CyberSecBrief

Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks


Daily Cybersecurity Briefing (3 April 2026)

Published: Loading…

At a Glance

  • Progress ShareFile Storage Zone Controller 5.12.3 can be compromised pre-auth via CVE-2026-2699 and CVE-2026-2701 to upload IIS webshells.
  • More than 14,000 internet-exposed F5 BIG-IP APM systems remain vulnerable to actively exploited CVE-2025-53521 remote code execution attacks.
  • UAT-10608 exploited React2Shell CVE-2025-55182 to compromise 766 Next.js hosts and steal SSH keys, AWS secrets, Stripe keys and GitHub tokens.
  • A DPRK-linked phishing campaign used malicious LNK files, scheduled tasks and GitHub repositories to persist and exfiltrate Windows host data.
  • Apple expanded iOS 18.7.7 and iPadOS 18.7.7 to more devices to block DarkSword web exploitation without requiring upgrades to iOS 26.

Summary

Progress ShareFile Storage Zone Controller 5.x through version 5.12.3 is exposed to a pre-authentication RCE chain using CVE-2026-2699 and CVE-2026-2701. The chain reaches Admin.aspx without login, changes storage paths, and uploads an ASPX webshell into the IIS webroot. More than 14,000 internet-exposed F5 BIG-IP APM systems also remain vulnerable to actively exploited CVE-2025-53521 remote code execution. F5 said compromised UCS backup files may contain persistent malware, and CISA added the flaw to its KEV catalogue on 28 March.

Cisco IMC received patches for CVE-2026-20093, a critical authentication bypass that can grant unauthenticated attackers elevated system access. Cisco also fixed multiple high-severity flaws affecting SSM and other products, including issues that can lead to remote code execution, privilege escalation, and information disclosure. Apple expanded iOS 18.7.7 and iPadOS 18.7.7 to more devices after the DarkSword exploit chain and related web exploitation activity. The DarkSword chain combines six bugs across WebKit, Safari, the dynamic loader, and the kernel to achieve full device compromise from a website visit.

UAT-10608 exploited React2Shell CVE-2025-55182 to compromise at least 766 public-facing Next.js and React Server Component applications. The NEXUS Listener framework harvested database credentials, SSH private keys, cloud tokens, Kubernetes service account tokens, shell history, Stripe API keys, and GitHub tokens. Separate supply-chain fallout continued after the LiteLLM compromise, with Mercor confirming it was among thousands of affected organisations. Attackers also abused the leaked Claude Code source to seed fake GitHub repositories that delivered Vidar infostealer and GhostSocks malware.

A DPRK-linked phishing campaign targeted South Korean organisations with malicious LNK files that dropped decoy PDFs and launched multi-stage PowerShell payloads. The malware created hidden scheduled tasks every 30 minutes, checked for virtual machines and analysis tools, and exfiltrated host details through GitHub repositories and API endpoints. A separate campaign used ISO lures and fake installers to deploy RATs and cryptocurrency miners while monetising victims through CPA fraud. Another emerging threat, CrystalX RAT, adds surveillance, information theft, and device configuration changes to the current remote access malware landscape.

WhatsApp alerted about 200 users who installed a fake iOS application carrying spyware, with most identified targets located in Italy. The UK’s NCSC separately issued a security alert warning high-risk individuals about ongoing attempts to hijack WhatsApp and Signal accounts through social engineering. Akira ransomware operators are now capable of completing full attacks in under an hour, while Qilin activity continued to feature EDR-killing tooling and highly active operations in Japan. Stryker said it has fully restored operations three weeks after a data-wiping attack claimed by the Iranian-linked Handala group.

BreachForums suffered an internal compromise that exposed more than 320,000 member accounts in a dump titled “Doomsday: The Story of James.” The breach stemmed from an August 2025 migration error that left a MySQL users table and forum PGP private keys in an unsecured temporary folder. Nacogdoches Memorial Hospital disclosed a January 2026 intrusion that affected 250,000 people after attackers accessed its internal network and stole personal and health information. In the crypto sector, Drift Protocol confirmed a $280 million theft after attackers rapidly seized its Security Council administrative powers.

Highlights of the Day

14,000 F5 BIG-IP APM Systems Remain Open to RCE

More than 14,000 internet-exposed F5 BIG-IP Access Policy Manager instances remain vulnerable to CVE-2025-53521, a flaw F5 disclosed in October 2025 as denial-of-service and reclassified in March 2026 as remote code execution. F5 said unauthenticated attackers are exploiting the bug against unpatched BIG-IP APM systems with access policies configured on a virtual server, and CISA added the vulnerability to its Known Exploited Vulnerabilities catalogue on 28 March. Shadowserver said it is tracking over 17,100 BIG-IP APM fingerprints online, while F5 published indicators of compromise and warned that compromised UCS backup files may contain persistent malware.

