Isometric network nodes highlighting critical iOS flaws, AI scams, and global cyber threats.

Daily Cybersecurity News - March 7, 2026

CISA Mandates Patches for Exploited iOS Flaws

Executive Summary

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch three actively exploited vulnerabilities in Apple’s iOS (added to KEV catalog). The flaws, identified as CVE-2021-30952, CVE-2023-41974, CVE-2023-43000 (part of Coruna exploit kit chains; additional older kit vulns include CVE-2024-23225/23296), are being leveraged in spyware and crypto-theft campaigns using the “Coruna” exploit kit.

Vulnerability Details

  • Affected Product:Apple iOS, iPadOS, macOS, watchOS, tvOS, and visionOS. Specific versions prior to iOS/iPadOS 17.4 and 16.7.6 are affected.
  • Identifier: CVE-2021-30952, CVE-2023-41974, CVE-2023-43000
  • CVSS Score:Available on NVD (high/critical range).
  • Exploitation Status: Actively Exploited

Risk & Impact

  • Triage: Critical: Immediate patching is required as per CISA directive.
  • Attack Vector: The vulnerabilities are memory corruption issues in the Kernel and RTKit. An attacker with arbitrary kernel read and write capabilities can exploit these flaws to bypass kernel memory protections.
  • Ease of Exploit: The vulnerabilities are part of a sophisticated "Coruna" exploit kit, suggesting ease of use for threat actors with access to this tool.

Action Plan

  • Immediate Action: Upgrade to iOS 17.4, iPadOS 17.4, macOS Sonoma 14.4 or newer versions. For older devices, update to iOS 16.7.6 and iPadOS 16.7.6.
  • Workaround: No workarounds are available; patching is the only mitigation.
  • Detection: Monitor for signs of compromise associated with known spyware and anomalous device behavior.

Relevant professional terms

Exploit Kit
A software toolkit designed to identify and leverage vulnerabilities on a target system, often automating the process of deploying malware.
Cyberespionage
The use of computer networks to gain illicit access to confidential information, typically held by a government or other organization.

DPRK Actors Weaponize AI for IT Scams

Executive Summary

North Korean (DPRK) threat actors are leveraging AI to enhance fraudulent IT worker campaigns, creating convincing personas to secure remote employment at global companies. These operations aim to generate revenue for the regime and establish long-term access for potential espionage and data theft.

Key TTPs

  • Initial Access: Using AI-generated resumes and fraudulent identities to apply for jobs on legitimate platforms. Operatives use deepfakes for video interviews and social engineering to pass screening processes.
  • Defense Evasion: Concealing their true location using VPNs, proxy services, and remote desktop software to appear as authentic remote workers.

Campaign Analysis

The integration of AI marks a significant evolution in DPRK tactics, allowing them to scale their scams and overcome language barriers more effectively. This increases the success rate of their infiltration attempts, posing a greater insider threat to targeted organizations.

Targeting & Infrastructure

  • Target Profile: Technology firms, cryptocurrency companies, and other organizations hiring for remote IT, software, and blockchain development roles.
  • Infrastructure: Relies on a network of front companies, mail forwarding services, and U.S.-based "laptop farms" to receive corporate hardware and manage operations.

Relevant Terms

  • APT (Advanced Persistent Threat): A term for a sophisticated, often state-sponsored, hacking group that gains unauthorized access to a network and remains undetected for an extended period.
  • Social Engineering: The psychological manipulation of people into performing actions or divulging confidential information.
Source: Dark Reading

Fake Update Grants Full PC Control

Executive Summary

Threat actors are using fake Google Meet update pages to trick users into downloading a malicious installer. This installer enrolls the victim's Windows PC into an attacker's device management system, granting them complete remote access and control.

