CyberSecBrief

Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks


Daily Cybersecurity Briefing (27 March 2026)

Published: Loading…

At a Glance

  • CISA warned that CVE-2026-33017 in Langflow is being actively exploited, allowing attackers to hijack AI workflows and execute arbitrary commands.
  • The Coruna iOS exploit kit updated CVE-2023-32434 and CVE-2023-38606 code from Operation Triangulation, targeting Apple devices across Ukraine and China.
  • TeamPCP compromised the LiteLLM PyPI package to harvest cloud credentials, SSH keys, and Kubernetes secrets while installing persistent remote backdoors.
  • Hambardzum Minasyan, alleged RedLine malware administrator, was extradited to the US, facing charges for managing C2 servers and affiliate payments.
  • VoidLink Linux rootkit leverages a Loadable Kernel Module and eBPF programs, using AI-assisted development to hide processes and network connections.
  • Anthropic’s Claude Chrome Extension had a zero-click XSS vulnerability, allowing websites to execute arbitrary commands and access emails, files, and chat history.

Summary

The Coruna iOS exploit kit has incorporated updated kernel exploits for CVE-2023-32434 and CVE-2023-38606, originally from Operation Triangulation. The toolkit has been deployed in targeted campaigns in Ukraine and financially motivated attacks in China.

TeamPCP compromised the LiteLLM PyPI package, embedding a multi-stage payload that steals cloud credentials, SSH keys, and Kubernetes secrets. The attack also installed persistent backdoors for remote code execution.

Armenian national Hambardzum Minasyan, accused of administering the RedLine infostealer, was extradited to the United States. Charges include conspiracy to commit access device fraud, money laundering, and violations of the CFAA.

The VoidLink Linux rootkit uses a hybrid architecture of Loadable Kernel Modules and eBPF programs, combining process hiding and network obfuscation. AI-assisted development is evident in iterative code and deployment scripts.

Anthropic’s Claude Chrome Extension had a zero-click XSS flaw, allowing malicious websites to execute arbitrary commands. The vulnerability enabled access to emails, files, and LLM chat history without user interaction.

CISA issued an alert regarding CVE-2026-33017 in the Langflow AI framework, which is actively exploited to hijack AI workflows and execute arbitrary commands. Agencies and developers are urged to apply immediate patches.

Highlights of the Day

Operation Triangulation Exploit Framework Reused in Broader iPhone Attack Campaign

Analysis of the Coruna exploit kit, first documented by Google and iVerify in March 2026, has identified its kernel exploits for CVE-2023-32434 and CVE-2023-38606 as updated versions of the same code used in Operation Triangulation, a sophisticated iOS espionage campaign targeting Apple devices. The kit includes four additional kernel exploits built on the same underlying framework and sharing common code, with two developed after Operation Triangulation was publicly disclosed, suggesting ongoing development by the same authors rather than independent reconstruction. Coruna has been observed in targeted attacks by a commercial surveillance vendor customer, watering-hole attacks in Ukraine, and financially motivated attacks in China, with its modular architecture supporting exploitation across a broad range of iOS versions and Apple processor generations.

Analysis of leaked source code for VoidLink, a cloud-native Linux rootkit attributed to a Chinese-speaking threat actor, reveals a hybrid architecture combining a Loadable Kernel Module with eBPF programs across at least four development generations, supporting kernel versions from CentOS 7's kernel 3.10 through Ubuntu 22.04. The LKM handles process hiding, syscall hooking via ftrace, and an ICMP-based covert command channel with runtime key rotation, whilst a companion eBPF program hides network connections from the ss utility by manipulating Netlink message structures directly in userspace memory — a technique rarely documented in the wild. Source code annotations, including phase-numbered refactoring tags, tutorial-style comments, and iterative version sequences consistent with multi-turn AI prompting, corroborate prior findings that the framework was developed through LLM-assisted workflows, with operational evidence including hardcoded Alibaba Cloud IP addresses confirming deployment against real targets.

ShadowPrompt Flaw Enabled Full Browser Control via Claude Extension

A critical vulnerability in Anthropic's Claude Chrome Extension allowed any website to silently inject prompts, giving attackers the ability to execute arbitrary commands with the same privileges as the user. The flaw combined an overly permissive origin allowlist and a DOM-based XSS in a CAPTCHA component, permitting attackers to access emails, files, and LLM chat history without user interaction. Anthropic and Arkose Labs patched the issues in early 2026, closing the trust boundary gap that exposed millions of users to potential account compromise.

