the time of publication, as the upstream Linux kernel CVE assignment process issues identifiers one to two weeks after fixes land in stable releases.

Source: Qualys

Daily Coverage

Developments
Crackarmor Apparmor FlawsChrome Zero-Days PatchedVeeam Rce VulnerabilitiesGlassworm Vsx Escalation
Vulnerabilities
CVE-2026-3909CVE-2026-3910CVE-2026-21708CVE-2026-21669
Threat Groups
AkiraAkira is a ransomware variant and ransomware deployment entity active since at least March 2023. Akira uses compromised credentials to access singlefactor external access mechanisms such as VPNs for initial access, then various publiclyavailable tools and techniques for lateral movement. Akira operations are associated with "double extortion" ransomware activity, where data is exfiltrated from victim environments prior to encryption, with threats to publish files if a ransom is not paid. Technical analysis of Akira ransomware indicates variants capable of targeting Windows or VMWare ESXi hypervisors and multiple overlaps with Conti ransomware.