Weekly review

ThreatNoir Afternoon Brief — March 27

2026-03-27Afternoon4 articles
Audio
Listen to the episode

Afternoon Review in IT Security — March 27, 2026

The threat landscape continues to evolve with nation-state actors refining their capabilities, cybercriminal groups expanding their operations, and critical vulnerabilities emerging across enterprise software and AI frameworks. Today's review covers developments spanning iOS exploits, ransomware campaigns, industrial control systems, and artificial intelligence security.

Coruna iOS Exploit Kit Likely an Update to Operation Triangulation

Security researchers have identified the Coruna iOS exploit kit as a likely successor to Operation Triangulation, containing an updated version of a kernel exploit that was deployed three years ago. The discovery indicates that state-sponsored threat actors continue to iterate on previously successful attack methodologies, maintaining access to sophisticated iOS exploitation techniques. Source: SecurityWeek

The exploit kit leverages vulnerabilities including CVE-2023-32434 and CVE-2023-38606, demonstrating the persistent threat posed by unpatched iOS systems to high-value targets. The continued development and refinement of these tools suggests that Apple users running older or unpatched versions remain at significant risk from advanced persistent threat actors.

Bearlyfy Hits 70+ Russian Firms with Custom GenieLocker Ransomware

The pro-Ukrainian threat group Bearlyfy, also known as Labuji, has been attributed to over 70 cyber attacks targeting Russian companies since emerging in January 2025, with recent campaigns deploying the custom Windows ransomware strain GenieLocker. The group operates with a dual-purpose mandate aimed at inflicting maximum damage on Russian business infrastructure. Source: The Hacker News

Beyond GenieLocker, Bearlyfy has leveraged additional malware families including LockBit 3 (Black), Babuk, PolyVice, and MeshAgent in its operations. The volume and velocity of attacks attributed to this group underscore the growing sophistication of state-aligned cybercriminal operations and the critical importance of robust incident response and backup recovery capabilities for organizations operating in geopolitically sensitive regions.

CISA Flags Critical PTC Vulnerability That Had German Police Mobilized

The Cybersecurity and Infrastructure Security Agency has flagged CVE-2026-4681, a critical vulnerability in PTC Windchill, following an unprecedented response in which German law enforcement physically visited organizations to warn them of the threat. The severity of this vulnerability prompted direct police intervention, highlighting the risk posed to product lifecycle management systems. Source: SecurityWeek

The involvement of German police in vulnerability notification represents an extraordinary escalation in disclosure protocols, underscoring the critical nature of the flaw and its potential impact on industrial and manufacturing sectors that rely heavily on PTC's software solutions. Organizations using PTC Windchill should prioritize patching efforts immediately.

LangChain, LangGraph Flaws Expose Files, Secrets, Databases in Widely Used AI Frameworks

Cybersecurity researchers have disclosed three security vulnerabilities affecting LangChain and LangGraph, popular open-source frameworks used to build large language model-powered applications, that could expose filesystem data, environment secrets, and conversation history if exploited. Source: The Hacker News

The vulnerabilities, tracked as CVE-2026-34070, CVE-2025-68664, CVE-2025-67644, CVE-2026-33017, and CVE-2025-3248, represent a significant supply chain risk given the widespread adoption of these frameworks in enterprise AI development. Organizations leveraging LangChain and LangGraph should audit their implementations for potential exposure of sensitive data and apply security updates as they become available.


Today's threat intelligence reveals the persistence of nation-state actors in refining their exploit capabilities, the growing sophistication of state-aligned cybercriminal operations, the emergence of critical vulnerabilities in specialized industrial software, and the expanding attack surface presented by artificial intelligence frameworks. Security teams should prioritize patching efforts across all identified vulnerabilities while maintaining vigilance for supply chain compromises and advanced persistent threat activity.

Sources & IOCs

Source articles and extracted indicators (defanged where appropriate).

Bearlyfy Hits 70+ Russian Firms with Custom GenieLocker Ransomware
Malware6
  • GenieLocker
    Custom Windows ransomware strain deployed by Bearlyfy since March 2026
  • LockBit 3 (Black)
    Ransomware encryptor leveraged by Bearlyfy in early 2025 attacks
  • MeshAgent
    Remote access tool deployed by Bearlyfy post-compromise for encryption and data destruction
  • PolyVice
    Modified version used by Bearlyfy starting May 2025, attributed to Vice Society
  • Babuk
    Ransomware encryptor leveraged by Bearlyfy in early 2025 attacks
  • Bearlyfy
    Pro-Ukrainian threat actor group, also known as Labuub, targeting Russian firms
LangChain, LangGraph Flaws Expose Files, Secrets, Databases in Widely Used AI Frameworks
CVE5
  • Path traversal in LangChain prompt-loading API (CVSS 7.5)
  • Related vulnerability sharing root cause with CVE-2026-33017, unauthenticated RCE
  • Related critical vulnerability in Langflow (CVSS 9.3) under active exploitation
  • SQL injection in LangGraph SQLite checkpoint implementation (CVSS 7.3)
  • Unsafe deserialization in LangChain leaking API keys and secrets (CVSS 9.3); also known as LangGrinch