Daily Drop (1260)
03-15-26
Sunday, Mar 15, 2025 // (IG): BB // Ghostwire
Ghostwire: Daily Briefing
Headline Threat:
GlassWorm Supply-Chain Campaign Compromises 72 Open VSX Extensions
Researchers have flagged a significant escalation in the GlassWorm campaign, which has now weaponized 72 extensions in the Open VSX registry — the primary extension marketplace for VS Code-compatible editors widely used across enterprise and open-source development environments. Unlike prior iterations that targeted individual packages, this wave appears to systematically abuse the registry’s trust model, meaning developers pulling routine updates may be silently infected. Any organization with developers using Open VSX-sourced extensions should treat all recent extension updates as suspect until integrity verification is confirmed. (THN)
Key Developments:
Stryker Hit by Ransomware, Global Operations Disrupted
Michigan-based medical device giant Stryker confirmed a cyberattack causing global network disruption, with manufacturing and shipping operations materially impacted. Attacks on medical device manufacturers carry compounded risk — not just operational and financial damage, but potential downstream effects on hospital supply chains and patient care continuity. This follows a well-established threat actor playbook of targeting high-revenue, operationally time-sensitive manufacturers to maximize ransom leverage.
INTERPOL-Led Operation Seizes 45,000 Malicious IPs
Global authorities coordinated a takedown of 45,000 IPs linked to ransomware and phishing infrastructure in what appears to be one of the largest single-operation IP seizures on record. While takedowns of this scale are operationally significant, threat actors historically reconstitute infrastructure within weeks using bulletproof hosting and fast-flux DNS. The immediate benefit is measurable disruption to active campaigns; the strategic benefit depends on whether arrests and attribution followed the infrastructure seizure. (GBhackers)
North Korea Nets $800M in Crypto — Treasury Responds with Sanctions
The U.S. Treasury Department imposed sanctions on a network facilitating North Korean cryptocurrency laundering tied to an $800 million operation. DPRK cyber units — primarily Lazarus Group and affiliated cells — continue to fund the regime’s weapons programs through crypto theft and laundering at industrial scale. Organizations in the DeFi, exchange, and Web3 space should treat this as a persistent and escalating threat requiring dedicated threat modeling, not routine compliance posture. (multiple)
McKinsey Breach: 46.5 Million Employee Chat Records Exposed
Hackers reportedly gained access to 46.5 million employee chat records from McKinsey, exposing the acute risk of rapid enterprise AI tool adoption without adequate access controls or data segmentation. The breach underscores a pattern emerging across large enterprises: AI-integrated collaboration platforms aggregate sensitive communications at scale, creating high-value targets that legacy DLP architectures were never designed to protect. Expect this class of breach to multiply as AI chat tooling becomes standard enterprise infrastructure. (Google News)
Loblaw Data Breach Exposes Customer and IT Network Data
Canada’s largest retailer, Loblaw Companies Limited, disclosed unauthorized access to portions of its internal IT network and customer data. Retail sector breaches of this scale typically involve payment data, loyalty program credentials, and PII — all of which have established underground market value. Canadian organizations should note that this breach may trigger obligations under PIPEDA and provincial privacy statutes, and regulators are likely to scrutinize incident response timelines carefully. (CyberPress)
Iran-Linked Groups Expand Cyber Operations Amid Kinetic Escalation
As Iran launches its 49th wave of kinetic strikes — drawing significant public attention — Iran-linked cyber threat groups are simultaneously expanding targeting of Australian infrastructure, leveraging Australia’s visible support role for U.S. operations as justification. This mirrors documented Iranian doctrine of pairing kinetic escalation with cyber harassment campaigns against perceived coalition partners. Australian critical infrastructure operators and government agencies should elevate monitoring posture immediately, particularly for OT/ICS-adjacent networks. (Weibo, China Cyber/Google News)
---
CVE Watch
CVE-2025-54920 — Apache Spark History Server: Remote Code Execution
Severity: Critical (RCE class)
Affects Apache Spark versions prior to 3.5.7 and 4.0.1. The History Server component is frequently exposed internally and sometimes externally in data engineering environments.
