Weekly review

ThreatNoir Morning Brief — March 17

2026-03-17Morning10 articles
Audio
Listen to the episode

Morning Review in IT Security — March 17, 2026

The cybersecurity landscape continues to face significant threats across multiple vectors on March 17, 2026. From supply chain compromises targeting open-source repositories to active exploitation of critical infrastructure vulnerabilities, security teams face an escalating array of challenges. Today's briefing covers emerging malware campaigns, government infrastructure attacks, and ongoing incidents affecting major organizations worldwide.

GlassWorm Attack Uses Stolen GitHub Tokens to Force-Push Malware Into Python Repos

A sophisticated malware campaign known as GlassWorm is leveraging stolen GitHub tokens to inject malicious code into hundreds of Python repositories. The attack specifically targets Python projects including Django applications, machine learning research code, Streamlit dashboards, and PyPI packages by appending obfuscated code to critical files such as setup.py, main.py, and app.py. According to security researchers at StepSecurity, the campaign represents a significant threat to the open-source ecosystem. Source: GlassWorm Attack Uses Stolen GitHub Tokens to Force-Push Malware Into Python Repos

CISA Flags Wing FTP Server Flaw as Actively Exploited in Attacks

The Cybersecurity and Infrastructure Security Agency has issued warnings to U.S. government agencies regarding active exploitation of vulnerabilities in Wing FTP Server. The flaws can be chained together to enable remote code execution attacks against affected systems. CISA has added evidence of active exploitation to its Known Exploited Vulnerabilities catalog, prompting immediate remediation efforts across federal agencies. Source: CISA flags Wing FTP Server flaw as actively exploited in attacks

CISA Flags Actively Exploited Wing FTP Vulnerability Leaking Server Paths

CISA added a medium-severity information disclosure vulnerability affecting Wing FTP to its Known Exploited Vulnerabilities catalog on Monday, citing confirmed active exploitation. The vulnerability, tracked as CVE-2025-47813 with a CVSS score of 4.3, leaks the installation path of the application under certain conditions. This disclosure flaw can provide attackers with critical information needed to chain with other vulnerabilities for more severe attacks. Source: CISA Flags Actively Exploited Wing FTP Vulnerability Leaking Server Paths

Stryker Attack Wiped Tens of Thousands of Devices, No Malware Needed

Medical technology giant Stryker fell victim to a cyberattack last week that remotely wiped tens of thousands of employee devices without requiring traditional malware deployment. The incident was confined to Stryker's internal Microsoft environment, demonstrating how attackers can leverage legitimate administrative capabilities to cause widespread damage. The attack highlights the critical importance of identity and access management controls in preventing catastrophic device loss. Source: Stryker attack wiped tens of thousands of devices, no malware needed

FBI Investigates Steam Games Linked to Malware and Crypto Wallet Theft

The Federal Bureau of Investigation has warned gamers about malware hidden within several Steam games that stole browser data and drained cryptocurrency wallets. The malicious activity occurred between May 2024 and January 2026, affecting an unknown number of gaming platform users. The compromise demonstrates the ongoing risk of supply chain attacks through legitimate distribution channels targeting consumer-level systems. Source: FBI Investigates Steam Games Linked to Malware and Crypto Wallet Theft

China-Nexus Hackers Skulk in Southeast Asian Military Orgs for Years

Researchers have uncovered an extensive cyberespionage campaign involving China-linked threat actors who maintained persistent access to Southeast Asian military organizations over extended periods. The campaign employed novel backdoors alongside familiar evasion techniques to evade detection and sustain long-term presence within regional defense networks. The discovery underscores the persistent nature of state-sponsored cyber operations targeting critical infrastructure in the region. Source: China-Nexus Hackers Skulk in Southeast Asian Military Orgs for Years

Help on the Line: How a Microsoft Teams Support Call Led to Compromise

Microsoft's Detection and Response Team investigated a voice phishing attack conducted through Microsoft Teams that resulted in organizational compromise. The incident demonstrates how threat actors exploit trusted communication tools and social engineering tactics to facilitate identity-led intrusions. The investigation provides critical insights into attack methodologies and defensive measures organizations can implement to prevent similar incidents. Source: Help on the line: How a Microsoft Teams support call led to compromise

Threat Actor Selling Kordon Database from Russian Federal Border Service

A threat actor is allegedly offering the Kordon database, allegedly compromised from the Russian Federal Border Service in September 2023, for sale on underground forums. The database reportedly contains over 1 billion total records covering 79.5 million unique individuals, including foreign nationals. The potential compromise represents a significant privacy and national security concern given the sensitive nature of border service data. Source: ‼️🇷🇺 A threat actor is allegedly selling the "Kordon" database from the Russian Federal Border Service

Oracle EBS Hack: Only 4 Corporate Giants Still Silent on Potential Impact

Four major corporations—Broadcom, Bechtel, Estée Lauder, and Abbott Technologies—remain silent regarding their potential exposure to the Oracle Enterprise Business Suite zero-day vulnerability exploitation. The Cl0p ransomware group has been linked to the attacks leveraging these critical vulnerabilities. Most other affected organizations have issued public statements regarding their security posture and remediation efforts. Source: Oracle EBS Hack: Only 4 Corporate Giants Still Silent on Potential Impact

UK's Companies House Confirms Security Flaw Exposed Business Data

Companies House, the British government agency responsible for the registry of all United Kingdom companies, confirmed that a security flaw in its WebFiling service exposed company information since October 2025. The service was taken offline on Friday to remediate the vulnerability and has since been restored to operational status. The incident raises concerns about the security of critical government business registration infrastructure. Source: UK's Companies House confirms security flaw exposed business data

Security teams should prioritize patching Wing FTP Server vulnerabilities, reviewing GitHub token access controls, auditing Microsoft Teams security configurations, and verifying their organizations' exposure to Oracle EBS zero-day exploits. The convergence of supply chain attacks, active exploitation of known vulnerabilities, and sophisticated state-sponsored campaigns underscores the need for comprehensive threat intelligence integration and rapid incident response capabilities.

Sources & IOCs

Source articles and extracted indicators (defanged where appropriate).

GlassWorm Attack Uses Stolen GitHub Tokens to Force-Push Malware Into Python Repos
Malware4
  • react-native-country-select v0.3.91
    Compromised npm package with malicious preinstall hook, part of ForceMemo campaign
  • GlassWorm
    Primary malware campaign targeting developers via VS Code extensions and GitHub account takeovers
  • ForceMemo
    New GlassWorm variant using force-push technique to inject malware into Python repos
  • react-native-international-phone-number v0.11.8
    Compromised npm package with preinstall hook delivering obfuscated malware
FBI Investigates Steam Games Linked to Malware and Crypto Wallet Theft
Malware7
  • Lampy
    Malicious Steam game distributing data-stealing malware
  • Lunara
    Malicious Steam game distributing data-stealing malware
  • PirateFi
    Malicious Steam game distributing data-stealing malware
  • Chemia
    Malicious Steam game distributing data-stealing malware
  • Tokenova
    Malicious Steam game distributing data-stealing malware
  • BlockBlasters
    Malicious Steam game; estimated $150,000 in community losses
  • Dashverse
    Malicious Steam game also known as DashFPS distributing data-stealing malware
Oracle EBS Hack: Only 4 Corporate Giants Still Silent on Potential Impact
CVE1
MITRE ATT&CK1
  • Threat actor cluster suspected by cybersecurity community of driving the Oracle EBS exploitation campaign
Malware1
  • Cl0p
    Ransomware and extortion group claiming responsibility for Oracle EBS campaign; believed to be public-facing brand for operation potentially driven by FIN11