CyberSecBrief

Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks


Daily Cybersecurity Briefing (23 March 2026)

Published: Loading…

At a Glance

  • TeamPCP deployed a Kubernetes wiper targeting Iranian systems using DaemonSets, erasing data while installing CanisterWorm backdoors on non-Iranian hosts.
  • Trivy Docker images 0.69.5 and 0.69.6 were compromised with TeamPCP infostealer, including typosquatted C2 domains and exfiltration artifacts, without corresponding GitHub releases.
  • Russian intelligence-linked actors conducted phishing campaigns against Signal and WhatsApp accounts to access messages, contacts, and extend attacks through compromised users.
  • Oracle patched CVE-2026-21992 in Identity Manager and Web Services Manager, a remotely exploitable RCE flaw with CVSS 9.8 allowing unauthenticated HTTP attacks.
  • CISA added five actively exploited vulnerabilities affecting Apple, Craft CMS, and Laravel Livewire to the KEV catalog, requiring federal agencies to patch by 3 April 2026.
  • Microsoft Azure Monitor alerts were abused in callback phishing campaigns, sending authentic-looking billing warnings via legitimate Microsoft email headers to target users.

Summary

TeamPCP released a destructive Kubernetes payload targeting Iranian systems while installing the CanisterWorm backdoor on other nodes. The malware spreads via privileged DaemonSets and abuses local network access through SSH key theft and Docker API exploitation. Targeting is determined by system timezone and locale, with persistence disguised as PostgreSQL monitoring services.

Trivy Docker images 0.69.5 and 0.69.6 were compromised with TeamPCP infostealer, containing typosquatted command-and-control domains and exfiltration artifacts. The images were published without corresponding GitHub releases, and exposure of the Aqua Security GitHub organisation may have granted temporary repository access.

Russian intelligence-affiliated actors conducted phishing campaigns against Signal and WhatsApp accounts, accessing messages, contacts, and sending further messages. The attacks targeted high-value individuals, including officials and journalists, without breaking encryption, leveraging social engineering to expand operations.

Oracle released patches for CVE-2026-21992 in Identity Manager and Web Services Manager. The flaw allows remote code execution over HTTP without authentication, affecting multiple product versions and carrying a CVSS score of 9.8, posing a high-risk exposure.

CISA added five actively exploited vulnerabilities impacting Apple products, Craft CMS, and Laravel Livewire to the Known Exploited Vulnerabilities catalog. Federal agencies are required to patch these flaws by 3 April 2026, covering buffer overflow, improper locking, and code injection issues.

Microsoft Azure Monitor alerts were abused in callback phishing campaigns, using legitimate Microsoft email headers to send billing warnings. The messages routed through attacker-controlled mailing lists while appearing authentic, targeting both individual users and corporate accounts.

Highlights of the Day

CISA Adds Five Actively Exploited Flaws to KEV List

CISA has added five vulnerabilities to its Known Exploited Vulnerabilities Catalog after confirming active exploitation, covering Apple products, Craft CMS, and the Laravel Livewire framework. The newly listed issues include buffer overflow, improper locking, and code injection flaws, reflecting continued attacker interest in widely used consumer and web application technologies. CISA said the additions were made under its established process for tracking CVEs that present significant risk to US federal networks.

Oracle Fixes Critical Identity Manager RCE Flaw

Oracle has released patches for CVE-2026-21992, a critical vulnerability in Identity Manager and Web Services Manager that can be exploited remotely without authentication over HTTP. The flaw affects versions 12.2.1.4.0 and 14.1.2.1.0 of both products, and Oracle said successful exploitation could lead to remote code execution and full compromise of vulnerable systems. Oracle has not indicated any known in-the-wild abuse of the issue at the time of disclosure.

Russian Phishing Campaign Hits Encrypted Messaging Accounts

CISA and the FBI have warned that cyber actors linked to Russian intelligence services are running phishing campaigns against commercial messaging application accounts used by officials, journalists, and political figures. The agencies said the activity targets individual user accounts rather than breaking the apps’ encryption, allowing attackers to read messages, access contact lists, send messages, and expand the campaigns through further phishing. The warning follows evidence that thousands of accounts have already been accessed in these global operations.