Action: Patch immediately to 3.5.7 or 4.0.1. Audit exposure of Spark History Server interfaces to internal and external networks. This class of vulnerability in data platform tooling is a high-value target for threat actors seeking lateral movement into data lakes and analytics infrastructure.
CVE-2026-25750 — LangSmith: Complete Account Takeover
Severity: Critical
A critical vulnerability in LangSmith, widely used by enterprises to monitor LLM applications, enables full account takeover. Given LangSmith’s visibility into AI model inputs and outputs — which frequently include sensitive business data — full account compromise is a high-impact event.
Action: Apply vendor patches immediately. Audit API key exposure and review access logs for anomalous activity since the disclosure window.
Coruna Exploit Chain — Multiple iOS/WebKit Vulnerabilities Enabling Device Compromise
Severity: Critical
Apple released iOS 15.8.7 / iPadOS 15.8.7 to address a chain of vulnerabilities in WebKit and the iOS Kernel that can be exploited by the Coruna exploit kit. Attackers can lure victims to malicious websites where WebKit memory corruption flaws trigger code execution, escape the browser sandbox, and leverage a kernel privilege escalation bug to gain full control of the device. Successful exploitation could enable spyware installation, activity monitoring, and persistent device access.
Action: Install iOS 15.8.7 or iPadOS 15.8.7 immediately on affected legacy devices. Restrict browsing from unpatched devices, monitor for suspicious mobile activity, and consider enforcing device lifecycle policies for unsupported hardware.
---
Outlook:
The convergence of AI-accelerated attack tooling (confirmed by Microsoft’s own warning issued this week), active nation-state operations from Iran and North Korea, and high-profile ransomware against critical manufacturers signals that March 2026 represents a sustained high-tempo threat period — not an anomalous spike. The LangSmith and McKinsey incidents together indicate that AI observability and collaboration platforms are emerging as the next major attack surface class. Immediate recommendation: conduct an emergency audit of all third-party AI-integrated platforms in your environment — identify what data they can access, who has administrative credentials, and whether MFA is enforced on all privileged accounts.
NEWS:
U.S. House Energy and Commerce Committee Move to Reinforce Cybersecurity for Rural Electric Utilities
Bottom Line Up Front (BLUF): The U.S. House Energy and Commerce Committee has advanced bipartisan legislation to reauthorize and expand a federal cybersecurity program supporting rural electric utilities. The proposal includes $250 million in grants over five years to help under-resourced cooperatives defend against growing cyber threats, particularly those linked to nation-state actors targeting the U.S. power grid.
Analyst Comments: Rural utilities remain one of the softest targets in U.S. critical infrastructure. Many electric cooperatives operate with extremely small IT teams—sometimes just one or two personnel—yet manage systems tied directly into regional grid reliability. That imbalance makes them attractive targets for both nation-state reconnaissance and disruptive attacks. The legislation is partly a response to persistent warnings about Chinese-linked activity such as Volt Typhoon, which has been associated with long-term access attempts inside U.S. infrastructure networks. While the program doesn’t eliminate the underlying risk, grant funding can help smaller utilities deploy modern monitoring, segmentation, and incident response capabilities that larger utilities already maintain.
READ THE STORY: ET
Congress Urged to Establish Legal Guardrails for Cross-Border Drone Operations
Bottom Line Up Front (BLUF): A new policy analysis warns that expanding U.S. drone surveillance operations near the U.S.–Mexico border—particularly those targeting drug cartels—are outpacing the legal framework governing them. Experts argue Congress must clarify authorities, oversight, and due process rules before routine drone operations evolve into precedent that could trigger sovereignty disputes, legal challenges, or escalation.
