Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks
Daily Cybersecurity Briefing (18 March 2026)
Published: Loading…
At a Glance
- Konni APT hijacked KakaoTalk PC sessions on infected systems to redistribute malicious LNK files to victim contacts, deploying EndRAT, RftRAT, and RemcosRAT.
- LSPosed module 'Digital Lutera' bypasses SIM-binding in Indian mobile payment apps by hooking TelephonyManager APIs and fabricating SMS database entries.
- Vidar Stealer 2.0, rewritten in C with polymorphic builds, is spreading via hundreds of fake GitHub game cheat repositories following Lummastealer's disruption.
- 28.65 million hardcoded secrets were added to public GitHub in 2025, a 34% increase, with AI service leaks up 81% and 64% of 2022 credentials still valid.
- LeakNet ransomware adopted ClickFix via compromised websites for initial access, deploying a Deno runtime-based in-memory JavaScript loader.
- The EU sanctioned a Chinese company and Iranian firm Emennet Pasargad for cyberattacks including a 65,000-device hack and election interference operations.
Summary
The Konni APT group conducted a multi-stage campaign using spear-phishing to install EndRAT via a malicious LNK file, then gained unauthorised access to the infected victim's KakaoTalk PC application to redistribute malicious files to selected contacts disguised as North Korea-related video materials. The campaign deployed three RAT families — EndRAT, RftRAT, and RemcosRAT — via AutoIt scripts communicating with C2 infrastructure across Finland, Japan, and the Netherlands. A separate LSPosed-based Android attack, attributed to a threat actor known as "Berlin," weaponised the Digital Lutera module to bypass SIM-binding in Indian mobile payment applications by hooking TelephonyManager APIs, fabricating SMS database entries, and routing exfiltrated OTPs to Telegram channels.
Developer tooling and AI environments faced multiple concurrent attack vectors. CursorJack demonstrated that Cursor IDE's Model Context Protocol deeplink installation flow can be abused via social engineering to execute attacker-controlled commands at user-level privileges, with Cursor having closed the report as out-of-scope. Hidden instructions in repository README files were separately confirmed to trigger AI coding agents into leaking sensitive local files through semantic injection, and a new font-rendering technique was identified that conceals malicious HTML commands from AI assistants.
28.65 million hardcoded secrets were added to public GitHub commits — a 34% year-on-year increase — with AI service leaks up 81% and 64% of credentials confirmed valid in 2022 still exploitable as of January 2026. The GlassWorm campaign separately expanded to hit over 400 code repositories, packages, and extensions across GitHub, npm, VSCode, and OpenVSX in a coordinated wave.
Vidar Stealer 2.0, rewritten from C++ to C with polymorphic builds and multithreaded execution, is being distributed via hundreds of fake GitHub repositories and Reddit posts advertising game cheats, filling demand left by Lummastealer's law enforcement disruption. The malware hides C2 infrastructure behind Telegram bots and Steam profiles and targets browser credentials, Azure tokens, cryptocurrency wallets, FTP and SSH credentials, and Discord session data. LeakNet ransomware separately adopted ClickFix social engineering via compromised websites for initial access, deploying a Deno runtime-based in-memory JavaScript loader to evade detection.
CISA added CVE-2025-47813, a Wing FTP Server path disclosure flaw, to its Known Exploited Vulnerabilities catalogue with a 30 March remediation deadline, noting it can be chained with the critical RCE vulnerability CVE-2025-47812 patched in the same release. Two critical flaws in Delta Electronics COMMGR version 2.11.0 — CVE-2026-3630 (CVSS 9.8, stack-based buffer overflow) and CVE-2026-3631 (CVSS 7.5, buffer over-read DoS) — were also disclosed, both exploitable via specially crafted network messages without authentication.
The EU Council sanctioned a Chinese company behind a 65,000-device hack and Iranian front company Emennet Pasargad for election interference operations and the Charlie Hebdo breach, applying asset freezes and travel bans. Medusa ransomware separately claimed an attack that knocked out systems at the largest hospital in Mississippi for nine days, adding to a series of healthcare sector incidents attributed to the group.
