CyberSecBrief

Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks


Daily Cybersecurity Briefing (26 March 2026)

Published: Loading…

At a Glance

  • TeamPCP compromised LiteLLM PyPI versions 1.82.7 and 1.82.8 with credential-stealing malware targeting AWS, GCP, Kubernetes, and cryptocurrency wallet data.
  • CVE-2026-3055, a CVSS 9.3 out-of-bounds read in Citrix NetScaler ADC and Gateway, allows unauthenticated memory reads on SAML IDP-configured appliances.
  • CVE-2026-21962, a CVSS 10.0 unauthenticated RCE flaw in Oracle WebLogic Server, was exploited within hours of public exploit code release.
  • Navia Benefit Solutions breach exposed names, Social Security numbers, and health data belonging to approximately 2.7 million individuals.
  • A mass phishing campaign posted thousands of fake VS Code security alerts across GitHub Discussions, routing victims through a traffic distribution system.
  • Dragonfly exploited default credentials on internet-exposed Hitachi RTU560 and Moxa NPort devices, causing destructive impact to hardware on the Polish power grid.

Summary

A coordinated phishing campaign targeting developers posted thousands of fake Visual Studio Code security alerts across GitHub Discussions, delivering email notifications directly to repository watchers. Linked payloads routed victims through a Google sharing endpoint to an attacker-controlled domain that fingerprinted browser environments before routing to follow-on infrastructure.

The Navia Benefit Solutions breach exposed names, Social Security numbers, dates of birth, and health plan information belonging to approximately 2.7 million individuals, following unauthorised access between 22 December 2025 and 15 January 2026. Puerto Rico's vehicle licensing agency CESCO cancelled all driver's licence appointments after a separate cyber incident disrupted its systems. A hacktivist group also claimed to have exfiltrated more than 8.3 million records from P3 Global Intel, a provider of tip management software used by Crime Stoppers programmes and US law enforcement agencies.

TeamPCP extended its supply chain campaign to PyPI on 24 March 2026, publishing malicious LiteLLM versions 1.82.7 and 1.82.8 containing credential-stealing malware. The compromised packages remained publicly available for approximately five hours, targeting AWS and GCP tokens, Kubernetes secrets, and cryptocurrency wallet data. The campaign previously compromised Trivy and Checkmarx KICS, with attackers claiming over 500,000 stolen accounts across more than 20,000 affected repositories.

Citrix disclosed two vulnerabilities in NetScaler ADC and NetScaler Gateway affecting on-premises deployments. CVE-2026-3055 (CVSS 9.3) allows unauthenticated remote attackers to read sensitive appliance memory when configured as a SAML identity provider. CVE-2026-4368 (CVSS 7.7) is a race condition on gateway and AAA virtual server configurations that can result in user session mixup.

Oracle WebLogic Server CVE-2026-21962, carrying a maximum CVSS score of 10.0, was exploited within hours of its public proof-of-concept release, with automated scanning tools dominating attack traffic against exposed instances. Alongside the new flaw, attackers continued targeting older critical WebLogic vulnerabilities including CVE-2020-14882/14883 and CVE-2017-10271. Internet-exposed ICS devices from Rockwell Automation, Moxa, and Hitachi Energy also faced active nation-state targeting, with Dragonfly exploiting default credentials to permanently destroy hardware on the Polish power grid in December 2025.

Two Russian nationals received US prison sentences for ransomware-related offences. Aleksei Volkov was sentenced to 81 months for operating as an initial access broker supporting Yanluowang ransomware attacks, with restitution ordered at $9.2 million. Ilya Angelov, linked by US authorities to TA551 activity, received a 24-month sentence and a $100,000 fine for managing a phishing botnet used to deploy BitPaymer ransomware against 72 US companies, with $1.6 million in proceeds forfeited.