Analyst Comments: Drone-enabled ISR has quietly become routine infrastructure for U.S. border and counter-narcotics operations, but the legal authorities behind those missions are fragmented. CIA surveillance programs operate under Title 50 intelligence authorities, while CBP’s MQ-9 Predator B missions fall under Title 6 and Title 19 law-enforcement authorities. From a platform standpoint the aircraft look identical, but the legal frameworks, oversight mechanisms, and reporting requirements are fundamentally different. That disconnect creates oversight gaps. Congress currently lacks a single integrated picture of how intelligence, border enforcement, and potential targeting authorities intersect in the drone ecosystem along the border.
READ THE STORY: SWJ
Iranian Hackers Exploit Internet-Connected Security Cameras for Israeli Surveillance
Bottom Line Up Front (BLUF): Israeli officials say Iranian hackers are attempting to access internet-connected security cameras inside Israel to gather real-time intelligence, particularly during periods of military tension. By compromising poorly secured cameras, operators can observe troop movements, infrastructure activity, and civilian areas without deploying traditional reconnaissance assets.
Analyst Comments: Security cameras are especially attractive: they’re everywhere, rarely patched, often internet-accessible, and provide live situational awareness. Iranian operators have experimented with this tactic before, but Israel’s public warning suggests activity increased during active conflict periods, when visual intelligence becomes more valuable. Even low-resolution feeds can reveal traffic patterns, emergency responses, or military staging.
READ THE STORY: ET
“Cyber Widowhood” Trend Emerges in China as Users Mourn Lost AI Companions
Bottom Line Up Front (BLUF): A growing number of users in China are experiencing emotional distress after losing their AI companion partners due to server shutdowns or system updates, a phenomenon now referred to as “cyber widowhood.” The trend highlights increasing emotional dependence on AI relationship apps and has sparked debate about the psychological and social impacts of AI-driven companionship.
Analyst Comments: AI companion platforms represent a rapidly expanding segment of the consumer AI ecosystem. These applications create highly personalized virtual partners designed to provide emotional support, conversation, and simulated romantic relationships. As the technology becomes more immersive, users can form strong parasocial bonds with digital entities. The “cyber widowhood” phenomenon demonstrates the unintended consequences of this model. When AI companions disappear due to platform shutdowns, system upgrades, or policy changes, users experience real emotional grief similar to losing a relationship. This underscores how AI-driven interactions can blur the boundary between digital simulation and genuine emotional attachment.
READ THE STORY: NDTV
Palo Alto Networks Warns of Rising “Cybercrime Olympics” as Threat Actors Compete in Sophistication
Bottom Line Up Front (BLUF): Researchers describe today’s cybercrime ecosystem as a “Winter Olympics of cybercrime,” where threat actors compete and collaborate to develop increasingly sophisticated attacks. Organized cybercriminal groups are rapidly adopting AI tools, advanced malware services, and ransomware-as-a-service models, creating a highly competitive underground economy that accelerates the speed and scale of cyber operations.
Analyst Comments: The “cybercrime Olympics” analogy reflects a major shift in the threat landscape: cybercrime has evolved into a structured, professional ecosystem. Attackers now specialize in roles—initial access brokers, malware developers, ransomware operators, and data extortion groups—creating an efficient supply chain for cyberattacks. Competition between groups is also driving innovation. Criminal marketplaces reward actors who develop more evasive malware, faster exploitation techniques, and automated attack infrastructure. This dynamic mirrors legitimate tech ecosystems where innovation accelerates under competitive pressure.
READ THE STORY: Cyber
Cryptomining Attack Discovered on Chinese Provincial Supercomputing Center Servers
Bottom Line Up Front (BLUF): Incident responders investigating a provincial supercomputing center in China uncovered a cryptomining intrusion in which attackers gained access to internal servers, escalated privileges using the PwnKit (CVE-2021-4034) vulnerability, deployed tunneling tools, and installed Monero (XMR) mining malware. The attack leveraged internal proxy tools and rootkits to maintain persistence and conceal malicious activity.
Analyst Comments: Supercomputing environments offer massive CPU resources, making them attractive targets for illicit cryptomining. Once attackers gain even limited user access, privilege escalation flaws like PwnKit allow rapid transition to root control. The tooling used here is also common in intrusion sets targeting Linux infrastructure. FRP (Fast Reverse Proxy) enables attackers to create covert tunnels and bypass internal network controls, while GOST proxy tools allow flexible traffic redirection and persistence. The attackers also used command replacement techniques—overwriting utilities such as top, uptime, and w—to hide abnormal resource consumption caused by mining processes.
