CyberSecBrief

Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks


Daily Cybersecurity Briefing (20 March 2026)

Published: Loading…

At a Glance

  • CISA added SharePoint CVE-2026-20963 to KEV after active exploitation, with unauthenticated deserialization enabling remote code execution on on-premises servers.
  • Interlock exploited a Cisco firewall zero-day since January, while ransomware affiliates increasingly used nearly 90 EDR killers to disable endpoint defences.
  • DarkSword chained six iOS and Safari flaws, including three zero-days, to infect iPhones through drive-by websites in targeted attacks.
  • Quest KACE SMA CVE-2025-32975 enabled administrative takeover, remote command execution, Mimikatz deployment and RDP access to backup and domain systems.
  • APT28 exploited a Zimbra stored XSS flaw against a Ukrainian maritime agency, while Speagle abused Cobra DocGuard servers to conceal espionage data theft.

Summary

SharePoint CVE-2026-20963 entered CISA’s Known Exploited Vulnerabilities catalogue after active exploitation exposed on-premises servers to unauthenticated remote code execution. Ubiquiti UniFi Network Application also patched CVE-2026-22557, a maximum-severity path traversal flaw that could expose system files and enable account hijacking.

Interlock used a Cisco firewall zero-day in ransomware attacks from late January, while affiliate crews deployed nearly 90 active EDR killers to disable security tools before encryption. The Gentlemen also relied on FortiGate CVE-2024-55591, maintained a database of compromised devices and credentials, and used BYOVD techniques during intrusions.

Mobile threats included DarkSword, which chained six iOS and Safari flaws, including three zero-days, for drive-by compromise of iPhones in targeted campaigns. Perseus targeted Android users by monitoring notes apps for passwords, recovery phrases and financial data, while Keenadu remained embedded in Android firmware across nearly 50 device models.

Quest KACE SMA CVE-2025-32975 was exploited for administrative takeover through SSO handling, followed by remote command execution, Mimikatz deployment and RDP access to backup infrastructure. A separate GNU inetutils telnetd flaw, CVE-2026-32746, exposed dozens of platforms to unauthenticated memory corruption through malformed LINEMODE negotiation.

Russian state activity included APT28 exploiting a Zimbra stored XSS flaw to breach a Ukrainian maritime agency. Speagle targeted Cobra DocGuard environments and exfiltrated data through a compromised legitimate server, including searches for documents tied to Chinese ballistic missiles.

Supply-chain and data exposure incidents also widened. The IndonesianFoods npm spam campaign pushed roughly 89,000 junk packages into the registry, while BigQuery Canvas assistant flaws enabled cross-tenant data extraction through hidden Gemini agent instructions, and breaches at Aura, Marquis and Navia exposed large volumes of personal records.

Highlights of the Day

Quest KACE SMA Authentication Bypass Exploited in Active Attacks

CVE-2025-32975, a critical authentication bypass in Quest KACE Systems Management Appliance patched in May 2025, has been observed under active exploitation against publicly exposed, unpatched instances. Attackers achieved administrative takeover via the SSO authentication handling mechanism, then used KACE's KPluginRunProcess functionality to execute remote commands, deployed Mimikatz for credential harvesting, created rogue administrative accounts, and gained RDP access to backup infrastructure including Veeam and Veritas servers and domain controllers. No public proof-of-concept has been identified and three related vulnerabilities patched alongside CVE-2025-32975 — CVE-2025-32976, CVE-2025-32977, and CVE-2025-32978 — were not observed in the same activity.

32-Year-Old Buffer Overflow in GNU Telnetd Affects Dozens of Systems

CVE-2026-32746, a BSS-based buffer overflow in the LINEMODE SLC negotiation handler of GNU inetutils telnetd, has gone undetected since 1994 and affects a wide range of systems including Ubuntu, Debian, FreeBSD, NetBSD, Citrix NetScaler, TrueNAS, and Apple Mac Tahoe, among others. The flaw allows an unauthenticated attacker to corrupt approximately 400 bytes of adjacent memory by sending malformed SLC triplets during Telnet negotiation, with demonstrated primitives including an arbitrary free and heap pointer leak on 32-bit Debian systems — though full remote code execution has not yet been achieved due to per-system memory layout variability. At the time of publication, the upstream inetutils project had not released a fixed version, with only Debian's sid/forky track carrying a patch; all other major distribution packages remain vulnerable.

