Summary & highlights
CVE-2026-21262: Microsoft SQL Server Elevation of Privilege via Improper Access Control in Merge Replication. Malicious Packagist Packages Deliver Cross-Platform PHP RAT via Fake Laravel Utilities (nhattuanbl Campaign). Storm-2561 SEO Poisoning Campaign Distributing Fake Ivanti VPN Clients for Credential Theft.
Highlights
- TL-2026-0216 — CVE-2026-21262: Microsoft SQL Server Elevation of Privilege via Improper Access Control in Merge Replication
- TL-2026-0217 — Malicious Packagist Packages Deliver Cross-Platform PHP RAT via Fake Laravel Utilities (nhattuanbl Campaign)
- TL-2026-0218 — Storm-2561 SEO Poisoning Campaign Distributing Fake Ivanti VPN Clients for Credential Theft
- TL-2026-0219 — Mustang Panda Deploys PlugX RAT via Multi-Stage CHM Sideloading Campaign Targeting Persian Gulf Region (March 2026)
- TL-2026-0214 — Lotus Blossom APT Supply Chain Compromise of Notepad++ Update Infrastructure (CVE-2025-15556)
Theme of the day
Iranian MOIS operations led the day as Void Manticore and MuddyWater ran wiper and cybercrime campaigns, joined by Lotus Blossom's Notepad++ supply-chain compromise, Mustang Panda PlugX, malicious Packagist packages, and Storm-2561 SEO poisoning.
- data-exfiltration
- credential-theft
- lateral-movement
- espionage
- active-exploitation
Threats published
47 threat lines in the 2026-03-12 debrief, most severe first; entries marked (update) revise an earlier report. Each links to its full profile.
- Lotus Blossom APT Supply Chain Compromise of Notepad++ Update Infrastructure (CVE-2025-15556)CRITICAL
- Iranian MOIS Actors Leveraging Cybercrime Ecosystem — Void Manticore & MuddyWater CampaignCRITICAL
- Handala Hack (Void Manticore) Wiper Campaign via Microsoft Intune Abuse — Stryker AttackCRITICAL
- Coruna iOS Exploit Kit — Government-Grade 23-Exploit Arsenal Proliferates from Surveillance Vendor to Russian Espionage and Chinese Cybercriminals Targeting 42K+ Devices (update)CRITICAL
- Microsoft MSHTML Remote Code Execution Zero-Day (CVE-2026-21513) (update)CRITICAL
- Seedworm (MuddyWater) Iranian MOIS APT Campaign Targeting U.S. Critical Infrastructure with Dindoor and Fakeset Backdoors (update)CRITICAL
- Android Exploit Chain — Saito Tech Commercial Spyware: ART Runtime RCE, Binder UAF LPE, Pixel Bootloader Persistence (CVE-2026-22104, CVE-2026-22107, CVE-2026-22112) (update)CRITICAL
- VMware Aria Operations Unauthenticated Command Injection RCE (CVE-2026-22719) (update)CRITICAL
- Qualcomm Adreno GPU KGSL Integer Overflow Memory Corruption Zero-Day (CVE-2026-21385) (update)CRITICAL
- CISA KEV: Hikvision Camera Auth Bypass (CVE-2017-7921) & Rockwell Logix Credential Exposure (CVE-2021-22681) — Active Exploitation (update)CRITICAL
- Iranian-Aligned Cyber Mobilization — 60+ Groups Targeting US Critical Infrastructure ICS/SCADA with AI-Assisted Reconnaissance Post Iran-US Escalation (Feb 28, 2026) (update)CRITICAL
- Cisco Catalyst SD-WAN Manager Active Exploitation — Arbitrary File Overwrite and Credential Exposure (CVE-2026-20122, CVE-2026-20128) (update)CRITICAL
- Coruna iOS Exploit Kit — 23 Exploits Across 5 Chains Targeting iOS 13-17.2.1 (CVE-2021-30952, CVE-2023-41974, CVE-2023-43000 + 20 More) (update)CRITICAL
- BeyondTrust Remote Support & PRA Pre-Authentication Remote Code Execution via OS Command Injection (CVE-2026-1731) (update)CRITICAL
- Dell RecoverPoint Hardcoded Credentials RCE + UNC6201 GRIMBOLT Backdoor (CVE-2026-22769) (update)CRITICAL
- UNC2814 GRIDTIDE Backdoor — China-Nexus Telecom & Government Espionage Campaign Exploiting Google Sheets API for C2 (update)CRITICAL
- Iranian APT MuddyWater (Seedworm) Deploys Novel Dindoor & Fakeset Backdoors Against U.S. Critical Infrastructure (update)CRITICAL