READ THE STORY: FREEBUF
Leaked Data From Russian Defense Contractor Exposes Details of Nuclear Infrastructure
Bottom Line Up Front (BLUF): Hackers reportedly breached a Russian defense contractor and leaked documents that reveal sensitive information about Russia’s nuclear weapons infrastructure, including facility layouts, procurement records, and internal documentation. The breach could provide intelligence agencies with insight into security practices, modernization programs, and vulnerabilities within Russia’s strategic weapons complex.
Analyst Comments: If authentic, leaks like this are gold for intelligence analysts. Nuclear programs are among the most tightly guarded state secrets, so even indirect data—like procurement lists, contractor communications, or facility schematics—can reveal far more than intended. Supply chain leaks are particularly damaging. Contractors often hold engineering documents, security procedures, maintenance schedules, and system diagrams that governments would never publish. That data can help adversaries map facilities, understand operational readiness, or identify potential weak points in command-and-control infrastructure.
READ THE STORY: United 24 // DEV
AWS Enables Multi-Region Access for IAM Identity Center to Improve Resilience
Bottom Line Up Front (BLUF): AWS has introduced multi-Region replication for IAM Identity Center, allowing organizations to provide workforce access to AWS accounts and applications from multiple regions. The capability improves availability, latency, and disaster resilience by enabling authentication and access through regional portals if the primary region becomes unavailable.
Analyst Comments: Identity infrastructure is a single point of failure in many cloud environments, so AWS extending Identity Center to a multi-Region model is a meaningful operational improvement. If an organization’s primary region goes down—or suffers authentication service disruption—users can still access AWS resources through replicated Identity Center endpoints in other regions. The design uses a primary–replica architecture: configuration and identity management remain centralized in the primary region, while additional regions host read-only replicas that handle authentication and application access locally. This reduces latency for globally distributed workforces while preserving centralized governance.
READ THE STORY: AWS
Attackers Exploit FortiGate Firewall Vulnerability to Maintain Persistent Network Access
Bottom Line Up Front (BLUF): Threat actors are actively exploiting a FortiGate firewall vulnerability to gain persistent access to enterprise networks, even after devices are patched. Attackers are reportedly creating malicious symbolic links and backdoor access mechanisms that survive remediation, allowing continued access to sensitive systems behind the firewall.
Analyst Comments: This is exactly the nightmare scenario defenders worry about with perimeter appliances: the firewall becomes the foothold. Once attackers compromise edge devices like FortiGate, they effectively gain visibility into internal network traffic and can pivot deeper into the environment. What makes this campaign particularly concerning is post-patch persistence. Even after organizations apply vendor fixes, attackers may leave behind artifacts—like rogue admin accounts, SSH keys, or filesystem modifications—that allow them to reconnect later. Many defenders patch the vulnerability but don’t perform full compromise assessments, which leaves networks exposed.
READ THE STORY: CSN
Apple Releases iOS 15.8.7 Emergency Update to Block Coruna Exploit Kit Targeting Legacy Devices
Bottom Line Up Front (BLUF): Apple pushed iOS 15.8.7 and iPadOS 15.8.7 as emergency security updates for legacy devices, patching four vulnerabilities that could be chained by the Coruna exploit kit to compromise iPhones and iPads via malicious web content. The flaws impact WebKit and the iOS Kernel, enabling attackers to escape the browser sandbox and escalate privileges. The update protects older devices that cannot upgrade to iOS 16 or 17.