PureLog Stealer Campaign Uses Copyright Lures and Fileless Execution Against Key Sectors

A targeted campaign distributing PureLog Stealer uses localised copyright violation notices as lures — with language-matched filenames in German and English — to deliver a multi-stage infection chain against healthcare, government, hospitality, and education organisations in Germany, Canada, the United States, and Australia. The chain downloads an encrypted payload disguised as a PDF, retrieves a decryption key dynamically from attacker-controlled infrastructure, extracts the payload using a renamed WinRAR executable, then executes the final stealer via a Python-based loader and two concurrent ConfuserEx-obfuscated .NET loaders — with PureLog Stealer running entirely in memory via Assembly.Load() and never touching disk. The loader incorporates AMSI bypass via AmsiScanBuffer patching, registry persistence under the "SystemSettings" Run key, desktop screenshot capture, AV enumeration via WMI, and victim fingerprinting, with all data exfiltrated over HTTPS to a dedicated C2 server.

Keenadu Firmware Backdoor Found Pre-Installed on Over 500 Android Devices

The Keenadu backdoor, embedded in the libandroid_runtime.so shared library during the firmware build phase as a supply chain compromise, has been detected on over 500 Android devices across nearly 50 models from manufacturers including BLU, DOOGEE, Gigaset, Gionee, Ulefone, and others, with infections spanning 40 countries. Because Keenadu injects itself into the Zygote process — the parent process for all Android applications — it gains persistent access to every app on the device and acts as a downloader for second-stage modules targeting storefronts, browsers, and social media apps, with clicker modules performing silent ad fraud against YouTube, Facebook, and the system launcher. The backdoor is embedded in trojanised versions of the system launcher APKs PriLauncher.apk and PriLauncher3QuickStep.apk, located in system-level directories, making removal without a firmware update effectively impossible.

Source: Sophos

EDR Killers Become Standard Ransomware Tool Across Nearly 90 Active Variants

Analysis of almost 90 EDR killers actively used in ransomware intrusions reveals a mature ecosystem spanning BYOVD-based tools abusing 35 vulnerable drivers, script-based approaches, and a growing class of driverless techniques such as EDRSilencer and EDR-Freeze that block telemetry or suspend EDR processes without touching the kernel. Affiliates — not ransomware operators — select EDR killers, with commercial offerings such as DemoKiller, AbyssKiller, and CardSpaceKiller confirmed in use across multiple RaaS programmes including Qilin, Akira, Medusa, and DragonForce, often packed with services like HeartCrypt and VX Crypt to add obfuscation. Driver-based attribution is identified as misleading, with the same vulnerable driver appearing across unrelated codebases and individual tools switching drivers between deployments — exemplified by CardSpaceKiller migrating from HwRwDrv.sys to ThrottleStop.sys with minimal logic changes.

Source: ESET

The Gentlemen RaaS Emerges From Qilin Dispute, Exploits FortiGate CVE at Scale

The Gentlemen, a ransomware-as-a-service operation of approximately 20 members that evolved from a former Qilin affiliate group called ArmCorp, has attacked around 94 organisations since mid-2025 using CVE-2024-55591 — a critical FortiOS authentication bypass — as its primary initial access vector, maintaining an operational database of approximately 14,700 already-compromised FortiGate devices shared with affiliates alongside 969 validated brute-forced VPN credentials. The group's operator, known as hastalamuerte, openly admitted to developing the ransomware whilst still an active Qilin affiliate, with a hardcoded string in the ransomware binary directly matching a forum post under his handle — an operational security failure that provided forensic proof of authorship. The Gentlemen employs BYOVD techniques using ThrottleBlood.sys and viragt64.sys drivers, a WMI-based domain-wide spread mechanism that recursively deploys the locker across all visible machines, and confirmed use of ChatGPT, Gemini, and Claude AI during ransomware development and operations.