Azure Monitor Alerts Used in Callback Phishing

Attackers are abusing Microsoft Azure Monitor to send callback phishing emails through the legitimate azure-noreply at microsoft dot com address, making the messages appear authentic and allowing them to pass standard email authentication checks. The campaign uses alert descriptions to insert fake billing warnings and phone numbers, then routes the messages through attacker-controlled mailing lists while preserving Microsoft headers. The emails impersonate account security notices and billing alerts, suggesting a shift towards more convincing lures aimed at both individual users and corporate environments.

TeamPCP Deploys Iran-Focused Kubernetes Wiper

Aikido reports that a new TeamPCP payload uses Kubernetes DaemonSets to spread across clusters, wiping Iranian systems while installing the CanisterWorm backdoor on non-Iranian hosts. The malware identifies targets through timezone and locale settings, then mounts the host filesystem from privileged containers to delete data or establish persistence as disguised PostgreSQL monitoring services. A newer variant also spreads over local networks by stealing SSH keys, parsing authentication logs, and abusing exposed Docker APIs on port 2375.

Trivy Docker Images Compromised with TeamPCP Infostealer

Socket's research team has identified that Trivy Docker images 0.69.5 and 0.69.6, published on 22 March 2026, contain indicators of compromise linked to the TeamPCP infostealer. The images were pushed without corresponding GitHub releases, and analysis confirmed typosquatted C2 domains and exfiltration artifacts embedded within the binaries. The incident also revealed potential exposure of the Aqua Security GitHub organisation, suggesting attackers may have gained temporary internal repository access, while earlier images (≤0.69.3) remain unmodified based on registry timelines.

Source: Socket

Daily Coverage

Developments
Teampcp Kubernetes WiperTrivy Supply-ChainRussian Messaging PhishingOracle Identity Manager Rce
Vulnerabilities
CVE-2026-21992Oracle Identity Manager 12.2.1.4.0 (Critical)CVE-2025-32975CVE-2026-20131CVE-2026-25769Wazuh >= 4.0.0, < 4.14.3 (Critical)CVE-2026-33017Langflow < 1.9.0 (Critical)CVE-2025-14233Satera Lbp670C Series 06.02 And Earlier (Critical)CVE-2025-58487Account 15.5.01.1 (Medium)CVE-2025-58486Account 15.5.01.1 (Medium)CVE-2025-58488Smart_Touch_Call 1.0.1.1 (Medium)
Threat Groups
PlayPlay is a ransomware group that has been active since at least 2022 deploying Playcrypt ransomware against the business, government, critical infrastructure, healthcare, and media sectors in North America, South America, and Europe. Play actors employ a doubleextortion model, encrypting systems after exfiltrating data, and are presumed by security researchers to operate as a closed group.Contagious InterviewContagious Interview is a North Korea–aligned threat group active since 2023. The group conducts both cyberespionage and financially motivated operations, including the theft of cryptocurrency and user credentials. Contagious Interview targets Windows, Linux, and macOS systems, with a particular focus on individuals engaged in software development and cryptocurrencyrelated activities.SILICONSea Turtle is a Türkiyelinked threat actor active since at least 2017 performing espionage and service provider compromise operations against victims in Asia, Europe, and North America. Sea Turtle is notable for targeting registrars managing ccTLDs and complex DNSbased intrusions where the threat actor compromised DNS providers to hijack DNS resolution for ultimate victims, enabling Sea Turtle to spoof log in portals and other applications for credential collection.NICKELKe3chang is a threat group attributed to actors operating out of China. Ke3chang has targeted oil, government, diplomatic, military, and NGOs in Central and South America, the Caribbean, Europe, and North America since at least 2010.Scattered SpiderScattered Spider is a native Englishspeaking cybercriminal group active since at least 2022. The group initially targeted customer relationship management (CRM) providers, business process outsourcing (BPO) firms, and telecommunications and technology companies before expanding in 2023 to gaming, hospitality, retail, managed service provider (MSP), manufacturing, and financial sectors. Scattered Spider relies heavily on social engineering, including impersonating IT and helpdesk staff, to gain initial access, bypass multifactor authentication (MFA), and compromise enterprise networks. The group has adapted its tooling to evade endpoint detection and response (EDR) defenses and used ransomware for financial gain. Scattered Spider had expanded into hybrid cloud and identity environments, using helpdesk impersonation and MFA bypass to obtain administrator access in Okta, AWS, and Office 365.