Weekly review

ThreatNoir Afternoon Brief — March 21

2026-03-21Afternoon4 articles
Audio
Listen to the episode

Afternoon Review in IT Security — March 21, 2026

The threat landscape continues to intensify as critical vulnerabilities emerge across enterprise infrastructure, supply chain attacks proliferate through open-source ecosystems, and operational disruptions cascade through critical services. Today's security briefing highlights several urgent developments requiring immediate attention from security teams.

Critical Quest KACE Vulnerability Potentially Exploited in Attacks

A critical vulnerability in Quest KACE has been identified as CVE-2025-32975 and may have already been exploited in attacks targeting the education sector. The vulnerability is one of several tracked identifiers including CVE-2025-32976, CVE-2025-32977, and CVE-2025-32978 that require immediate remediation. Source: Critical Quest KACE Vulnerability Potentially Exploited in Attacks

Organizations relying on Quest KACE infrastructure should prioritize patching efforts and conduct forensic analysis to determine whether their systems have been compromised. The active exploitation in the education sector suggests attackers are actively targeting this vulnerability in production environments.

Oracle Patches Critical CVE-2026-21992 Enabling Unauthenticated RCE in Identity Manager

Oracle has released security updates addressing a critical vulnerability in Identity Manager and Web Services Manager tracked as CVE-2026-21992, which carries a CVSS score of 9.8. The vulnerability is remotely exploitable without authentication and could enable attackers to achieve remote code execution. Additionally, CVE-2025-61757 has been addressed in the same update cycle. Source: Oracle Patches Critical CVE-2026-21992 Enabling Unauthenticated RCE in Identity Manager

The unauthenticated nature of this vulnerability represents an exceptional risk to organizations operating Oracle Identity Manager in internet-facing or otherwise exposed environments. Immediate patching is strongly recommended given the severity rating and the absence of authentication requirements for exploitation.

Trivy Supply Chain Attack Triggers Self-Spreading CanisterWorm Across 47 npm Packages

Following the initial compromise of the Trivy scanner, threat actors have conducted follow-on attacks resulting in the compromise of 47 npm packages with a previously undocumented self-propagating worm designated CanisterWorm. The malware leverages ICP canisters and is associated with additional malware families including sysmon.py and entities tracked as TeamPCP. Source: Trivy Supply Chain Attack Triggers Self-Spreading CanisterWorm Across 47 npm Packages

The self-propagating nature of CanisterWorm represents a significant escalation in supply chain attack sophistication, as the malware can autonomously spread across dependent packages within the npm ecosystem. Organizations should audit their npm dependencies and implement heightened monitoring for suspicious package behavior and network communications to external command and control infrastructure.

Cyberattack on a Car Breathalyzer Firm Leaves Drivers Stuck

A cyberattack on a car breathalyzer firm has disrupted service availability for drivers, contributing to a broader week of significant security incidents. The week's threat landscape also includes FBI acknowledgment of purchasing phone data to track Americans, Iranian-linked attacks disrupting medical care at Maryland hospitals, and the emergence of multiple botnet families including Aisuru, Kimwolf, JackSkid, and Mossad. Additional malware families such as DarkSword and Handala have been identified in concurrent threat activity. Source: Cyberattack on a Car Breathalyzer Firm Leaves Drivers Stuck

The operational disruption to critical automotive services demonstrates the cascading impact of targeted attacks on specialized infrastructure providers. The concurrent emergence of multiple botnet families and state-sponsored activity targeting healthcare systems underscores the sustained pressure across both commercial and critical infrastructure sectors.

Security teams should prioritize patching of identified vulnerabilities, conduct supply chain audits of open-source dependencies, and enhance monitoring for indicators of compromise associated with the identified malware families and threat actors.

Sources & IOCs

Source articles and extracted indicators (defanged where appropriate).

Critical Quest KACE Vulnerability Potentially Exploited in Attacks
CVE4
  • Related Quest KACE SMA vulnerability patched May 2025; no evidence of exploitation in observed incidents
  • Related Quest KACE SMA vulnerability patched May 2025; no evidence of exploitation in observed incidents
  • Critical authentication bypass in Quest KACE SMA allowing unauthenticated user impersonation and administrative takeover; actively exploited in attacks
  • Related Quest KACE SMA vulnerability patched May 2025; no evidence of exploitation in observed incidents
Cyberattack on a Car Breathalyzer Firm Leaves Drivers Stuck
Malware6
  • DarkSword
    Russian hacker tool used to steal victims' data from iPhones; hundreds of millions vulnerable
  • Aisuru botnet
    Botnet taken down by US law enforcement; infected 3M+ devices globally
  • Kimwolf botnet
    Botnet taken down by US law enforcement; infected 3M+ devices globally
  • JackSkid botnet
    Botnet taken down by US law enforcement; infected 3M+ devices globally
  • Mossad botnet
    Botnet taken down by US law enforcement; infected 3M+ devices globally
  • Handala
    Iranian-linked hacking group that conducted cyberattack on Stryker medical technology firm in early March, disrupting emergency care at Maryland hospitals