Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks
Daily Cybersecurity Briefing (23 March 2026)
Published: Loading…
At a Glance
- TeamPCP deployed a Kubernetes wiper targeting Iranian systems using DaemonSets, erasing data while installing CanisterWorm backdoors on non-Iranian hosts.
- Trivy Docker images 0.69.5 and 0.69.6 were compromised with TeamPCP infostealer, including typosquatted C2 domains and exfiltration artifacts, without corresponding GitHub releases.
- Russian intelligence-linked actors conducted phishing campaigns against Signal and WhatsApp accounts to access messages, contacts, and extend attacks through compromised users.
- Oracle patched CVE-2026-21992 in Identity Manager and Web Services Manager, a remotely exploitable RCE flaw with CVSS 9.8 allowing unauthenticated HTTP attacks.
- CISA added five actively exploited vulnerabilities affecting Apple, Craft CMS, and Laravel Livewire to the KEV catalog, requiring federal agencies to patch by 3 April 2026.
- Microsoft Azure Monitor alerts were abused in callback phishing campaigns, sending authentic-looking billing warnings via legitimate Microsoft email headers to target users.
Summary
TeamPCP released a destructive Kubernetes payload targeting Iranian systems while installing the CanisterWorm backdoor on other nodes. The malware spreads via privileged DaemonSets and abuses local network access through SSH key theft and Docker API exploitation. Targeting is determined by system timezone and locale, with persistence disguised as PostgreSQL monitoring services.
Trivy Docker images 0.69.5 and 0.69.6 were compromised with TeamPCP infostealer, containing typosquatted command-and-control domains and exfiltration artifacts. The images were published without corresponding GitHub releases, and exposure of the Aqua Security GitHub organisation may have granted temporary repository access.
Russian intelligence-affiliated actors conducted phishing campaigns against Signal and WhatsApp accounts, accessing messages, contacts, and sending further messages. The attacks targeted high-value individuals, including officials and journalists, without breaking encryption, leveraging social engineering to expand operations.
Oracle released patches for CVE-2026-21992 in Identity Manager and Web Services Manager. The flaw allows remote code execution over HTTP without authentication, affecting multiple product versions and carrying a CVSS score of 9.8, posing a high-risk exposure.
CISA added five actively exploited vulnerabilities impacting Apple products, Craft CMS, and Laravel Livewire to the Known Exploited Vulnerabilities catalog. Federal agencies are required to patch these flaws by 3 April 2026, covering buffer overflow, improper locking, and code injection issues.
Microsoft Azure Monitor alerts were abused in callback phishing campaigns, using legitimate Microsoft email headers to send billing warnings. The messages routed through attacker-controlled mailing lists while appearing authentic, targeting both individual users and corporate accounts.
Highlights of the Day
CISA Adds Five Actively Exploited Flaws to KEV List
CISA has added five vulnerabilities to its Known Exploited Vulnerabilities Catalog after confirming active exploitation, covering Apple products, Craft CMS, and the Laravel Livewire framework. The newly listed issues include buffer overflow, improper locking, and code injection flaws, reflecting continued attacker interest in widely used consumer and web application technologies. CISA said the additions were made under its established process for tracking CVEs that present significant risk to US federal networks.
Oracle Fixes Critical Identity Manager RCE Flaw
Oracle has released patches for CVE-2026-21992, a critical vulnerability in Identity Manager and Web Services Manager that can be exploited remotely without authentication over HTTP. The flaw affects versions 12.2.1.4.0 and 14.1.2.1.0 of both products, and Oracle said successful exploitation could lead to remote code execution and full compromise of vulnerable systems. Oracle has not indicated any known in-the-wild abuse of the issue at the time of disclosure.
Russian Phishing Campaign Hits Encrypted Messaging Accounts
CISA and the FBI have warned that cyber actors linked to Russian intelligence services are running phishing campaigns against commercial messaging application accounts used by officials, journalists, and political figures. The agencies said the activity targets individual user accounts rather than breaking the apps’ encryption, allowing attackers to read messages, access contact lists, send messages, and expand the campaigns through further phishing. The warning follows evidence that thousands of accounts have already been accessed in these global operations.
Azure Monitor Alerts Used in Callback Phishing
Attackers are abusing Microsoft Azure Monitor to send callback phishing emails through the legitimate azure-noreply at microsoft dot com address, making the messages appear authentic and allowing them to pass standard email authentication checks. The campaign uses alert descriptions to insert fake billing warnings and phone numbers, then routes the messages through attacker-controlled mailing lists while preserving Microsoft headers. The emails impersonate account security notices and billing alerts, suggesting a shift towards more convincing lures aimed at both individual users and corporate environments.
TeamPCP Deploys Iran-Focused Kubernetes Wiper
Aikido reports that a new TeamPCP payload uses Kubernetes DaemonSets to spread across clusters, wiping Iranian systems while installing the CanisterWorm backdoor on non-Iranian hosts. The malware identifies targets through timezone and locale settings, then mounts the host filesystem from privileged containers to delete data or establish persistence as disguised PostgreSQL monitoring services. A newer variant also spreads over local networks by stealing SSH keys, parsing authentication logs, and abusing exposed Docker APIs on port 2375.
Trivy Docker Images Compromised with TeamPCP Infostealer
Socket's research team has identified that Trivy Docker images 0.69.5 and 0.69.6, published on 22 March 2026, contain indicators of compromise linked to the TeamPCP infostealer. The images were pushed without corresponding GitHub releases, and analysis confirmed typosquatted C2 domains and exfiltration artifacts embedded within the binaries. The incident also revealed potential exposure of the Aqua Security GitHub organisation, suggesting attackers may have gained temporary internal repository access, while earlier images (≤0.69.3) remain unmodified based on registry timelines.
Daily Coverage