Analyst Comments: Exploit kits targeting mobile browsers aren’t new, but chaining WebKit bugs with kernel privilege escalation remains one of the most reliable paths to full device compromise. In this case, the attack flow is straightforward: a victim visits a malicious site, WebKit memory corruption triggers code execution, the exploit escapes the sandbox, then a kernel bug grants system-level control. The bigger takeaway is legacy exposure. Devices stuck on iOS 15 still represent a large global footprint, and once vulnerabilities are patched in newer versions, attackers often reverse-engineer them to target older systems. Apple’s “lifeline” updates are essentially backports to prevent exactly that scenario. Still, organizations allowing older iPhones or iPads in corporate environments should assume these devices will remain a high-value target for mobile spyware and credential harvesting.
READ THE STORY: Cyber Press
Rockwell Automation Verve Asset Manager Vulnerabilities Expose Industrial Networks to Remote Compromise
Bottom Line Up Front (BLUF): CISA issued an advisory for multiple vulnerabilities in Rockwell Automation Verve Asset Manager, an industrial asset management platform widely used in OT environments. The flaws could allow attackers to execute code, escalate privileges, or manipulate system functions depending on configuration. Organizations running vulnerable versions should prioritize patching or mitigation, as compromise of asset management platforms can provide deep visibility—and control—inside industrial networks.
Analyst Comments: Asset management platforms like Verve are high-value targets because they sit in the middle of OT environments, aggregating inventory, credentials, and configuration data. If an attacker compromises that layer, they often gain a roadmap of the entire industrial network. Even when the vulnerabilities themselves are not wormable, they dramatically lower the barrier for lateral movement once a foothold exists. From a defensive perspective, this is less about a single bug and more about blast radius. Many organizations deploy OT management tools with broad privileges across PLCs, HMIs, and engineering workstations. That means exploitation could enable reconnaissance, configuration manipulation, or staging for operational disruption. Expect threat actors focused on industrial espionage or disruptive operations to monitor these advisories closely, particularly where patch cycles in OT lag behind IT.
READ THE STORY: CISA
Zero-Click FreeScout Vulnerability Enables Remote Code Execution via Email Processing
Bottom Line Up Front (BLUF): Researchers disclosed a critical vulnerability in the open-source help desk platform FreeScout that can lead to zero-click remote code execution (RCE). The flaw allows attackers to send a specially crafted email that triggers code execution when the message is automatically processed by the help desk system. Because exploitation requires no user interaction, exposed FreeScout deployments could be compromised simply by receiving a malicious email.
Analyst Comments: Zero-click vulnerabilities in email processing pipelines are especially dangerous because they bypass the human layer entirely. FreeScout’s workflow—automatically ingesting inbound emails and converting them into support tickets—creates a perfect attack surface. If input validation fails during that process, malicious payloads can move directly from email to server execution. For defenders, this falls into the broader class of server-side mail parsing bugs, which have historically produced some ugly compromises across ticketing systems, email gateways, and CRM platforms. Any system that automatically processes attachments, HTML content, or message metadata is a potential entry point.
READ THE STORY: InfoSecMag
CVE-2026-3910: Actively Exploited Chrome V8 Memory Bug Enables Sandbox Escape via Malicious Webpage
Bottom Line Up Front (BLUF): CVE-2026-3910 is a high-severity memory corruption vulnerability in the Chromium V8 JavaScript engine that allows attackers to execute arbitrary code inside the browser sandbox via a crafted HTML page. CISA has added the flaw to the Known Exploited Vulnerabilities (KEV) catalog, confirming exploitation in the wild. The issue affects Chromium-based browsers—including Google Chrome, Microsoft Edge, and Opera—and requires immediate patching to Chrome 146.0.7680.75 or later.
Analyst Comments: V8 bugs tend to move fast from disclosure to exploitation because the JavaScript engine sits directly in the browser attack surface. A single memory safety issue—like improper bounds checking—can allow attackers to corrupt memory through JavaScript executed on a webpage. While this specific bug executes code within the sandbox, history shows these vulnerabilities are frequently paired with sandbox escape or privilege escalation bugs to achieve full system compromise. That’s why V8 vulnerabilities often appear in drive-by exploit chains, watering-hole attacks, and exploit kits.
