Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks
Daily Cybersecurity Briefing (30 March 2026)
Published: Loading…
At a Glance
- CISA added CVE-2025-53521 to KEV after active exploitation of F5 BIG-IP APM enabled unauthenticated remote code execution on exposed systems.
- Handala Hack breached FBI Director Kash Patel’s personal email and separately used wiper malware in the destructive Stryker intrusion.
- Citrix NetScaler devices faced active reconnaissance for CVE-2026-3055, a memory overread flaw that can leak sensitive information from vulnerable appliances.
- TA446 used the DarkSword iOS exploit kit in targeted spear-phishing operations linked to Russian state-sponsored espionage activity.
- Infinity Stealer targeted macOS users through Cloudflare-themed ClickFix lures, delivering a Python infostealer via Bash scripts and a Nuitka-packed loader.
- Smart Slider 3 exposed more than 800,000 WordPress sites to arbitrary file reads, allowing subscriber-level users to access sensitive server files.
Summary
Internet-facing infrastructure remained under pressure from high-severity flaws in F5 BIG-IP APM and Citrix NetScaler. CVE-2025-53521 was added to CISA’s Known Exploited Vulnerabilities catalogue after active exploitation, while CVE-2026-3055 drew active reconnaissance against exposed appliances. NetScaler analysis also indicated multiple memory overread issues tied to the same patch cycle.
State-linked operations featured both espionage and destructive activity across personal and enterprise targets. Handala Hack breached FBI Director Kash Patel’s personal email account and leaked historical material online. The same Iran-linked actor was also tied to the Stryker incident, where wiper malware and persistence mechanisms affected the company’s internal Microsoft environment.
Mobile and endpoint delivery chains continued to centre on highly targeted social engineering. TA446 deployed the DarkSword iOS exploit kit through spear-phishing in activity attributed to Russian state-sponsored operations. On Apple desktops, Infinity Stealer used Cloudflare-themed ClickFix lures, Bash execution, and a Nuitka-packed Python payload to steal macOS data.
Web platforms and content management environments also saw notable exposure from authenticated abuse paths. The Smart Slider 3 WordPress plugin left sites running versions up to 3.5.1.33 vulnerable to arbitrary file read through the actionExportAll function. The flaw allowed subscriber-level users to retrieve sensitive server files, including material such as wp-config.php.
Malware development and deployment methods also reflected continued operational use of AI-assisted tooling. The VoidLink malware framework was described as modular, professionally engineered, and built by a single developer using a commercial AI-powered IDE.
Highlights of the Day
CISA Flags Actively Exploited F5 BIG-IP Flaw
CISA has added CVE-2025-53521, a remote code execution flaw affecting F5 BIG-IP, to its Known Exploited Vulnerabilities catalogue after confirming active exploitation. The agency said the vulnerability presents a significant risk to federal networks and reflects a broader pattern of attackers targeting internet-facing infrastructure appliances.
Infiniti Stealer Brings ClickFix to macOS
Malwarebytes has documented Infiniti Stealer, a newly identified macOS infostealer delivered through fake CAPTCHA pages that trick users into pasting malicious commands into Terminal. The campaign uses a Bash dropper and a Python payload compiled with Nuitka, producing a native binary that complicates static analysis and detection. The malware targets browser credentials, Keychain data, cryptocurrency wallets, developer secrets, and screenshots, then exfiltrates the data over HTTP while using anti-analysis checks to evade sandboxes and virtual machines.
Iran-Linked Group Breaches FBI Director and Stryker
Handala Hack, a persona linked by researchers to Iran’s Ministry of Intelligence and Security, breached FBI Director Kash Patel’s personal email account and leaked historical personal emails and files online. The same group also claimed a destructive attack against medical technology firm Stryker, with the company saying the breach was contained within its internal Microsoft environment. Researchers cited phishing, compromised VPN credentials, RDP movement, wiper malware, and abuse of Microsoft Intune administrative access among the group’s known intrusion and disruption methods.
Citrix NetScaler Flaw Leaks Memory in SAML Setups
watchTowr Labs has analysed CVE-2026-3055, a critical memory overread vulnerability in Citrix NetScaler ADC and Gateway that can expose fragments of process memory when the appliance is configured as a SAML identity provider. The issue appears in responses from the /saml/login endpoint, where malformed authentication requests can trigger leakage through the NSC_TASS cookie. Researchers said the flaw echoes concerns raised by earlier “CitrixBleed” incidents, although this case appears narrower and dependent on specific SAML configurations.
Smart Slider 3 Flaw Exposes Server Files
Wordfence disclosed CVE-2026-3098, an arbitrary file read vulnerability in Smart Slider 3 affecting versions up to 3.5.1.33 and exposing more than 800,000 WordPress installations. The flaw allows authenticated users with subscriber-level access to abuse the plugin’s export workflow and read arbitrary server files, including sensitive files such as wp-config.php. The issue stems from missing capability checks in AJAX export functions and insufficient file validation in actionExportAll, and it was patched in version 3.5.1.34.
Daily Coverage