Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks
Daily Cybersecurity Briefing (19 March 2026)
Published: Loading…
At a Glance
- DarkSword, a six-vulnerability iOS exploit chain, has been used by UNC6748, PARS Defense, and Russian group UNC6353 against targets in four countries since November 2025.
- Interlock ransomware exploited CVE-2026-20131, a CVSS 10.0 deserialization flaw in Cisco Secure Firewall Management Center, as a zero-day since late January 2026.
- GlassWorm sleeper extensions on Open VSX activated on 18 March, shifting payload delivery to GitHub-hosted VSIX files outside registry takedown reach.
- The GlassWorm-linked npm account hijack buried malware three dependency layers deep across two packages with 134,000 combined monthly downloads.
- CVE-2026-32746, a CVSS 9.8 out-of-bounds write in GNU InetUtils telnetd, allows unauthenticated remote attackers to execute code as root via port 23.
- Marquis, a US bank software vendor, confirmed a ransomware attack exposed data of 672,000 individuals across 74 financial institutions in August 2025.
Summary
The DarkSword iOS exploit chain, leveraging six vulnerabilities including four zero-days, has been deployed by at least three distinct actors — UNC6748, Turkish commercial surveillance vendor PARS Defense, and suspected Russian espionage group UNC6353 — against targets in Saudi Arabia, Turkey, Malaysia, and Ukraine since November 2025. The chain supports iOS 18.4 through 18.7 and deploys three malware families: GHOSTKNIFE, GHOSTSABER, and GHOSTBLADE, with all six vulnerabilities now patched across iOS 18.7.2, 18.7.3, and 26.x. Apple separately issued its first Background Security Improvements update to patch CVE-2026-20643, a WebKit cross-origin flaw in the Navigation API that could allow same-origin policy bypass on iOS, iPadOS, and macOS.
GlassWorm expanded its supply chain campaign on two simultaneous fronts on 18 March. On Open VSX, previously dormant sleeper extensions were activated as extension pack droppers, with at least one (lauracode.wrap-selected-code) updated to force-install a malicious VSIX sourced directly from throwaway GitHub accounts — bypassing registry-level takedowns entirely. Separately, the npm account behind two React Native packages with 134,000 combined monthly downloads was fully hijacked across three attack waves, with the attacker ultimately burying the GlassWorm-attributed Solana blockchain C2 payload two transitive dependency layers deep and pinning versions to "latest" for dynamic payload rotation.
Three critical vulnerabilities affecting widely deployed infrastructure components required patching. Interlock ransomware exploited CVE-2026-20131 (CVSS 10.0), an insecure Java deserialization flaw in Cisco Secure Firewall Management Center, as a zero-day since late January 2026 — over a month before Cisco issued a patch. A separate critical flaw, CVE-2026-32746 (CVSS 9.8), affecting the GNU InetUtils telnet daemon allows unauthenticated remote code execution as root via port 23, with no patch available at time of disclosure. CISA separately ordered federal agencies to patch an actively exploited cross-site scripting vulnerability in Zimbra Collaboration Suite.
Financial and personal data were exposed in multiple confirmed breach disclosures. Texas-based bank software provider Marquis confirmed a ransomware attack in August 2025 that exposed data belonging to 672,000 individuals across 74 US financial institutions. Identity protection firm Aura separately confirmed an unauthorised party accessed nearly 900,000 customer records containing names and email addresses.
Phishing campaigns exploited seasonal and developer community trust signals across multiple regions. A Horabot campaign compromised over 5,000 victims — 93% in Mexico — via fake CAPTCHA ClickFix lures delivering a Delphi banking trojan with an email spreader that mass-distributes malicious PDF attachments to harvested contacts. A separate campaign targeting OpenClaw developers used GitHub issue threads tagging users with fake $5,000 CLAW token giveaways, directing them to a cloned site that drained connected cryptocurrency wallets. A Ramadan-themed campaign in the Middle East used fake discount coupons impersonating AlCoupon to deploy the Ftu4You RAT, routing exfiltration through AWS S3 presigned URLs.
CVE-2026-3888 (CVSS 7.8) in Ubuntu Desktop 24.04 and later allows an unprivileged local attacker to escalate to root by exploiting a timing interaction between snap-confine and systemd-tmpfiles, requiring a 10 to 30-day wait for cleanup cycles before the attack can proceed. Nine vulnerabilities across four IP KVM device vendors — GL-iNet Comet, Angeet/Yeeso, Sipeed NanoKVM, and JetKVM — separately allow unauthenticated root access to compromised hosts. North Korea's Lazarus group accessed 18,500 purchase records from crypto e-commerce platform Bitrefill, including email addresses, crypto payment addresses, and IP metadata.
Highlights of the Day
DarkSword iOS Exploit Chain Deployed by Multiple Threat Actors Across Four Countries
A new iOS full-chain exploit kit called DarkSword, exploiting six vulnerabilities including four zero-days, has been used by at least three distinct threat actors — UNC6748, Turkish commercial surveillance vendor PARS Defense, and suspected Russian espionage group UNC6353 — to target users in Saudi Arabia, Turkey, Malaysia, and Ukraine since November 2025. The chain supports iOS 18.4 through 18.7 and deploys three distinct malware families: GHOSTKNIFE (a JavaScript backdoor with audio recording and screenshot capabilities), GHOSTSABER (a modular backdoor supporting arbitrary SQL queries and file exfiltration), and GHOSTBLADE (a dataminer collecting iMessage, WhatsApp, location history, keychain data, and cryptocurrency wallet contents). All six vulnerabilities were reported to Apple and patched across iOS 18.7.2, 18.7.3, and 26.x releases, with the final zero-day CVE-2026-20700 — a PAC bypass in dyld — addressed in iOS 26.3.