READ THE STORY: CVEFEED
CVE-2026-26133: Microsoft 365 Copilot Information Disclosure Vulnerability Raises Data Exposure Risks
Bottom Line Up Front (BLUF): CVE-2026-26133 is a high-severity information disclosure vulnerability affecting Microsoft 365 Copilot, with a CVSS score of 7.1. The flaw could allow attackers or unauthorized users to access sensitive information within the Copilot ecosystem under certain conditions. While the vulnerability is not remotely exploitable, it may still expose internal data if exploited through authenticated access or misuse of Copilot’s data retrieval capabilities.
Analyst Comments: Information disclosure issues in AI-assisted productivity platforms like Microsoft 365 Copilot are increasingly important because these systems aggregate data across email, documents, chats, and enterprise knowledge bases. If access controls or context isolation fail, Copilot could inadvertently expose sensitive corporate data from unrelated sources. Unlike classic software bugs that lead to code execution, these vulnerabilities often stem from data boundary failures, where the AI retrieves or surfaces information a user shouldn’t normally see. In enterprise environments where Copilot integrates with SharePoint, Teams, Outlook, and OneDrive, even a small permissions oversight could result in cross-document data leakage.
READ THE STORY: CVEFEED
CVE-2025-14287: Command Injection Vulnerability in MLflow CLI Enables Arbitrary Command Execution
Bottom Line Up Front (BLUF): CVE-2026-26133 is a high-severity information disclosure vulnerability affecting Microsoft 365 Copilot, with a CVSS score of 7.1. The flaw could allow attackers or unauthorized users to access sensitive information within the Copilot ecosystem under certain conditions. While the vulnerability is not remotely exploitable, it may still expose internal data if exploited through authenticated access or misuse of Copilot’s data retrieval capabilities.
Analyst Comments: Information disclosure issues in AI-assisted productivity platforms like Microsoft 365 Copilot are increasingly important because these systems aggregate data across email, documents, chats, and enterprise knowledge bases. If access controls or context isolation fail, Copilot could inadvertently expose sensitive corporate data from unrelated sources. Unlike classic software bugs that lead to code execution, these vulnerabilities often stem from data boundary failures, where the AI retrieves or surfaces information a user shouldn’t normally see. In enterprise environments where Copilot integrates with SharePoint, Teams, Outlook, and OneDrive, even a small permissions oversight could result in cross-document data leakage.
READ THE STORY: CVEFEED
Items of interest
NAC in SCADA: Why Controlling Internal Network Access Is Critical for OT Security
Bottom Line Up Front (BLUF): Internal connectivity—not external intrusion—is often the weakest link in industrial networks. Contractors, engineers, and vendor devices frequently connect directly into OT segments, where flat architectures and weak access controls allow unauthorized systems to interact with critical SCADA assets. Implementing Network Access Control (NAC) can reduce this risk, but OT deployments must prioritize passive discovery, behavioral profiling, and phased enforcement to avoid disrupting industrial processes.
Analyst Comments: Traditional NAC models used in corporate networks rely on authentication protocols such as 802.1X and assume endpoints can run security agents or tolerate active scanning. OT environments rarely meet these assumptions. Devices like PLCs, RTUs, and HMIs often run legacy stacks, cannot install agents, and may fail when exposed to aggressive network interrogation.
READ THE STORY: CODEBY
SCADA Architecture Simplified: 5-Minute Industrial Control Guide (Video)
FROM THE MEDIA: Discover the fundamental architecture behind the industrial control systems that power our modern world! With 35 years of hands-on experience, I break down SCADA systems into simple, practical components that anyone in the industry can understand.
Introduction To 𝐒𝐂𝐀𝐃𝐀 𝐒𝐲𝐬𝐭𝐞𝐦 (Video)
FROM THE MEDIA: What is Scada?
The selected stories cover a broad range of cyber threats and are intended to help readers frame key publicly discussed threats and improve overall situational awareness. InfoDom Securities does not endorse any third-party claims made in its original material or related links on its sites; the opinions expressed by third parties are theirs alone. For further questions, don't hesitate to get in touch with InfoDom Securities at dominanceinformation@gmail.com.


