Isometric network nodes visualizing critical cybersecurity exploits and global cyber operations.

Daily Cybersecurity News - March 5, 2026

Cisco Confronts Exploited SD-WAN Flaws

High

Executive Summary

Cisco has confirmed active exploitation of two vulnerabilities, CVE-2026-20122 and CVE-2026-20128, in its Catalyst SD-WAN Manager software. The company strongly urges administrators to upgrade to a fixed software release to remediate these actively exploited flaws.

Vulnerability Details

  • Affected Product: Cisco Catalyst SD-WAN Manager (formerly vManage)
  • Identifier: CVE-2026-20122, CVE-2026-20128
  • CVSS Score: CVE-2026-20122: 7.1 (High); CVE-2026-20128: 5.5 (Medium).
  • Exploitation Status: Actively Exploited

Risk & Impact

  • Triage: Immediate patching is required due to active exploitation.
  • Attack Vector: CVE-2026-20122 allows a remote attacker with read-only credentials to overwrite arbitrary files. CVE-2026-20128 is an information disclosure flaw requiring a local attacker to have valid credentials.
  • Ease of Exploit: The exploits require valid credentials, either for remote API access (CVE-2026-20122) or local access (CVE-2026-20128).

Action Plan

  • Immediate Action: Cisco strongly recommends that all customers upgrade to a fixed software release to remediate these vulnerabilities.
  • Workaround: No workarounds have been provided; upgrading is the only remediation.
  • Detection: Administrators should monitor for unauthorized file modifications and unusual activity from authenticated users, especially concerning API access.

Relevant professional terms

SD-WAN (Software-Defined Wide Area Network)
A virtual WAN architecture that allows enterprises to leverage any combination of transport services - including MPLS, LTE, and broadband internet services - to securely connect users to applications.
Arbitrary File Overwrite
A type of vulnerability where an attacker can write data to any file on the target system. This can lead to remote code execution, denial of service, or elevation of privileges by overwriting critical system files.

VMware Flaw Enables Remote Code Execution

High

Executive Summary

A high-severity command injection vulnerability, identified as CVE-2026-22719, has been found in VMware Aria Operations. The flaw is under active exploitation and allows an unauthenticated attacker to execute arbitrary commands, potentially leading to remote code execution.

Vulnerability Details

  • Affected Product: VMware Aria Operations (formerly vRealize Operations)
  • Identifier: CVE-2026-22719
  • CVSS Score: 8.1 (High)
  • Exploitation Status: Actively Exploited

Risk & Impact

  • Triage: Urgent. CISA has added this vulnerability to its Known Exploited Vulnerabilities (KEV) catalog.
  • Attack Vector: An unauthenticated attacker can remotely exploit this command injection flaw. However, the vulnerability is only exposed during a support-assisted product migration, which makes the attack complexity high.
  • Ease of Exploit: The exploit requires a specific operational condition (product migration), making it complex but proven to be possible.

Action Plan

  • Immediate Action: Upgrade to a fixed version, such as VMware Aria Operations 8.18.6 or other resolved versions as specified by the vendor.

Relevant professional terms

Command Injection
A type of cyber attack that involves executing arbitrary commands on a host operating system. The attacker exploits a vulnerability in an application to extend its functionality and run commands, often to gain unauthorized access to the system or data.
Remote Code Execution (RCE)
A vulnerability that allows a malicious actor to execute any code of their choice over a network on a target machine. RCE vulnerabilities are often considered the most critical as they can grant an attacker full control over the compromised system.
Source: Dark Reading

Israeli Cyber Operation Assists Targeted Killing

Executive Summary

Israeli intelligence reportedly hacked nearly all of Tehran's traffic cameras in a multi-year operation to gather intelligence and monitor the movements of Iran's Supreme Leader Ali Khamenei and his security detail, culminating in a lethal, targeted airstrike.

Key TTPs

  • Initial Access: Long-term compromise of nearly all traffic cameras in Tehran and penetration of mobile phone networks.
  • Execution: Used AI and complex algorithms to process surveillance data and build "pattern of life" models on key individuals.
  • Defense Evasion: Disrupted cellular service near the target area to prevent potential warnings from being communicated.

Campaign Analysis

This operation demonstrates a sophisticated fusion of long-term cyber-espionage with kinetic military action, turning civilian infrastructure into a tactical asset for assassination. The extensive data analysis highlights a mature capability to process vast information for precise, real-world outcomes.

Targeting & Infrastructure

  • Target Profile: Iranian Supreme Leader Ali Khamenei and his senior security officials.
  • Infrastructure: Tehran's city-wide traffic camera network and local mobile phone towers.

Relevant Terms

  • Cyber-Espionage: The use of computer networks to gain illicit access to confidential information, typically held by a government or other organization.
  • Pattern of Life: An intelligence analysis method used to identify and understand the habits, routines, and relationships of a target through surveillance.

US-Israel Launch Hybrid Iran Assault

Executive Summary

The U.S. and Israel launched "Operation Epic Fury" (also called "Operation Lion's Roar"), a coordinated kinetic and cyber campaign against Iran. The operation aims to dismantle Iran's security and military infrastructure through integrated physical strikes and large-scale cyberattacks targeting critical systems.

