Weekly review

ThreatNoir Morning Brief — March 20

2026-03-20Morning4 articles
Audio
Listen to the episode

Morning Review in IT Security — March 20, 2026

The technology security landscape continues to face significant threats as critical vulnerabilities emerge across multiple platforms and law enforcement takes action against threat actors. Today's review covers developments in remote access security, medical device attacks, cryptocurrency breaches, and e-commerce vulnerabilities that demand immediate attention from security teams.

Critical ScreenConnect Vulnerability Exposes Machine Keys

ScreenConnect has released an update addressing a critical vulnerability that exposed machine keys to unauthorized access. The latest version of the software now includes encrypted storage and management capabilities designed to prevent threat actors from obtaining these sensitive cryptographic materials. Source: Critical ScreenConnect Vulnerability Exposes Machine Keys. The vulnerability, tracked as CVE-2026-3564, represents a significant risk to organizations relying on ScreenConnect for remote management and support operations.

FBI Seizes Handala Data Leak Site After Stryker Cyberattack

Federal law enforcement has successfully seized two websites operated by the Handala hacktivist group following a destructive cyberattack against medical technology company Stryker. The attack resulted in the wiping of approximately 80,000 devices across the organization's infrastructure. Source: FBI seizes Handala data leak site after Stryker cyberattack. The seized domains, handala-hack.to and handala-redwanted.to, had been used by the group to distribute stolen data and communicate with victims.

Bitrefill Attributes Cyberattack to North Korean Lazarus Group

Bitrefill, a cryptocurrency-powered gift card retailer, has attributed a cyberattack that occurred at the beginning of the month to the Bluenoroff group, a North Korean-affiliated threat actor operating under the Lazarus umbrella. Source: Bitrefill blames North Korean Lazarus group for cyberattack. The attribution highlights the continued targeting of cryptocurrency and financial services platforms by state-sponsored threat actors seeking to generate revenue and disrupt digital asset operations.

New PolyShell Vulnerability Threatens Magento E-Commerce Platforms

A newly disclosed vulnerability designated PolyShell affects all Magento Open Source and Adobe Commerce stable version 2 installations, enabling unauthenticated remote code execution and account takeover attacks. Source: New 'PolyShell' flaw allows unauthenticated RCE on Magento e-stores. The flaw represents a critical risk to e-commerce organizations, as attackers can exploit it without authentication to gain complete control over affected systems and compromise customer data.

Security teams across all affected platforms should prioritize patching and mitigation efforts to address these emerging threats before exploitation becomes widespread in the threat landscape.

FBI seizes Handala data leak site after Stryker cyberattack

Source: FBI seizes Handala data leak site after Stryker cyberattack

The FBI has seized two websites used by the Handala hacktivist group after the threat actors conducted a destructive cyberattack on medical technology giant Stryker that wiped approximately 80,000 devices. [...]

Bitrefill blames North Korean Lazarus group for cyberattack

Source: Bitrefill blames North Korean Lazarus group for cyberattack

Crypto-powered gift card store Bitrefill says that the attack it suffered at the beginning of the month was likely perpetrated by North Korean hackers of the Bluenoroff group. [...]

New ‘PolyShell’ flaw allows unauthenticated RCE on Magento e-stores

Source: New ‘PolyShell’ flaw allows unauthenticated RCE on Magento e-stores

A newly disclosed vulnerability dubbed 'PolyShell' affects all Magento Open Source and Adobe Commerce stable version 2 installations, allowing unauthenticated code execution and account takeover. [...]

Sources & IOCs

Source articles and extracted indicators (defanged where appropriate).

FBI seizes Handala data leak site after Stryker cyberattack
Malware1
  • Handala
    Iranian-linked hacktivist group (also known as Handala Hack Team, Hatef, Hamsa) conducting destructive wiper attacks
Domain2
  • handala-redwanted.to
    Handala hacktivist group data leak site, seized by FBI
  • handala-hack.to
    Handala hacktivist group data leak site, seized by FBI