Highlights of the Day

TeamPCP Supply Chain Attack Hits Trivy, Checkmarx, and LiteLLM in Coordinated Campaign

TeamPCP conducted a multi-stage supply chain attack beginning 19 March 2026, compromising GitHub Actions workflows and Docker images for Trivy, followed by Checkmarx KICS and AST on 23 March, and LiteLLM PyPI versions 1.82.7 and 1.82.8 on 24 March. The credential-stealing malware searched CI/CD environments for AWS and GCP tokens, Kubernetes secrets, database credentials, cryptocurrency wallet data, and API keys, exfiltrating encrypted payloads to typosquatted domains including scan.aquasecurtiy[.]org and models.litellm[.]cloud. Attackers claim to have stolen hundreds of gigabytes of data and over 500,000 accounts across more than 20,000 potentially affected repositories, with destructive capabilities that wipe Kubernetes clusters on systems where Farsi or the Tehran time zone is detected.

Source: Kaspersky

Two Citrix NetScaler Vulnerabilities Expose SAML and Gateway Configurations

Citrix has disclosed two vulnerabilities in NetScaler ADC and NetScaler Gateway affecting customer-managed on-premises deployments. CVE-2026-3055 (CVSS 9.3) is a critical out-of-bounds read flaw triggered when an appliance is configured as a SAML identity provider, allowing unauthenticated remote attackers to read sensitive memory contents. CVE-2026-4368 (CVSS 7.7) is a race condition affecting appliances configured as a gateway or AAA virtual server that can result in user session mixup, with exploitation requiring prior authentication.

Benefits administrator Navia Benefit Solutions has disclosed a breach in which an unauthorised party accessed its systems between 22 December 2025 and 15 January 2026, exposing names, dates of birth, Social Security numbers, phone numbers, email addresses, and health plan information belonging to approximately 2.7 million individuals. Cybersecurity firm HackerOne has separately confirmed that personal data belonging to 287 of its employees may have been compromised through Navia, which serves as one of its US benefits administrators. HackerOne received Navia's notification on 20 February 2026, though it was not delivered until March, and the firm has stated it will conduct its own investigation and review Navia's privacy and security practices.

Thousands of Internet-Exposed ICS Devices Targeted by Nation-State Actors

Analysis of internet-exposed industrial control systems across January 2026 identified 9,764 unique IP addresses associated with targeted ICS devices from manufacturers including Rockwell Automation, Moxa, Siemens, Schneider Electric, and Hitachi Energy, with Rockwell accounting for 68.1% of exposed devices and the United States representing 45.4% of all targeted infrastructure. The findings are accompanied by two documented attack cases attributed to Dragonfly, a Russian FSB-linked threat group, which exploited default credentials on internet-exposed Hitachi RTU560 and Moxa NPort devices against the Polish power grid in December 2025, in one instance permanently destroying hardware through corrupted firmware and in another locking out devices by reconfiguring them to a non-routable loopback address. A separate 2023 case involving Rockwell Automation ControlLogix communication modules highlighted the potential for nation-state actors to develop exploit capabilities enabling firmware manipulation and persistent access without triggering visible operator alerts.

Source: Team Cymru

Critical Oracle WebLogic Flaw Exploited Within Hours of Public Disclosure

A 12-day honeypot study emulating a vulnerable Oracle WebLogic Server recorded exploitation attempts against CVE-2026-21962 — a CVSS 10.0 unauthenticated remote code execution flaw — within hours of its public exploit code being released on 22 January 2026, with attackers operating from rented VPS infrastructure across DigitalOcean, HOSTGLOBAL.PLUS, and Microsoft Azure. Alongside the newly disclosed flaw, the honeypot captured continued active exploitation of older critical WebLogic vulnerabilities including CVE-2020-14882/14883, CVE-2020-2551, and CVE-2017-10271, confirming that threat actors consistently return to a small set of unauthenticated, high-impact exploits. Attack traffic was dominated by automated scanning tools including libredtail-http and the Nmap Scripting Engine, with a broad spray-and-pray pattern also targeting unrelated flaws including a Hikvision CVE and PHPUnit RCE endpoints.

