Weekly review

ThreatNoir Morning Brief — March 22

2026-03-22Morning4 articles
Audio
Listen to the episode

Morning Review in IT Security — March 22, 2026

The cybersecurity landscape continues to face significant threats as March progresses, with supply-chain attacks, critical firewall vulnerabilities, and data breaches dominating the threat landscape. Today's review covers a compromised vulnerability scanner, FortiGate firewall exploits, a major hospitality data breach, and an emerging Magento exploit being sold on dark web markets.

Trivy Vulnerability Scanner Compromised in Supply-Chain Attack

Threat actors known as TeamPCP have successfully compromised the Trivy vulnerability scanner in a sophisticated supply-chain attack that distributed credential-stealing malware through official releases and GitHub Actions. The attack leveraged malware variants including TeamPCP Cloud Stealer and CanisterWorm to target users of this widely-used security tool. The compromise demonstrates how attackers are increasingly targeting development and security infrastructure to gain access to downstream victims. Source: Trivy vulnerability scanner breach pushed infostealer via GitHub Actions

FortiGate Next-Generation Firewall Compromises Escalate

Throughout early 2026, digital forensics and incident response teams have been tracking a wave of FortiGate NGFW compromises where attackers have exploited vulnerabilities to turn the network's protective firewall into a backdoor for unauthorized access. This trend highlights the critical risk when perimeter security appliances become entry points for threat actors rather than barriers against them. Source: In case you missed it: What happens when the FortiGate next-generation firewall protecting your network becomes the backdoor?

Preferred Hotels & Resorts Data Breach Impacts 450,000 Guests

A threat actor is allegedly selling 450,000 hotel reservations extracted from Preferred Hotels & Resorts' Central Reservation System, affecting approximately 620 luxury hotels worldwide. The compromised data reportedly includes hotel names, guest names, confirmation numbers, and check-in dates, exposing sensitive information for a significant portion of the hospitality chain's customer base. This breach underscores the ongoing vulnerability of centralized reservation systems to cyber attacks. Source: A threat actor is allegedly selling 450,000 reservations extracted from Preferred Hotels & Resorts

Magento 2 Zero-Day Exploit Available on Dark Web Markets

A threat actor is actively selling an unpatched Magento 2 zero-day or one-day exploit with no CVE assignment, enabling unauthenticated file uploads on versions up to 2.4.9-alpha2. The exploit is being offered at a price of $30,000 with only two copies available for purchase, suggesting limited initial distribution but significant risk for affected e-commerce platforms. Source: A threat actor is allegedly selling a Magento 2 0-day/1-day exploit with no CVE assigned yet

As the security community faces these interconnected threats spanning development tools, network infrastructure, hospitality services, and e-commerce platforms, organizations must prioritize rapid vulnerability assessment, supply-chain verification, and incident response readiness to mitigate exposure.

Sources & IOCs

Source articles and extracted indicators (defanged where appropriate).

Trivy vulnerability scanner breach pushed infostealer via GitHub Actions
MITRE ATT&CK3
  • Boot or Logon Initialization Scripts; persistence via systemd user service (sysmon.py)
  • Data from Local System; credential harvesting from environment variables and config files
  • Input Capture; scanning GitHub Actions Runner process memory for secrets
Malware2
  • CanisterWorm
    Self-propagating worm targeting npm packages in follow-up campaign by same threat actor
  • TeamPCP Cloud Stealer
    Infostealer payload embedded in trojanized Trivy binary and GitHub Actions; self-identified in Python comment
Domain1
  • scan.aquasecurtiy[.]org
    Malicious C2 server used for exfiltrating stolen credentials and secrets