Key TTPs

  • Initial Access: Widespread offensive cyber operations preceded or accompanied initial kinetic strikes. This included deep network intrusions and compromising satellite broadcasts for psychological operations.
  • Execution: A massive cyberattack caused a near-total internet blackout, with connectivity dropping to 1-4% of normal levels. This was synchronized with air and missile strikes on over 1,700 targets.

Campaign Analysis

This operation represents a significant evolution in warfare, seamlessly fusing large-scale kinetic strikes with a comprehensive cyber assault to paralyze a nation's command and control. The campaign's goal was to degrade military capabilities while simultaneously creating a communications blackout and sowing internal disruption.

Targeting & Infrastructure

  • Target Profile: Iranian leadership and the Islamic Revolutionary Guard Corps (IRGC), including command centers, air defense, missile sites, and naval assets.
  • Infrastructure: The cyberattack targeted critical national infrastructure, including internet connectivity, government websites, communications systems, and media outlets.

Relevant Terms

  • Kinetic Warfare: Military action involving physical force and conventional weapons, such as missile strikes and bombing campaigns.
  • Command and Control (C2): The infrastructure and systems used by military commanders to direct and control forces and operations. Disrupting C2 is a primary goal in modern warfare.
Source: Flashpoint

iOS Exploit Kit Pivots to Crypto Theft

Executive Summary

The Coruna exploit kit, a sophisticated toolkit with 23 exploits, has transitioned from state-sponsored espionage to financially motivated attacks. Threat actors are now using it to target cryptocurrency users by compromising vulnerable iPhones.

Key TTPs

  • Initial Access: Victims are directed to malicious websites (watering hole attack), where a hidden iFrame delivers the exploit kit.
  • Execution: The framework fingerprints the device and iOS version to deliver a tailored WebKit remote code execution exploit.
  • Defense Evasion: The exploit kit checks for and aborts its execution if the device is in Lockdown Mode or using private browsing.

Campaign Analysis

Coruna's evolution from a targeted surveillance tool used by state actors to a commodity for mass-scale criminal operations marks a significant proliferation of advanced mobile threats. This shift dramatically expands the potential victim pool beyond traditional espionage targets.

Targeting & Infrastructure

  • Target Profile: Initially Ukrainian users and government targets, now broadened to global cryptocurrency and finance app users.
  • Infrastructure: A large network of fake Chinese websites related to finance and cryptocurrency are used to host the exploit kit.

Relevant Terms

  • Exploit Kit: A software toolkit designed to identify and attack vulnerabilities on a victim's device, typically through a web browser, to deploy malware.
  • Watering Hole Attack: A cyberattack strategy where an attacker compromises a website likely to be visited by a specific target group, rather than attacking the targets directly.

Iranian Hackers Strike Iraqi Government

Executive Summary

A suspected Iran-nexus threat actor, dubbed Dust Specter, is targeting Iraqi government officials by impersonating the nation's Ministry of Foreign Affairs. The campaign, observed in January 2026, delivers a suite of new malware tools to compromise high-value targets.

Key TTPs

  • Initial Access: Social engineering lures with password-protected RAR archives delivered to targets.
  • Execution: In-memory PowerShell execution and commands polled from text files.
  • Defense Evasion: DLL sideloading via legitimate applications like VLC and WingetUI, alongside using invisible Windows forms to delay execution.

Campaign Analysis

This campaign marks an evolution in the actor's methods, utilizing four previously undocumented .NET malware families. Evidence also suggests the use of generative AI in the malware development process, indicating experimentation with new techniques to enhance their toolkit.

Targeting & Infrastructure

  • Target Profile: Government officials within, or affiliated with, Iraq's Ministry of Foreign Affairs.
  • Infrastructure: Compromised Iraqi government-related infrastructure used to host malicious payloads and C2 domains.

Actionable Intelligence

  • Domains: meetingapp[.]site

Relevant Terms

  • DLL Sideloading: A technique where an attacker places a malicious DLL file in a location where a legitimate application will load it instead of the intended one, allowing the malicious code to be executed.
  • C2 (Command and Control): The server infrastructure that attackers use to send commands to and receive data from compromised systems (bots).

Russian APT Deploys Novel Malware

Executive Summary

The Russian-linked threat actor APT28 is targeting Ukrainian entities with a new campaign. The operation uses phishing emails to deliver two new malware families, a loader called BadPaw and a backdoor named MeowMeow.

Key TTPs

  • Initial Access: Phishing emails from a compromised, legitimate Ukrainian email provider containing a link to a ZIP archive.
  • Execution: A malicious HTML Application (HTA) file, disguised as an HTML file, is launched from the ZIP archive to initiate the infection chain.
  • Defense Evasion: The malware checks for sandbox environments by querying the OS installation date and scans for analysis tools like Wireshark and ProcMon before executing. Both malware strains are obfuscated using the .NET Reactor packer.

Campaign Analysis

This campaign showcases APT28's continued focus on Ukraine, evolving its toolkit with previously undocumented malware. The use of multi-layered defense evasion and legitimate infrastructure for initial access highlights the group's increasing sophistication.

Targeting & Infrastructure

  • Target Profile: Ukrainian entities.
  • Infrastructure: Phishing emails are sent from the legitimate Ukrainian provider ukr[.]net to increase credibility.

Relevant Terms

  • Backdoor: A type of malware that bypasses normal authentication procedures to grant a remote attacker unauthorized access to a system.
  • Loader: A malicious program used to download and execute other malware payloads onto a compromised system.