Weekly review

ThreatNoir Morning Brief — March 18

2026-03-18Morning10 articles
Audio
Listen to the episode

Morning Review in IT Security — March 18, 2026

The cybersecurity landscape continues to intensify as nation-state actors, criminal syndicates, and supply-chain adversaries escalate their operations across multiple vectors. Today's briefing covers significant developments spanning sanctions enforcement, malware campaigns targeting developers, espionage operations, critical vulnerabilities in AI platforms, and widespread supply-chain compromises affecting open-source ecosystems.

Europe Sanctions Chinese and Iranian Firms for Cyberattacks

The European Union Council has announced sanctions against three entities and two individuals for their involvement in cyberattacks targeting critical infrastructure across the region. The action represents a coordinated diplomatic response to state-sponsored cyber operations. Source: Europe sanctions Chinese and Iranian firms for cyberattacks

The sanctioned actors have been linked to the deployment of Holy Souls and Raptor Train malware families in attacks against European critical infrastructure. This enforcement action underscores the EU's commitment to holding malicious state actors accountable through economic and diplomatic measures.

ClickFix Attack Targets Developers with MacSync Malware via Fake Claude Tools

Cybersecurity researchers at 7AI have identified a sophisticated campaign exploiting developer communities through fraudulent AI tool extensions and malicious Google advertisements. The attack leverages the popularity of Claude AI tools to distribute MacSync malware and related payloads to unsuspecting technical professionals. Source: ClickFix Attack Targets Devs with MacSync Malware via Fake Claude Tools

The campaign employs Claude Fraud and CrossMark2 malware variants to harvest sensitive data from compromised development environments. This supply-chain focused attack demonstrates adversaries' continued targeting of software developers as high-value victims capable of introducing malware into downstream products and services.

Suspected China-Based Espionage Operation Against Military Targets in Southeast Asia

Intelligence analysts have uncovered a sophisticated espionage operation attributed to China-based threat actors demonstrating strategic operational patience against military and defense-related targets throughout Southeast Asia. The campaign deploys custom backdoors including AppleChris, Getpass, and MemFun to establish persistent access within target networks. Source: Suspected China-Based Espionage Operation Against Military Targets in Southeast Asia

The operation leverages DLL hijacking and WMI-based lateral movement techniques to expand access across compromised environments. Infrastructure associated with the campaign includes IP addresses 109.248.24.177, 154.39.137.203, 154.39.142.177, and 8.212.169.27. The attackers' use of Mimikatz and custom backdoors indicates advanced capability and deep familiarity with target network architectures.

Fortinet VPN Zero-Day Vulnerability Available for Sale

A zero-day vulnerability affecting Fortinet VPN products has surfaced on darknet markets with an asking price of 3 Bitcoin. The vulnerability permits unauthorized bypass of VPN authentication mechanisms, potentially enabling threat actors to gain unauthorized access to protected networks. Source: ‼️ Fortinet VPN 0-day bypass up for sale for 3 BTC

This disclosure represents a critical risk to organizations relying on Fortinet VPN infrastructure for secure remote access. The availability of exploit code on underground markets significantly increases the likelihood of rapid weaponization and widespread exploitation.

AI Flaws in Amazon Bedrock, LangSmith, and SGLang Enable Data Exfiltration and Remote Code Execution

BeyondTrust researchers have disclosed critical vulnerabilities affecting major AI code execution platforms that permit data exfiltration and remote code execution through DNS query manipulation. Amazon Bedrock AgentCore Code Interpreter's sandbox environment permits outbound DNS queries that attackers can exploit to establish interactive shells and exfiltrate sensitive data. Source: AI Flaws in Amazon Bedrock, LangSmith, and SGLang Enable Data Exfiltration and RCE

The vulnerabilities (CVE-2026-25750, CVE-2026-3059, and CVE-2026-3060) enable attackers to establish DNS tunneling command-and-control channels from within sandboxed AI environments. The research reveals that inadequate network isolation in popular AI platforms creates significant security gaps that could permit compromise of sensitive data processed through these services.

CVE-2026-3888: Critical Snap Privilege Escalation Vulnerability in Ubuntu Desktop

The Qualys Threat Research Unit has identified a local privilege escalation vulnerability (CVE-2026-3888) affecting default installations of Ubuntu Desktop 24.04 and later. The flaw permits unprivileged local attackers to escalate privileges to full root access through interaction between snap-confine and systemd-tmpfiles. Source: CVE-2026-3888: Important Snap Flaw Enables Local Privilege Escalation to Root

This vulnerability poses significant risk to Ubuntu Desktop deployments, particularly in environments where local user access is permitted. The exploitation pathway requires no special privileges, making it readily exploitable by any local user account on affected systems.

