- Related Quest KACE SMA vulnerability patched May 2025; no evidence of exploitation in observed incidents
- Related Quest KACE SMA vulnerability patched May 2025; no evidence of exploitation in observed incidents
- Critical authentication bypass in Quest KACE SMA allowing unauthenticated user impersonation and administrative takeover; actively exploited in attacks
- Related Quest KACE SMA vulnerability patched May 2025; no evidence of exploitation in observed incidents
ThreatNoir Afternoon Brief — March 21
Afternoon Review in IT Security — March 21, 2026
The threat landscape continues to intensify as critical vulnerabilities emerge across enterprise infrastructure, supply chain attacks proliferate through open-source ecosystems, and operational disruptions cascade through critical services. Today's security briefing highlights several urgent developments requiring immediate attention from security teams.
Critical Quest KACE Vulnerability Potentially Exploited in Attacks
A critical vulnerability in Quest KACE has been identified as CVE-2025-32975 and may have already been exploited in attacks targeting the education sector. The vulnerability is one of several tracked identifiers including CVE-2025-32976, CVE-2025-32977, and CVE-2025-32978 that require immediate remediation. Source: Critical Quest KACE Vulnerability Potentially Exploited in Attacks
Organizations relying on Quest KACE infrastructure should prioritize patching efforts and conduct forensic analysis to determine whether their systems have been compromised. The active exploitation in the education sector suggests attackers are actively targeting this vulnerability in production environments.
Oracle Patches Critical CVE-2026-21992 Enabling Unauthenticated RCE in Identity Manager
Oracle has released security updates addressing a critical vulnerability in Identity Manager and Web Services Manager tracked as CVE-2026-21992, which carries a CVSS score of 9.8. The vulnerability is remotely exploitable without authentication and could enable attackers to achieve remote code execution. Additionally, CVE-2025-61757 has been addressed in the same update cycle. Source: Oracle Patches Critical CVE-2026-21992 Enabling Unauthenticated RCE in Identity Manager
The unauthenticated nature of this vulnerability represents an exceptional risk to organizations operating Oracle Identity Manager in internet-facing or otherwise exposed environments. Immediate patching is strongly recommended given the severity rating and the absence of authentication requirements for exploitation.
Trivy Supply Chain Attack Triggers Self-Spreading CanisterWorm Across 47 npm Packages
Following the initial compromise of the Trivy scanner, threat actors have conducted follow-on attacks resulting in the compromise of 47 npm packages with a previously undocumented self-propagating worm designated CanisterWorm. The malware leverages ICP canisters and is associated with additional malware families including sysmon.py and entities tracked as TeamPCP. Source: Trivy Supply Chain Attack Triggers Self-Spreading CanisterWorm Across 47 npm Packages
The self-propagating nature of CanisterWorm represents a significant escalation in supply chain attack sophistication, as the malware can autonomously spread across dependent packages within the npm ecosystem. Organizations should audit their npm dependencies and implement heightened monitoring for suspicious package behavior and network communications to external command and control infrastructure.
Cyberattack on a Car Breathalyzer Firm Leaves Drivers Stuck
A cyberattack on a car breathalyzer firm has disrupted service availability for drivers, contributing to a broader week of significant security incidents. The week's threat landscape also includes FBI acknowledgment of purchasing phone data to track Americans, Iranian-linked attacks disrupting medical care at Maryland hospitals, and the emergence of multiple botnet families including Aisuru, Kimwolf, JackSkid, and Mossad. Additional malware families such as DarkSword and Handala have been identified in concurrent threat activity. Source: Cyberattack on a Car Breathalyzer Firm Leaves Drivers Stuck
The operational disruption to critical automotive services demonstrates the cascading impact of targeted attacks on specialized infrastructure providers. The concurrent emergence of multiple botnet families and state-sponsored activity targeting healthcare systems underscores the sustained pressure across both commercial and critical infrastructure sectors.
Security teams should prioritize patching of identified vulnerabilities, conduct supply chain audits of open-source dependencies, and enhance monitoring for indicators of compromise associated with the identified malware families and threat actors.
Sources & IOCs
Source articles and extracted indicators (defanged where appropriate).
- Related pre-authenticated RCE in Oracle Identity Manager, actively exploited, tracked in CISA KEV catalog
- Critical unauthenticated RCE in Oracle Identity Manager and Web Services Manager (CVSS 9.8)
- CanisterWormSelf-spreading npm worm using ICP canister for C2 resolution
- TeamPCPCloud-focused cybercriminal operation suspected behind Trivy and CanisterWorm attacks
- sysmon.pyPython dropper in trojanized Trivy binary v0.69.4
youtube.comKill switch domain used by CanisterWorm; C2 redirects here to disable payload
- DarkSwordRussian hacker tool used to steal victims' data from iPhones; hundreds of millions vulnerable
- Aisuru botnetBotnet taken down by US law enforcement; infected 3M+ devices globally
- Kimwolf botnetBotnet taken down by US law enforcement; infected 3M+ devices globally
- JackSkid botnetBotnet taken down by US law enforcement; infected 3M+ devices globally
- Mossad botnetBotnet taken down by US law enforcement; infected 3M+ devices globally
- HandalaIranian-linked hacking group that conducted cyberattack on Stryker medical technology firm in early March, disrupting emergency care at Maryland hospitals