Key TTPs

  • Initial Access: Social engineering through phishing links disguised as meeting invitations, leading to fake update pages that mimic the Microsoft Store.
  • Execution: The user is prompted to download and run a malicious MSI file that silently installs Esper (SaaS MDM at tnrmuv-api.esper[.]cloud), a legitimate remote monitoring tool.
  • Defense Evasion: The campaign abuses a legitimate, commercially available monitoring tool which may not be flagged by security software. The tool is often configured to run in "stealth mode" with no visible icons.

Campaign Analysis

This campaign highlights the abuse of legitimate commercial software for malicious ends, bypassing traditional malware detection. By exploiting user trust in well-known brands like Google, attackers can deploy powerful surveillance tools without developing custom malware.

Targeting & Infrastructure

  • Target Profile: Windows PC users, with a focus on corporate environments, including logistics and transportation sectors.
  • Infrastructure: Phishing domains impersonating Google Meet and fake Microsoft Store pages hosted on attacker-controlled infrastructure.

Relevant Terms

  • Social Engineering: A manipulation technique used to trick individuals into divulging confidential information or performing specific actions, such as clicking a malicious link.
  • Remote Monitoring Tool: Legitimate software used by administrators to manage and monitor computer systems, which can be abused by attackers for surveillance and control.
Source: Malwarebytes

GitHub Repos Distribute Widespread Stealer

Executive Summary

A new data-stealing malware campaign, BoryptGrab, is leveraging over 100 deceptive GitHub repositories to target Windows users. The malware's primary goal is to exfiltrate browser data, cryptocurrency wallet information, system details, and user files.

Key TTPs

  • Initial Access: Victims are lured through SEO-poisoned GitHub repositories masquerading as free software or gaming tools.
  • Execution: A malicious ZIP file is downloaded from a fake download page, initiating the infection chain upon execution.
  • Defense Evasion: The malware checks if it is running inside a virtual machine (VM) or near analysis tools to avoid detection.

Campaign Analysis

The BoryptGrab campaign demonstrates an evolving threat that exploits user trust in legitimate platforms like GitHub. Some variants deliver a secondary payload, a reverse SSH backdoor called TunnesshClient, for persistent access and command and control.

Targeting & Infrastructure

  • Target Profile: The campaign targets Windows users, focusing on individuals with cryptocurrency wallets and sensitive browser data.
  • Infrastructure: The operation utilizes over 100 public GitHub repositories to host and distribute the malware.

Relevant Terms

  • Stealer Malware: A type of malware designed to illicitly collect and exfiltrate sensitive information, such as login credentials, financial data, and personal files, from a victim's computer.
  • Reverse SSH Backdoor: A malicious tool that establishes an outbound, encrypted connection from a compromised computer to an attacker-controlled server, bypassing firewalls to allow remote command execution.
Source: SecurityWeek

Iranian Hackers Deploy New Backdoor

Executive Summary

The Iranian state-sponsored group MuddyWater (aka Seedworm) has targeted U.S. and Israeli organizations with a new backdoor called Dindoor. The campaign, which began in February 2026, has impacted sectors including finance, aviation, and defense.

Key TTPs

  • Initial Access: Exploiting public-facing applications and using targeted spearphishing campaigns are common methods for this actor.
  • Execution: The Dindoor backdoor uniquely leverages the Deno JavaScript/TypeScript runtime to execute commands, helping to evade security tools focused on PowerShell.
  • Defense Evasion: The group uses digitally signed malware and brings its own runtime (BYOR) to bypass endpoint detection systems.

Campaign Analysis

This campaign showcases MuddyWater's tactical evolution, adopting legitimate and less-monitored developer tools like Deno to conduct espionage. The reuse of digital certificates provides high-confidence attribution to this Iranian Ministry of Intelligence and Security (MOIS) subordinate.

Targeting & Infrastructure

  • Target Profile: A U.S. bank, an airport, non-profits, and the Israeli branch of a U.S. defense/aerospace software supplier.

Relevant Terms

  • Backdoor: A covert method of bypassing normal authentication or security controls in a computer system to gain unauthorized access.
  • Spearphishing: A targeted email-based attack on a specific individual or organization, seeking to steal sensitive information or install malware.