Automated React2Shell Attacks Steal Secrets from 766 Hosts

Cisco Talos said threat cluster UAT-10608 exploited CVE-2025-55182, a pre-authentication remote code execution flaw known as React2Shell, to compromise at least 766 public-facing Next.js and React Server Component applications. The attackers deployed a multi-phase shell framework called NEXUS Listener that harvested environment secrets, database credentials, SSH keys, cloud tokens, Kubernetes service account tokens and shell history, then exfiltrated the data to a web-based command-and-control panel. Talos said the exposed dataset included roughly 701 hosts with database credentials, 599 with SSH private keys, 196 with AWS credentials, 87 with live Stripe API keys and 66 with GitHub tokens.

ShareFile Flaws Enable Pre-Auth RCE on On-Prem Servers

watchTowr disclosed a pre-authentication remote code execution chain affecting Progress ShareFile Storage Zone Controller 5.x, combining CVE-2026-2699, an authentication bypass, with CVE-2026-2701, a post-auth file upload abuse. The researchers said the bug chain affects branch 5.x through version 5.12.3 and lets attackers reach Admin.aspx without logging in, reconfigure storage paths, and upload an ASPX webshell into the IIS webroot. watchTowr estimated roughly 30,000 internet-facing Storage Zone Controller instances and said Progress fixed both vulnerabilities in version 5.12.4, released on 10 March 2026.

DPRK Phishing Chain Uses GitHub for Stealthy Windows C2

FortiGuard Labs said a DPRK-linked campaign is targeting South Korean organisations with malicious LNK files that drop decoy PDFs, launch multi-stage PowerShell scripts, and use GitHub repositories and API endpoints for command-and-control and data exfiltration. The second-stage script checks for analysis tools and virtual machine processes, creates a hidden scheduled task every 30 minutes, and uploads host details including OS version, boot time, running processes, and IP address to the actor’s GitHub infrastructure. Fortinet linked the activity to earlier XenoRAT delivery campaigns and identified GitHub accounts including motoralis, God0808RAMA, Pigresy80, entire73, and brandonleeodd93-blip as part of the operation.

Source: Fortinet

BreachForums Dark Web Forum Compromised, 320,000 Member Records Exposed

In January 2026, BreachForums, a major dark web marketplace for stolen data, suffered an internal attack that exposed over 320,000 member accounts in a release titled “Doomsday: The Story of James.” The forum, successor to RaidForums, had previously mishandled a migration in August 2025, leaving a MySQL users table (hcclmafd2jnkwmfufmybb_users) and forum PGP private keys in an unsecured temporary folder. This administrative error enabled the breach that ultimately undermined trust within the criminal ecosystem and led to the forum’s collapse by March 2026.

Daily Coverage

Developments
Sharefile Rce ChainF5 Apm ExposureReact2Shell TheftDarksword Patches
Vulnerabilities
CVE-2026-20093Cisco Enterprise Nfv Infrastructure Software 4.1.1 (Critical)CVE-2026-2699Sharefile Storage Zones ControllerCVE-2025-53521Big-Ip 17.5.0 (Critical)CVE-2026-2701Sharefile Storage Zones ControllerCVE-2025-55182A Pre-Authentication Remote Code Execution Vulnerability Exists In React Server Components Versions 19.0.0, 19.1.0, 19.1.1, And 19.2.0 Including The Following Packages: React-Server-Dom-Parcel, React-Server-Dom-Turbopack, And React-Server-Dom-Webpack. The Vulnerable Code Unsafely Deserializes Payloads From Http Requests To Server Function Endpoints.CVE-2026-33309Langflow >= 1.2.0, < 1.9.0 (Critical)CVE-2026-3502Trueconf Client Trueconf Client Versions 8.1.0 Through 8.5.2 (High)
Threat Groups
PlayPlay is a ransomware group that has been active since at least 2022 deploying Playcrypt ransomware against the business, government, critical infrastructure, healthcare, and media sectors in North America, South America, and Europe. Play actors employ a doubleextortion model, encrypting systems after exfiltrating data, and are presumed by security researchers to operate as a closed group.RedDelta[Also known as: TA416, UNC6384, Red Lich] Mustang Panda is a Chinabased cyber espionage threat actor that has been conducting operations since at least 2012. Mustang Panda has been known to use tailored phishing lures and decoy documents to deliver malicious payloads. Mustang Panda has targeted government, diplomatic, and nongovernmental organizations, including think tanks, religious institutions, and research entities, across the United States, Europe, and Asia, with notable activity in Russia, Mongolia, Myanmar, Pakistan, and Vietnam.AkiraAkira is a ransomware variant and ransomware deployment entity active since at least March 2023. Akira uses compromised credentials to access singlefactor external access mechanisms such as VPNs for initial access, then various publiclyavailable tools and techniques for lateral movement. Akira operations are associated with "double extortion" ransomware activity, where data is exfiltrated from victim environments prior to encryption, with threats to publish files if a ransom is not paid. Technical analysis of Akira ransomware indicates variants capable of targeting Windows or VMWare ESXi hypervisors and multiple overlaps with Conti ransomware.