Source: CloudSEK

Fake VS Code Security Alerts Spread Across GitHub Discussions in Mass Phishing Campaign

A coordinated phishing campaign is targeting developers on GitHub by posting fake Visual Studio Code security advisories through the Discussions feature, with thousands of near-identical posts appearing across repositories and triggering email notifications to watchers and participants. Each post references fabricated CVEs and directs users to download a purported security fix via external file-sharing links, with analysis of one payload revealing a multi-step redirection chain through a Google sharing endpoint to an attacker-controlled domain that fingerprints visitors for timezone, platform, user agent, and automation signals before routing them to follow-on infrastructure. The fingerprinting stage does not deliver an immediate payload, indicating the campaign likely operates as a traffic distribution system used to profile and selectively route victims to further stages such as exploit kits or phishing pages.

Source: Socket

Reservation Hijack Scam Uses Compromised Hotel Accounts to Defraud Travellers

A fraud campaign targeting hotel guests operates by first phishing hospitality staff to steal credentials for property management platforms such as Cloudbeds, then using the resulting access to retrieve real reservation data and contact upcoming guests through legitimate hotel or booking-platform accounts. Victims receive messages via WhatsApp, SMS, or booking platform threads that reference accurate stay details, creating a highly convincing pretext before redirecting them through fake guest portals or professionally styled PDFs to typosquatted payment pages designed to harvest card details or bank transfer approvals. In cases where hotel partner accounts on platforms such as Booking.com have been compromised, malicious payment requests have been injected directly into existing legitimate reservation message threads, making the fraud difficult to distinguish from routine pre-arrival communications.

Daily Coverage

Developments
Teampcp / Litellm PypiCVE-2026-3055 CitrixCVE-2026-21962 WeblogicNavia Data Breach
Vulnerabilities
CVE-2023-32434CVE-2023-38606CVE-2023-46604CVE-2023-38646CVE-2025-55182A Pre-Authentication Remote Code Execution Vulnerability Exists In React Server Components Versions 19.0.0, 19.1.0, 19.1.1, And 19.2.0 Including The Following Packages: React-Server-Dom-Parcel, React-Server-Dom-Turbopack, And React-Server-Dom-Webpack. The Vulnerable Code Unsafely Deserializes Payloads From Http Requests To Server Function Endpoints.CVE-2026-33017Langflow < 1.9.0 (Critical)CVE-2026-20079Cisco Secure Firewall Management Center (Fmc) 7.0.0 (Critical)CVE-2026-21962Oracle Http Server, Oracle Weblogic Server Proxy Plug-In 12.2.1.4.0 (Critical)CVE-2020-2551CVE-2026-3055Adc 14.1 (Critical)
Threat Groups
DragonflyDragonfly is a cyber espionage group that has been attributed to Russia's Federal Security Service (FSB) Center 16. Active since at least 2010, Dragonfly has targeted defense and aviation companies, government entities, companies related to industrial control systems, and critical infrastructure sectors worldwide through supply chain, spearphishing, and driveby compromise attacks.Pawn StormAPT28 is a threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) 85th Main Special Service Center (GTsSS) military unit 26165. This group has been active since at least 2004. APT28 reportedly compromised the Hillary Clinton campaign, the Democratic National Committee, and the Democratic Congressional Campaign Committee in 2016 in an attempt to interfere with the U. S. presidential election. In 2018, the US indicted five GRU Unit 26165 officers associated with APT28 for cyber operations (including closeaccess operations) conducted between 2014 and 2018 against the World AntiDoping Agency (WADA), the US AntiDoping Agency, a US nuclear facility, the Organization for the Prohibition of Chemical Weapons (OPCW), the Spiez Swiss Chemicals Laboratory, and other organizations. Some of these were conducted with the assistance of GRU Unit 74455, which is also referred to as Sandworm Team.Salt TyphoonSalt Typhoon is a People's Republic of China (PRC) statebacked actor that has been active since at least 2019 and responsible for numerous compromises of network infrastructure at major U. S. telecommunication and internet service providers (ISP).TA551TA551 is a financiallymotivated threat group that has been active since at least 2018. The group has primarily targeted English, German, Italian, and Japanese speakers through emailbased malware distribution campaigns.