Weekly review

ThreatNoir Afternoon Brief — March 19

2026-03-19Afternoon4 articles
Audio
Listen to the episode

Afternoon Review in IT Security — March 19, 2026

The cybersecurity landscape continues to face significant threats as critical vulnerabilities in widely-deployed enterprise systems come under active exploitation. Today's threat intelligence reveals urgent risks spanning cloud infrastructure, mobile platforms, and network security that demand immediate organizational attention.

CISA Urges US Organizations to Secure Microsoft Intune Systems After Stryker Breach

The Cybersecurity and Infrastructure Security Agency has issued a warning to U.S. organizations following a cyberattack that exploited Microsoft Intune to compromise medical technology company Stryker's systems. Source: CISA urges US orgs to secure Microsoft Intune systems after Stryker breach. CISA is directing organizations to implement Microsoft's guidance for strengthening the Intune endpoint management tool to prevent similar incidents. The attack demonstrates the critical importance of securing cloud-based identity and access management solutions that serve as gateways to enterprise infrastructure.

New Perseus Android Malware Targets User Notes for Credential Theft

Security researchers have identified a new Android malware variant called Perseus that scans user-created notes to extract sensitive information including passwords, cryptocurrency recovery phrases, and financial data. Source: New 'Perseus' Android malware checks user notes for secrets. The malware represents an evolution in mobile threat tactics, exploiting users' common practice of storing sensitive credentials in note-taking applications. This discovery highlights the expanding threat landscape targeting mobile devices and the risks associated with inadequate mobile security practices.

Critical Microsoft SharePoint Vulnerability Now Actively Exploited

A critical vulnerability in Microsoft SharePoint that was patched in January is now being actively exploited in real-world attacks, according to CISA warnings. Source: Critical Microsoft SharePoint flaw now exploited in attacks. Organizations that have not applied the January patches remain at significant risk, as threat actors are actively leveraging this flaw against unpatched systems. The delay between patch release and active exploitation underscores the critical importance of timely vulnerability remediation across enterprise environments.

Cisco Firewall Vulnerability Exploited as Zero-Day in Interlock Ransomware Campaign

Amazon security researchers have uncovered evidence that a Cisco Firewall Management Center software vulnerability has been exploited as a zero-day since late January, with connections traced to Russia-based threat actors. Source: Cisco Firewall Vulnerability Exploited as Zero-Day in Interlock Ransomware Attacks. The vulnerability has been weaponized by the Interlock ransomware group to gain initial access to target networks, demonstrating how critical perimeter security devices remain high-value targets for sophisticated threat actors. Organizations operating Cisco FMC infrastructure should prioritize immediate assessment and remediation efforts.

Organizations face a convergence of threats across multiple attack vectors today, from cloud infrastructure to mobile platforms to network perimeter devices. Immediate action on vulnerability patching, endpoint security hardening, and access control strengthening remains essential to defending against these active threats.

CISA urges US orgs to secure Microsoft Intune systems after Stryker breach

Source: CISA urges US orgs to secure Microsoft Intune systems after Stryker breach

CISA warned U.S. organizations to follow Microsoft guidance to strengthen the Intune endpoint management tool after a cyberattack exploited it to wipe medical technology giant Stryker's systems. [...]

New ‘Perseus’ Android malware checks user notes for secrets

Source: New ‘Perseus’ Android malware checks user notes for secrets

A new Android malware called Perseus is checking user-curated notes to steal sensitive information, like passwords, recovery phrases, or financial data. [...]

Critical Microsoft SharePoint flaw now exploited in attacks

Source: Critical Microsoft SharePoint flaw now exploited in attacks

A critical Microsoft SharePoint vulnerability patched in January is now being exploited in attacks, the Cybersecurity and Infrastructure Security Agency (CISA) warned. [...]

Cisco Firewall Vulnerability Exploited as Zero-Day in Interlock Ransomware Attacks

Source: Cisco Firewall Vulnerability Exploited as Zero-Day in Interlock Ransomware Attacks

Amazon found evidence that the FMC software vulnerability has been exploited since late January, and found links to Russia. The post Cisco Firewall Vulnerability Exploited as Zero-Day in Interlock Ransomware Attacks appeared first on SecurityWeek.

Sources & IOCs

Source articles and extracted indicators (defanged where appropriate).

New ‘Perseus’ Android malware checks user notes for secrets
Malware6
  • Perseus
    Android malware scanning notes for credentials, passwords, recovery phrases, and financial data
  • Klopatra
    Android malware sharing the same dropper as Perseus
  • Medusa
    Android malware sharing the same dropper as Perseus
  • Massiv
    Android banking malware distributed via IPTV app lure in similar campaigns
  • Phoenix
    Codebase used as basis for Perseus development
  • Cerberus
    Original leaked malware code from six years ago, ancestor of Perseus lineage