Source: Koi.ai

Kinsing Resurfaces Exploiting Multiple CVEs on Fresh Infrastructure

The Kinsing malware has returned, leveraging CVE-2023-46604, CVE-2023-38646, and CVE-2025-55182 across newly deployed infrastructure, with attacks traced to a single staging host and attacker node. Exploitation involves scripts that download and execute Kinsing components, combining persistence, stealth, and command execution, including a Go-based binary and a shared library loaded via /etc/ld.so.preload. Analysis confirms that Kinsing’s operations remain consistent with prior campaigns, showing that older malware families can continue affecting systems using new vulnerabilities without altering core binaries.

Source: VulnCheck

TeamPCP Joins Vect Ransomware to Exploit OSS Supply Chains

TeamPCP, known for recent open source supply chain attacks, is reportedly partnering with the Vect ransomware group to convert compromised CI/CD pipelines and security tools into ransomware deployment vectors. The collaboration leverages stolen credentials and tokens from tools like Trivy and LiteLLM, scaling access across enterprise environments through BreachForums-affiliated operators. Analysts note this represents a growing trend where attackers target open source infrastructure to gain privileged entry, moving beyond data theft to orchestrated, multi-stage ransomware campaigns.

Source: Socket.dev

TeamPCP Exploits LiteLLM Supply Chain to Steal Cloud and AI Credentials

The criminal group TeamPCP compromised the PyPI package LiteLLM, embedding a three-stage payload that harvested cloud credentials, SSH keys, and Kubernetes secrets while installing a persistent backdoor for remote code execution. The attack was facilitated through prior compromise of the Trivy CI/CD security scanner, which allowed malicious versions of LiteLLM to be published and propagated across AI development pipelines. Although discovery was triggered by a payload bug, the campaign demonstrates how widely used AI proxy services and developer tooling can serve as high-value targets for supply chain attacks, exposing sensitive infrastructure and LLM API keys.

CISA Adds Langflow Vulnerability to Known Exploited Catalog

The Cybersecurity and Infrastructure Security Agency has listed CVE-2026-33017, a Langflow code injection vulnerability, in its Known Exploited Vulnerabilities Catalog following evidence of active exploitation. The flaw allows attackers to inject arbitrary code into AI workflows, posing risks to managed systems across federal and enterprise environments. The catalog serves as a reference for organisations to track and remediate high-risk vulnerabilities that have been observed in active cyberattacks.

Alleged RedLine Infostealer Administrator Extradited to United States

Armenian national Hambardzum Minasyan has been extradited to the United States and appeared in a Texas court on charges related to his alleged role in administering the RedLine infostealer, including maintaining command-and-control servers, administration panels, and affiliate payment systems. The indictment alleges Minasyan registered virtual private servers and internet domains to host RedLine infrastructure, created file-sharing repositories to distribute the malware to affiliates, and registered a cryptocurrency account in November 2021 to receive affiliate payments. Minasyan faces charges of conspiracy to commit access device fraud, conspiracy to commit money laundering, and conspiracy to violate the Computer Fraud and Abuse Act, carrying a maximum combined sentence of up to 50 years.

Russian Authorities Detain Alleged Administrator of LeakBase Stolen Data Marketplace

Russian police have detained a resident of Taganrog suspected of administering LeakBase, a subscription-based cybercrime marketplace launched in 2021 that hosted hundreds of millions of compromised records including banking information, login credentials, and corporate documents, with more than 147,000 registered users. The arrest follows a coordinated international operation earlier in March 2026 in which the FBI and European partners conducted over 100 law enforcement actions against 45 individuals across more than a dozen countries, seizing forum domains and shutting down hosting infrastructure in the Netherlands and Malaysia. It remains unclear whether Russian authorities coordinated the domestic arrest with Western law enforcement, with Europol having suspended cooperation with Russia following the 2022 invasion of Ukraine.

Source: The Record

Daily Coverage

Developments
Langflow ExploitationCoruna Ios KitLitellm CompromiseRedline Extradition
Vulnerabilities
CVE-2026-33017Langflow < 1.9.0 (Critical)CVE-2026-4681CVE-2026-33634CVE-2023-32434CVE-2023-46604CVE-2023-38606CVE-2023-38646CVE-2025-55182A Pre-Authentication Remote Code Execution Vulnerability Exists In React Server Components Versions 19.0.0, 19.1.0, 19.1.1, And 19.2.0 Including The Following Packages: React-Server-Dom-Parcel, React-Server-Dom-Turbopack, And React-Server-Dom-Webpack. The Vulnerable Code Unsafely Deserializes Payloads From Http Requests To Server Function Endpoints.
Threat Groups
PlayPlay is a ransomware group that has been active since at least 2022 deploying Playcrypt ransomware against the business, government, critical infrastructure, healthcare, and media sectors in North America, South America, and Europe. Play actors employ a doubleextortion model, encrypting systems after exfiltrating data, and are presumed by security researchers to operate as a closed group.