Storm-2561 Uses Fake Fortinet and Ivanti VPN Sites to Distribute Hyrax Infostealer

Microsoft Defender Experts identified a campaign in which the Storm-2561 threat group deceives users into visiting fraudulent VPN provider websites to download Hyrax infostealer malware. The adversaries operate spoofed domains including vpn-fortinet.com and ivanti-vpn.org to impersonate legitimate VPN services. Source: Storm-2561 Uses Fake Fortinet, Ivanti VPN Sites to Drop Hyrax Infostealer

This social engineering approach exploits users' legitimate desire to secure their network connections by directing them to malicious infrastructure. The Hyrax infostealer harvests credentials and sensitive data from compromised systems, enabling subsequent unauthorized access and lateral movement.

GlassWorm Malware Hits 400+ Code Repositories Across Multiple Platforms

The GlassWorm supply-chain campaign has returned with a coordinated attack targeting over 400 packages, repositories, and extensions across GitHub, npm, and VSCode/OpenVSX platforms. The campaign represents a significant escalation in supply-chain targeting of open-source ecosystems. Source: GlassWorm malware hits 400+ code repos on GitHub, npm, VSCode, OpenVSX

The GlassWorm malware employs obfuscation and credential harvesting techniques to establish persistence within compromised repositories. The widespread distribution across multiple platforms and package ecosystems increases the likelihood of downstream compromise affecting numerous organizations and developers relying on affected open-source components.

Boggy Serpens Threat Assessment: Iranian Espionage Group Evolves Capabilities

Unit 42 has released a comprehensive threat assessment of Boggy Serpens, an Iranian cyberespionage group whose operations have evolved to incorporate AI-enhanced malware and refined social engineering techniques. The group demonstrates persistent targeting of strategic objectives through advanced operational tradecraft. Source: Boggy Serpens Threat Assessment

Boggy Serpens deploys BlackBeard and LampoRAT malware families in campaigns employing phishing, trusted relationship exploitation, and custom command-and-control protocols. The group's evolving capabilities and persistent operational tempo indicate sustained investment in cyber operations infrastructure and advanced tradecraft development.

UK Companies House Exposed Details of Millions of Firms

The UK Companies House government agency confirmed that a vulnerability in its systems could have been exploited to obtain company details and alter official records for millions of registered businesses. The incident represents a significant breach of critical business registry infrastructure. Source: UK Companies House Exposed Details of Millions of Firms

The exposure of Companies House data creates substantial risk for affected organizations, including potential for fraud, identity theft, and business impersonation. The compromise of authoritative business records underscores the critical importance of security controls protecting government registry systems.


Today's threat landscape reflects continued sophistication and coordination among nation-state actors, criminal enterprises, and supply-chain adversaries. Organizations should prioritize patching critical vulnerabilities, implementing supply-chain security controls, and enhancing monitoring for indicators associated with these active campaigns.

Europe sanctions Chinese and Iranian firms for cyberattacks

Source: Europe sanctions Chinese and Iranian firms for cyberattacks

The European Union Council has announced sanctions against three entities and two individuals for their involvement in cyberattacks targeting critical infrastructure in the region. [...]

ClickFix Attack Targets Devs with MacSync Malware via Fake Claude Tools

Source: ClickFix Attack Targets Devs with MacSync Malware via Fake Claude Tools

Cybersecurity researchers at 7AI have revealed a new Claude Fraud campaign in which hackers use fake AI extensions and Google ads to steal data from tech professionals.

‼️ Fortinet VPN 0-day bypass up for sale for 3 BTC https://t.co/rQOmE3qFOp

Source: ‼️ Fortinet VPN 0-day bypass up for sale for 3 BTC https://t.co/rQOmE3qFOp

‼️ Fortinet VPN 0-day bypass up for sale for 3 BTC https://t.co/rQOmE3qFOp

AI Flaws in Amazon Bedrock, LangSmith, and SGLang Enable Data Exfiltration and RCE

Source: AI Flaws in Amazon Bedrock, LangSmith, and SGLang Enable Data Exfiltration and RCE

Cybersecurity researchers have disclosed details of a new method for exfiltrating sensitive data from artificial intelligence (AI) code execution environments using domain name system (DNS) queries. In a report published Monday, BeyondTrust revealed that Amazon Bedrock AgentCore Code Interpreter's sandbox mode permits outbound DNS queries that an attacker can exploit to enable interactive shells

