- Critical ScreenConnect vulnerability exposing ASP.NET machine keys; CVSS 9.0; allows privilege escalation and session hijacking
ThreatNoir Morning Brief — March 20
Morning Review in IT Security — March 20, 2026
The technology security landscape continues to face significant threats as critical vulnerabilities emerge across multiple platforms and law enforcement takes action against threat actors. Today's review covers developments in remote access security, medical device attacks, cryptocurrency breaches, and e-commerce vulnerabilities that demand immediate attention from security teams.
Critical ScreenConnect Vulnerability Exposes Machine Keys
ScreenConnect has released an update addressing a critical vulnerability that exposed machine keys to unauthorized access. The latest version of the software now includes encrypted storage and management capabilities designed to prevent threat actors from obtaining these sensitive cryptographic materials. Source: Critical ScreenConnect Vulnerability Exposes Machine Keys. The vulnerability, tracked as CVE-2026-3564, represents a significant risk to organizations relying on ScreenConnect for remote management and support operations.
FBI Seizes Handala Data Leak Site After Stryker Cyberattack
Federal law enforcement has successfully seized two websites operated by the Handala hacktivist group following a destructive cyberattack against medical technology company Stryker. The attack resulted in the wiping of approximately 80,000 devices across the organization's infrastructure. Source: FBI seizes Handala data leak site after Stryker cyberattack. The seized domains, handala-hack.to and handala-redwanted.to, had been used by the group to distribute stolen data and communicate with victims.
Bitrefill Attributes Cyberattack to North Korean Lazarus Group
Bitrefill, a cryptocurrency-powered gift card retailer, has attributed a cyberattack that occurred at the beginning of the month to the Bluenoroff group, a North Korean-affiliated threat actor operating under the Lazarus umbrella. Source: Bitrefill blames North Korean Lazarus group for cyberattack. The attribution highlights the continued targeting of cryptocurrency and financial services platforms by state-sponsored threat actors seeking to generate revenue and disrupt digital asset operations.
New PolyShell Vulnerability Threatens Magento E-Commerce Platforms
A newly disclosed vulnerability designated PolyShell affects all Magento Open Source and Adobe Commerce stable version 2 installations, enabling unauthenticated remote code execution and account takeover attacks. Source: New 'PolyShell' flaw allows unauthenticated RCE on Magento e-stores. The flaw represents a critical risk to e-commerce organizations, as attackers can exploit it without authentication to gain complete control over affected systems and compromise customer data.
Security teams across all affected platforms should prioritize patching and mitigation efforts to address these emerging threats before exploitation becomes widespread in the threat landscape.
FBI seizes Handala data leak site after Stryker cyberattack
Source: FBI seizes Handala data leak site after Stryker cyberattack
The FBI has seized two websites used by the Handala hacktivist group after the threat actors conducted a destructive cyberattack on medical technology giant Stryker that wiped approximately 80,000 devices. [...]
Bitrefill blames North Korean Lazarus group for cyberattack
Source: Bitrefill blames North Korean Lazarus group for cyberattack
Crypto-powered gift card store Bitrefill says that the attack it suffered at the beginning of the month was likely perpetrated by North Korean hackers of the Bluenoroff group. [...]
New ‘PolyShell’ flaw allows unauthenticated RCE on Magento e-stores
Source: New ‘PolyShell’ flaw allows unauthenticated RCE on Magento e-stores
A newly disclosed vulnerability dubbed 'PolyShell' affects all Magento Open Source and Adobe Commerce stable version 2 installations, allowing unauthenticated code execution and account takeover. [...]
Sources & IOCs
Source articles and extracted indicators (defanged where appropriate).
- HandalaIranian-linked hacktivist group (also known as Handala Hack Team, Hatef, Hamsa) conducting destructive wiper attacks
handala-redwanted.toHandala hacktivist group data leak site, seized by FBIhandala-hack.toHandala hacktivist group data leak site, seized by FBI
- North Korean state-sponsored threat actor attributed to the Bitrefill attack; focuses on cryptocurrency theft and financial targets
- Bluenoroff malware (unspecified variant)Malware used in the Bitrefill attack; signature matched previous Lazarus campaigns
- Newly disclosed vulnerability affecting Magento Open Source and Adobe Commerce v2