- INC Ransom Affiliate Network Targeting Pacific Critical Infrastructure (AU/NZ/Tonga Joint Advisory) (update)CRITICAL
- Ivanti Endpoint Manager Pre-Auth Credential Leak via Authentication Bypass (CVE-2026-1603) (update)CRITICAL
- Omnissa Workspace ONE UEM Pre-Auth SSRF Active Exploitation (CVE-2021-22054) (update)CRITICAL
- UNC4899/Jade Sleet Cryptocurrency Exchange Breach via AirDrop Trojanization and Cloud Infrastructure Compromise (update)CRITICAL
- FortiGate SSO Authentication Bypass Campaign (CVE-2025-59718, CVE-2025-59719, CVE-2026-24858) (update)CRITICAL
- Microsoft Office Preview Pane Remote Code Execution — CVE-2026-26110 (Type Confusion) & CVE-2026-26113 (Untrusted Pointer Dereference) (update)CRITICAL
- GIBCRYPTO Destructive Ransomware with Snake Keylogger Shared Telegram C2 Infrastructure (update)CRITICAL
- Microsoft Office RCE via Preview Pane (CVE-2026-26110, CVE-2026-26113) — March 2026 Patch Tuesday (update)CRITICAL
- CVE-2026-21262: Microsoft SQL Server Elevation of Privilege via Improper Access Control in Merge ReplicationHIGH
- Malicious Packagist Packages Deliver Cross-Platform PHP RAT via Fake Laravel Utilities (nhattuanbl Campaign)HIGH
- Storm-2561 SEO Poisoning Campaign Distributing Fake Ivanti VPN Clients for Credential TheftHIGH
- Mustang Panda Deploys PlugX RAT via Multi-Stage CHM Sideloading Campaign Targeting Persian Gulf Region (March 2026)HIGH
- XWorm v6.4 Delivery Campaign — Obfuscated JavaScript/PowerShell Loaders with ProcessHollowing DLL Injection (March 2026) (update)HIGH
- Fake OpenClaw Installers Distributed via Bing Search Poisoning and Malicious GitHub Repos Deploy Infostealers and GhostSocks Proxy Malware (update)HIGH
- Mustang Panda LOTUSLITE Backdoor & StealC Campaigns Exploiting Middle East Conflict Themes (update)HIGH
- CL-UNK-1068: China-Nexus APT Targeting Critical Infrastructure via DLL Sideloading, Xnote Backdoor, ScanPortPlus Scanner, and FRP Tunneling (update)HIGH
- APT28 (Fancy Bear) Deploys BadPaw Loader and MeowMeow Backdoor Targeting Ukrainian Critical Infrastructure (update)HIGH
- Transparent Tribe (APT36) AI-Assisted Vibeware Campaign — 14+ Malware Families Across 6+ C2 Channels (update)HIGH
- Fake Laravel Packages on Packagist Deploy Cross-Platform RAT via Supply Chain Compromise (update)HIGH
- UAT-9244 (China-Nexus FamousSparrow Cluster) — TernDoor Backdoor, PeerTime BitTorrent C2 Linux Implant, and BruteEntry ORB Scanner Targeting South American Telecom (update)HIGH
- Trojanized Red Alert Rocket Warning App — Arid Viper Mobile Spyware Campaign Targeting Israeli Users (update)HIGH
- VOID#GEIST Multi-RAT Campaign — Early Bird APC Injection Delivering XWorm, AsyncRAT, and Xeno RAT via Python Runtime (update)HIGH
- HoneyMyte (Mustang Panda) CoolClient Backdoor Update with Browser Data Stealers Targeting Southeast Asian Government and Military (update)HIGH
- Chrome Extension Supply Chain Attack — QuickLens/ShotBird Ownership Transfer Hijack (CVE-less) (update)HIGH
- APT28 (Fancy Bear) BEARDSHELL Backdoor & COVENANT C2 Framework — Long-term Ukrainian Military Espionage Campaign (CVE-2026-21509) (update)HIGH
- KadNap P2P Botnet — 14,000+ Asus Routers Compromised via Custom Kademlia DHT C2 (update)HIGH
- BoryptGrab GitHub Supply Chain Malware Campaign — 100+ Malicious Repositories Distributing Multi-Stage Stealer (update)HIGH
- KongTuke ClickFix Campaign — ModeloRAT Deployment via Compromised WordPress Sites and CrashFix Browser Extension (update)HIGH
- KadNap Botnet Targeting Asus Routers via Kademlia DHT C2 for Doppelganger Proxy Network (update)HIGH
- Contagious Interview: DPRK Campaign Delivers OtterCookie and FlexibleFerret Backdoors via Fake Developer Job Interviews (update)HIGH
Techniques observed
214 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.