CVE-2026-3888: Important Snap Flaw Enables Local Privilege Escalation to Root

Source: CVE-2026-3888: Important Snap Flaw Enables Local Privilege Escalation to Root

The Qualys Threat Research Unit has identified a Local Privilege Escalation (LPE) vulnerability affecting default installations of Ubuntu Desktop version 24.04 and later. This flaw (CVE-2026-3888) allows an unprivileged local attacker to escalate privileges to full root access through the interaction of two standard system components: snap-confine and systemd-tmpfiles. While the exploit requires a specific […]

Storm-2561 Uses Fake Fortinet, Ivanti VPN Sites to Drop Hyrax Infostealer

Source: Storm-2561 Uses Fake Fortinet, Ivanti VPN Sites to Drop Hyrax Infostealer

In mid-January 2026, Microsoft Defender Experts identified a devious way that cybercriminals are tricking people into giving away…

GlassWorm malware hits 400+ code repos on GitHub, npm, VSCode, OpenVSX

Source: GlassWorm malware hits 400+ code repos on GitHub, npm, VSCode, OpenVSX

The GlassWorm supply-chain campaign has returned with a new, coordinated attack that targeted hundreds of packages, repositories, and extensions on GitHub, npm, and VSCode/OpenVSX extensions. [...]

Sources & IOCs

Source articles and extracted indicators (defanged where appropriate).

Europe sanctions Chinese and Iranian firms for cyberattacks
Malware2
  • Raptor Train
    Botnet operated by Chinese state-sponsored threat actor Flax Typhoon; 260,000 infected devices
  • Holy Souls
    Moniker used by Emennet Pasargad on hacker forums; offered to sell 230,000 Charlie Hebdo subscriber records in January 2023
ClickFix Attack Targets Devs with MacSync Malware via Fake Claude Tools
Malware3
  • MacSync
    macOS malware that targets Keychain credentials, passwords, browser cookies, and crypto-wallet keys
  • CrossMark2
    Windows second-stage malware deployed via fake VS Code Claude plugin after antivirus is disabled
  • Claude Fraud
    Campaign name for the coordinated attack using fake AI extensions and Google ads targeting developers
Suspected China-Based Espionage Operation Against Military Targets in Southeast Asia
MITRE ATT&CK2
Malware4
  • AppleChris
    Custom backdoor deployed for lateral movement and persistence
  • MemFun
    Custom backdoor with distinct functionality deployed in campaign
  • Getpass
    Custom credential harvester tool
  • Mimikatz
    Used for credential extraction in campaign
IP Address4
  • 109.248.24.177
    C2 server used in reverse shell connections
  • 154.39.142.177
    C2 server used in reverse shell connections
  • 154.39.137.203
    C2 server used in reverse shell connections
  • 8.212.169.27
    C2 server used in reverse shell connections
AI Flaws in Amazon Bedrock, LangSmith, and SGLang Enable Data Exfiltration and RCE
CVE3
  • SGLang unauthenticated RCE via unsafe pickle deserialization in ZeroMQ broker (CVSS 9.8)
  • LangSmith URL parameter injection vulnerability enabling token theft and account takeover (CVSS 8.5)
  • SGLang unsafe pickle deserialization vulnerability (CVSS 9.8)
Malware1
  • DNS tunneling C2 channel
    Amazon Bedrock AgentCore Code Interpreter abuse for command-and-control via DNS queries
Domain1
  • smith.langchain[.]com
    LangSmith cloud deployment vulnerable to parameter injection attacks
GlassWorm malware hits 400+ code repos on GitHub, npm, VSCode, OpenVSX
MITRE ATT&CK4
  • Masquerading with invisible Unicode characters to hide malicious code
  • Credential Access: targeting cryptocurrency wallet data
  • Credential Access: stealing SSH keys, access tokens, and developer credentials
  • C2: querying Solana blockchain for command instructions every 5 seconds
Malware1
  • GlassWorm
    Supply-chain malware campaign targeting open-source repositories and extensions; uses invisible Unicode obfuscation; steals crypto wallet data and developer credentials
Boggy Serpens Threat Assessment
MITRE ATT&CK4
  • Trusted Relationship - exploitation of hijacked legitimate internal accounts for access
  • Phishing: Spearphishing Link - primary delivery mechanism used by Boggy Serpens
  • Non-Standard Port - customized UDP-based traffic for C2
  • Application Layer Protocol: Web Protocols - HTTP status codes used for C2 communication
Malware2
  • BlackBeard
    Rust-based backdoor developed by Boggy Serpens for rapid custom implant deployment and persistence
  • LampoRAT
    Remote Access Trojan associated with Boggy Serpens operations