Ubuntu Snap Flaw Allows Unprivileged Users to Escalate to Root
CVE-2026-3888, a local privilege escalation vulnerability rated CVSS 7.8, affects default installations of Ubuntu Desktop 24.04 and later, exploiting an unintended interaction between snap-confine and systemd-tmpfiles. An unprivileged attacker must wait for systemd-tmpfiles to delete the /tmp/.snap directory — after 10 days on newer Ubuntu versions and 30 days on 24.04 — then recreate it with malicious content, which snap-confine subsequently bind-mounts as root during the next sandbox initialisation. Patched versions are available across Ubuntu 24.04, 25.10, and 26.04, as well as upstream snapd 2.75; a separate race condition in the uutils coreutils rm utility on Ubuntu 25.10 was separately identified and mitigated prior to that release by reverting to GNU coreutils.
Ramadan-Themed Malware Campaign Targets Middle East Retail Customers
A malware campaign is targeting Windows users in the Middle East through fake Ramadan discount coupons impersonating AlCoupon, a well-known Egyptian coupon platform, with lures referencing major retailers including Carrefour, Hyper One, and Metro. A hidden VBA macro within the malicious document silently drops and compiles a C# loader, which fetches a raw MSIL assembly from a delivery server, compiles it on-device, and executes it via rundll32 to deploy a full-featured RAT operating under the namespace Ftu4You. The RAT supports persistent remote shell access, screenshot capture, filesystem browsing, and bidirectional file transfer, routing all exfiltration through AWS S3 presigned URLs to evade network-layer detection and domain-based DLP controls.
Horabot Banking Trojan Campaign Targets Mexico via ClickFix and Email Spreader
An active Horabot campaign has compromised over 5,000 victims — 93% in Mexico — using a fake CAPTCHA ClickFix lure that executes a multi-stage chain involving server-side polymorphic VBScripts, an AutoIt loader, and a Delphi banking trojan identified as Casbaneiro. The Delphi payload communicates with C2 infrastructure via both HTTPS and a custom socket protocol using a stateful XOR cipher, displays fake bank credential overlays, and falls back to a hardcoded secondary C2 at lifenews[.]pro:49569 if primary configuration retrieval fails. A PowerShell-based email spreader harvests victim contacts via the MAPI namespace and mass-distributes Spanish-language phishing emails with malicious PDF attachments to propagate the infection chain further.
Fake OpenClaw Token Giveaway on GitHub Used to Drain Crypto Wallets
A phishing campaign is targeting OpenClaw developers on GitHub by opening issue threads in attacker-controlled repositories and tagging users with claims they have won $5,000 worth of CLAW tokens. The linked site is a near-identical clone of openclaw.ai with a wallet connection prompt added, supporting MetaMask, WalletConnect, Trust Wallet, OKX Wallet, and Bybit Wallet, with connected wallets drained via obfuscated JavaScript that transmits wallet addresses and transaction values to a C2 server at watery-compost[.]today. The attacker accounts were created approximately one week before the campaign launched and were deleted within hours of it beginning; no confirmed victim losses have been reported at time of publication.
GlassWorm-Linked Attack Hijacks npm Account to Deliver Three Waves of Malware
The npm account behind react-native-international-phone-number (92,000 monthly downloads) and react-native-country-select (42,000 monthly downloads) was fully hijacked across three attack waves between 16 and 18 March 2026, with the attacker ultimately changing the account email to a Proton Mail address to lock out the legitimate maintainer. The GlassWorm-attributed payload uses the Solana blockchain as a censorship-resistant command-and-control channel, querying a hardcoded wallet address across nine legitimate public RPC endpoints to retrieve AES-256-encrypted stage-2 payloads executed entirely in memory via eval() or vm.Script. By Wave 3, the parent packages contained no malicious code or install hooks — the malware was buried two transitive dependency layers deep via attacker-controlled scoped packages pinned to "latest", enabling dynamic payload rotation without publishing new parent versions.
GlassWorm Campaign Escalates With GitHub-Hosted VSIX Payloads and Sleeper Extensions
The GlassWorm supply chain campaign expanded significantly on 18 March 2026, with previously dormant Open VSX extensions activated as extension pack droppers and at least one sleeper extension (lauracode.wrap-selected-code) updated to download and force-install a malicious VSIX directly from throwaway GitHub accounts, bypassing the Eclipse Foundation's registry takedown capability entirely. The delivered VSIX is a trojanised clone of the legitimate Auto Import extension, with 623 lines of obfuscated malware injected into the compiled extension.js between the activate() function signature and the legitimate code — invisible to source-level review. The payload follows the established GlassWorm pattern: a 10-second activation delay, Russian locale geofencing across 13 timezone checks, Solana blockchain C2 via the same hardcoded wallet address (6YGcuyFRJKZtcaYCCFba9fScNUvPkGXodXE1mJiSzqDJ), and in-memory execution of an AES-256-encrypted stage-2 payload via eval() or vm.Script.
Daily Coverage