Source: Group-IB

Speagle Infostealer Hijacks Cobra DocGuard Infrastructure to Mask Espionage Activity

A previously undocumented .NET infostealer tracked as Speagle, attributed to an unidentified threat actor designated Runningcrab, targets machines with the Cobra DocGuard document security platform installed and exfiltrates data to a compromised legitimate Cobra DocGuard server — masking the theft as normal client-server communications. The malware conducts phased collection including WMI system enumeration, browser history, autofill data, bookmarks, and file listings from user directories, with one variant containing additional functionality to specifically search for documents related to Chinese ballistic missiles including the Dongfeng-27 and associated technical terminology. The infection vector remains unconfirmed, though the malware's use of a legitimate Cobra DocGuard driver for self-deletion suggests a possible trojanised software update, consistent with two prior supply chain attacks against the same platform.

Source: Symantec

CISA Orders Patch for Actively Exploited Critical SharePoint RCE Flaw

CISA has added CVE-2026-20963, a critical deserialization vulnerability in Microsoft SharePoint, to its Known Exploited Vulnerabilities catalogue and ordered Federal Civilian Executive Branch agencies to patch by 21 March. The flaw, patched in January 2026's Patch Tuesday, allows an unauthenticated attacker to achieve remote code execution on affected servers via a network-based attack with no user interaction required, affecting SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition. Microsoft has not independently confirmed in-the-wild exploitation and CISA has found no evidence of use in ransomware attacks at this stage.

Ubiquiti Patches Maximum-Severity Path Traversal Flaw in UniFi Network App

Ubiquiti has patched two vulnerabilities in the UniFi Network Application, including CVE-2026-22557, a maximum-severity path traversal flaw affecting version 10.1.85 and earlier that allows an unauthenticated network-adjacent attacker to access files on the underlying system and potentially hijack user accounts in low-complexity attacks requiring no user interaction. A second authenticated NoSQL injection vulnerability was also addressed, enabling privilege escalation for attackers with low-level access. Both flaws are resolved in UniFi Network Application version 10.1.89 and later.

BigQuery flaw exposed cross-tenant data through Canvas assistant

Tenable disclosed a high-severity flaw in Google BigQuery’s Canvas assistant that could let an attacker extract data from another tenant by hiding malicious instructions inside a shared Gemini agent. According to the advisory, the issue hinged on how tool execution and session persistence were handled in shared Canvas environments, allowing victim data to be saved server-side even when the attacker saw a failed save message. Google told Tenable it added a warning for end users on 18 March 2026.

Source: Tenable

Daily Coverage

Developments
Sharepoint KevInterlock Zero-DayDarksword ExploitsKace Takeover
Vulnerabilities
CVE-2026-20131CVE-2026-3564Screenconnect All Versions Prior To 26.1 (Critical)CVE-2025-68613N8N >= 0.211.0, < 1.120.4 (Critical)CVE-2026-21858N8N < 1.121.0 (Critical)CVE-2026-33307CVE-2026-33017Langflow < 1.9.0 (Critical)CVE-2026-21992Oracle Identity Manager 12.2.1.4.0 (Critical)CVE-2026-20963Microsoft Sharepoint Enterprise Server 2016 16.0.0 (High)CVE-2026-32746Inetutils (Critical)CVE-2025-32977
Threat Groups
APT28APT28 is a threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) 85th Main Special Service Center (GTsSS) military unit 26165. This group has been active since at least 2004. APT28 reportedly compromised the Hillary Clinton campaign, the Democratic National Committee, and the Democratic Congressional Campaign Committee in 2016 in an attempt to interfere with the U. S. presidential election. In 2018, the US indicted five GRU Unit 26165 officers associated with APT28 for cyber operations (including closeaccess operations) conducted between 2014 and 2018 against the World AntiDoping Agency (WADA), the US AntiDoping Agency, a US nuclear facility, the Organization for the Prohibition of Chemical Weapons (OPCW), the Spiez Swiss Chemicals Laboratory, and other organizations. Some of these were conducted with the assistance of GRU Unit 74455, which is also referred to as Sandworm Team.AkiraAkira is a ransomware variant and ransomware deployment entity active since at least March 2023. Akira uses compromised credentials to access singlefactor external access mechanisms such as VPNs for initial access, then various publiclyavailable tools and techniques for lateral movement. Akira operations are associated with "double extortion" ransomware activity, where data is exfiltrated from victim environments prior to encryption, with threats to publish files if a ransom is not paid. Technical analysis of Akira ransomware indicates variants capable of targeting Windows or VMWare ESXi hypervisors and multiple overlaps with Conti ransomware.