- T0831
- T0875
- T0879
- T0889
- T1001
- T1003
- T1005
- T1008
- T1012
- T1014
- T1016
- T1018
- T1020
- T1021
- T1021.002
- T1021.004
- T1027
- T1027.013
- T1033
- T1036
- T1036.005
- T1037
- T1040
- T1041
- T1046
- T1047
- T1048
- T1048.003
- T1049
- T1053
- T1053.005
- T1055
- T1055.004
- T1056
- T1056.001
- T1057
- T1059
- T1059.001
- T1059.003
- T1059.004
- T1059.005
- T1059.006
- T1059.007
- T1068
- T1069
- T1070
- T1070.004
- T1070.006
- T1071
- T1071.001
- T1071.004
- T1072
- T1074
- T1078
- T1078.002
- T1082
- T1083
- T1087
- T1087.002
- T1090
- T1090.001
- T1091
- T1095
- T1098
- T1102
- T1102.002
- T1104
- T1105
- T1106
- T1110
- T1110.001
- T1112
- T1113
- T1114
- T1115
- T1119
- T1120
- T1123
- T1125
- T1129
- T1132
- T1133
- T1134
- T1135
- T1136
- T1136.001
- T1136.002
- T1137
- T1140
- T1176
- T1185
- T1187
- T1189
- T1190
- T1195
- T1195.002
- T1199
- T1202
- T1203
- T1204
- T1204.002
- T1205
- T1210
- T1211
- T1212
- T1213
- T1218
- T1219
- T1406
- T1407
- T1417
- T1418
- T1426
- T1430
- T1437
- T1480
- T1482
- T1484
- T1485
- T1486
- T1489
- T1490
- T1491
- T1496
- T1497
- T1497.001
- T1498
- T1499
- T1505
- T1505.003
- T1518
- T1518.001
- T1528
- T1529
- T1530
- T1531
- T1533
- T1537
- T1539
- T1542
- T1543
- T1546
- T1547
- T1547.001
- T1548
- T1548.002
- T1550
- T1552
- T1552.001
- T1553
- T1553.002
- T1553.006
- T1554
- T1555
- T1555.003
- T1557
- T1558
- T1560
- T1561
- T1561.002
- T1562
- T1562.001
- T1562.002
- T1564
- T1564.003
- T1565
- T1566
- T1566.001
- T1566.002
- T1567
- T1568
- T1569
- T1570
- T1571
- T1572
- T1573
- T1573.001
- T1574
- T1574.002
- T1580
- T1583
- T1583.001
- T1583.003
- T1584
- T1585
- T1587
- T1587.001
- T1587.004
- T1588
- T1588.003
- T1588.005
- T1589
- T1590
- T1592
- T1593
- T1595
- T1596
- T1598
- T1599
- T1608
- T1608.006
- T1611
- T1613
- T1620
- T1622
- T1624
- T1630
- T1632
- T1636
- T1646
- T1655
- T1656
- T1657
- T1660
Threat actors
26 named threat actors across the reports.
- nhattuanbl
- Storm-2561
- Mustang Panda (medium confidence)
- Lotus Blossom / Spring Dragon
- Void Manticore / MuddyWater (MOIS)
- Handala Hack / Void Manticore
- Mustang Panda / Earth Preta
- CL-UNK-1068
- APT28 / Fancy Bear
- APT36 / Transparent Tribe
- UAT-9244 / FamousSparrow
- Arid Viper / APT-C-23
- HoneyMyte / Mustang Panda
- APT28 / Fancy Bear / Sednit
- KongTuke / TAG-124
- Famous Chollima / Tenacious Pungsan / DEV#POPPER
- APT29 / Midnight Blizzard (IRON TWILIGHT cluster)
- Seedworm / MuddyWater
- Saito Tech (Candiru)
- CyberAv3ngers / APT33 / MuddyWater / APT34 / Handala Hack Team / APT35
- UNC6353 / UNC6691
- UNC6201
- UNC2814 / Gallium
- MuddyWater / Seedworm
- INC Ransom / GOLD IONIC
- UNC4899 / Jade Sleet
Nation-state attribution
- China
- Iran
- Russia
- Pakistan
- Palestine
- North Korea
- Israel
- Russia / China
Threat categories
- VULNERABILITY
- SUPPLY_CHAIN
- MALWARE
- APT
- ZERO_DAY
- ICS_SCADA
- RANSOMWARE
Severity breakdown
- critical25
- high22
- medium0
- low0
Indicator & detection coverage
Counts only: the indicator values and detection rule text behind them are tiered.
- file 416
- network 364
- behavioral 235
- malware 93
- infrastructure 67
- tool 48
- entity 13
- package 11
- technique 8