Highlights of the Day
Cursor IDE MCP Deeplinks Abused to Execute Malicious Code on Developer Machines
A proof-of-concept attack dubbed CursorJack demonstrates that Cursor IDE's Model Context Protocol deeplink installation flow can be abused via social engineering to achieve arbitrary code execution on developer workstations. A single click on a crafted phishing link followed by user acceptance of an install prompt can trigger a malicious MCP configuration that executes attacker-controlled commands with the IDE's user-level privileges, in one demonstrated path establishing a full Meterpreter reverse shell. Cursor was notified prior to publication but closed the report as out-of-scope; no visual distinction exists in the default UI between a legitimate and malicious MCP install deeplink.
CISA Adds Wing FTP Path Disclosure Flaw to Exploited Vulnerabilities List
CISA has added CVE-2025-47813, a medium-severity path disclosure vulnerability in Wing FTP Server, to its Known Exploited Vulnerabilities catalogue, ordering federal agencies to patch by 30 March. The flaw, present in Wing FTP versions prior to 7.4.4, allows an attacker to retrieve the server's full local installation path by supplying an overlong value in the UID cookie of the loginok.html endpoint. The disclosed path can be used to chain exploitation with CVE-2025-47812, a critical remote code execution vulnerability in the same product that was itself added to the KEV catalogue in July 2025.
Konni APT Hijacks KakaoTalk Sessions to Spread Malware via Victim Contact Lists
The Konni APT group conducted a multi-stage intrusion campaign beginning with a spear-phishing email disguised as a North Korean human rights lecturer appointment notice, delivering a malicious LNK file that installed EndRAT remote access malware and established minute-interval persistence via a scheduled task. After maintaining long-term concealed access to the victim's system, the threat actor gained unauthorised access to the installed KakaoTalk PC application and used the victim's contact list to redistribute malicious files — disguised as North Korea-related video planning materials — to selected contacts. The campaign deployed three distinct RAT families (EndRAT, RftRAT, and RemcosRAT) via AutoIt scripts communicating with C2 infrastructure across Finland, Japan, and the Netherlands, with the Japan-based server linking the operation to earlier documented Konni infrastructure.
LSPosed Framework Weaponised to Bypass SIM Binding in Indian Payment Apps
A threat actor operating under the alias "Berlin" has weaponised the LSPosed Android hooking framework to bypass SIM-binding security in India's mobile payment ecosystem, deploying a module called "Digital Lutera" that hooks system-level APIs to intercept outgoing registration SMS messages, spoof device phone numbers, and fabricate sent-message database entries to deceive bank servers. Because LSPosed operates at runtime without modifying the payment application itself, the app's digital signature remains valid, bypassing Google Play Protect and standard APK integrity checks. The module communicates with a Socket.IO-based command-and-control server to enable real-time fraud orchestration, with exfiltrated tokens and OTPs forwarded to attacker-controlled Telegram channels — with one group's channel already logging over 500 successful login interceptions.
29 Million Secrets Leaked on Public GitHub in 2025 as AI Coding Accelerates Sprawl
GitGuardian's State of Secrets Sprawl 2026 report found 28.65 million new hardcoded secrets added to public GitHub commits in 2025 — a 34% year-on-year increase and the largest single-year jump recorded — with AI service secrets reaching 1.275 million, up 81%, including 113,000 leaked DeepSeek API keys. Eight of the ten fastest-growing leak categories were tied to AI services, with LLM infrastructure components such as orchestration, RAG, and vector storage leaking five times faster than core model providers. A separate analysis of 6,943 compromised developer machines found 294,842 secret occurrences, with 59% of those machines identified as CI/CD runners rather than personal workstations, and 64% of credentials confirmed valid in 2022 remaining active and exploitable as of January 2026.
Vidar Stealer 2.0 Spreads via Hundreds of Fake Game Cheat Repositories
Hundreds of fake GitHub repositories and Reddit posts have been identified distributing Vidar Stealer 2.0 under the guise of free game cheats for titles including CS2, with the campaign exploiting the post-Lummastealer enforcement vacuum — Vidar detections have surged sharply as Lumma and Rhadamanthys activity declined. The new version represents a full rewrite from C++ to C with polymorphic builds, multithreaded execution, and advanced anti-analysis techniques including debugger detection, timing checks, and RAM-based VM detection, whilst concealing C2 infrastructure behind Telegram bots and Steam profiles as dead drop resolvers. Vidar 2.0 targets browser credentials, Azure tokens, Monero wallets, cryptocurrency browser extensions, FTP and SSH credentials, Telegram and Discord session data, and arbitrary files — completing exfiltration before victims are typically aware of compromise.
Daily Coverage