Floating servers and digital shields highlighting critical cybersecurity news.

Daily Cybersecurity News - March 16, 2026

Wing FTP Flaw Exposes Server Paths

Medium

Executive Summary

CISA has added CVE-2025-47813, an information disclosure vulnerability in Wing FTP Server, to its Known Exploited Vulnerabilities (KEV) catalog based on evidence of active exploitation. The flaw allows authenticated attackers to discover the full local installation path of the application.

Vulnerability Details

  • Affected Product: Wing FTP Server versions prior to 7.4.4
  • Identifier: CVE-2025-47813
  • CVSS Score: 4.3 (Medium)
  • Exploitation Status: Actively Exploited

Risk & Impact

  • Triage: Immediate patching is required due to inclusion in the CISA KEV catalog.
  • Attack Vector: An authenticated attacker can send a long value in the UID cookie to the `loginok.html` endpoint, causing the server to return an error message that contains the full local installation path.
  • Ease of Exploit: The exploit requires low privileges, as an authenticated session is necessary to manipulate the session cookie.

Action Plan

  • Immediate Action: Upgrade Wing FTP Server to version 7.4.4 or later.
  • Workaround: Restrict access to the web interface to trusted IP addresses to limit exposure.
  • Detection: Monitor web server logs for requests to `loginok.html` with unusually long UID cookie values.

Relevant professional terms

Known Exploited Vulnerabilities (KEV) Catalog
A list curated by CISA of vulnerabilities that have been confirmed through evidence to be actively exploited in the wild, helping organizations prioritize remediation.
Information Disclosure Vulnerability
A security flaw where an application unintentionally reveals sensitive information, such as system paths or configuration details, to unauthorized users.
Source: CISA

AWS Bedrock Flaw Exposes Cloud Data

Executive Summary

A security issue has been identified in AWS Bedrock's Code Interpreter that could allow for data exfiltration from sandboxed environments. AWS has reviewed the issue and states it is intended functionality, updating documentation to clarify that the sandbox mode has limited network access.

Vulnerability Details

  • Affected Product: AWS Bedrock AgentCore Code Interpreter
  • Exploitation Status: Proof-of-concept exists

Risk & Impact

  • Triage: Medium - Immediate review of IAM policies for Bedrock agents is recommended.
  • Attack Vector: An attacker can craft malicious instructions within files processed by the interpreter. These instructions leverage DNS resolution, which remains active in the sandbox, to create a covert channel for exfiltrating data, such as credentials or S3 bucket contents.
  • Ease of Exploit: Trivial, if an attacker can influence code execution within the interpreter.

Action Plan

  • Immediate Action: AWS has updated its documentation to clarify the networking capabilities of the sandbox mode. Customers should review and apply the principle of least-privilege to IAM roles assigned to code interpreters.
  • Workaround: Administrators should inventory all active AgentCore Code Interpreter instances and migrate any that handle sensitive data to environments with stricter network controls.
  • Detection: Monitor CloudTrail for unusual invocation activity, though this may require enabling Data Events which can incur extra costs. Basline and monitor for anomalous agent behavior, data access, and tool invocation patterns.

Relevant professional terms

Data Exfiltration
The unauthorized transfer of data from a computer or server. In this context, it refers to using DNS queries to sneak sensitive information out of the supposedly isolated AWS environment.
Sandbox
A security mechanism for separating running programs, usually in an effort to mitigate system failures or software vulnerabilities from spreading. In this case, the AWS Bedrock sandbox's network restrictions were not as complete as might be assumed.

Polish Nuclear Center Thwarts Cyberattack

Executive Summary

Poland's National Centre for Nuclear Research (NCBJ) successfully detected and blocked a cyberattack targeting its IT infrastructure. Early detection by security systems prevented any data compromise or operational impact on the facility, including its MARIA research reactor.

Attack Overview

  • Attack Path: The specific initial access vector has not been disclosed; however, officials noted that the entry points were traced to Iranian infrastructure.
  • Attacker:Iranian-linked actors (Suspected)

Impact Assessment

  • Data Stolen: No data was leaked from the center.
  • Operational Impact: No operational, production, or research processes were disrupted. The MARIA reactor remained safe and at full power.

Strategic Takeaway

The successful defense highlights the importance of robust, pre-emptive security monitoring for critical infrastructure, though attribution remains cautious as the indicators could be a false flag.

Relevant professional terms

False Flag
A clandestine operation designed to deceive in such a way that activities appear as though they are being carried out by entities, groups, or nations other than those who actually planned and executed them.
Critical Infrastructure
Assets, systems, and networks, whether physical or virtual, that are considered so vital to a country that their incapacitation or destruction would have a debilitating effect on security, national economic security, or public health and safety.
Source: SecurityWeek

Hacked Sites Spread Vidar Infostealer

Executive Summary

Threat actors are compromising WordPress websites to display fake verification pages, tricking Windows users into downloading and installing the Vidar information stealer. This malware is designed to harvest a wide range of sensitive data from browsers, cryptocurrency wallets, and other applications.

Key TTPs

  • Initial Access: Delivered via social engineering on compromised websites, malvertising, and phishing emails containing malicious attachments.
  • Execution: A user is tricked into running a malicious installer disguised as legitimate software or a verification step.
  • Defense Evasion: Employs file bloating to exceed antivirus scan limits, uses obfuscation techniques like control flow flattening, and may self-destruct after data exfiltration to remove traces.

Campaign Analysis

This campaign leverages trusted, albeit compromised, infrastructure to bypass user suspicion and distribute malware effectively. Vidar continues to evolve, with newer versions rewritten for efficiency and incorporating advanced methods to bypass browser security features.

Targeting & Infrastructure

  • Target Profile: Windows operating system users.
  • Infrastructure: Utilizes compromised WordPress sites for distribution and social media platforms like Telegram for Command and Control (C2) communications.

Relevant Terms

  • Infostealer: A type of malware designed specifically to collect and exfiltrate sensitive information from a victim's computer, such as login credentials, financial data, and browser history.
  • C2 (Command and Control): The server infrastructure that attackers use to send commands to compromised systems and receive stolen data.
Source: Malwarebytes

Brazilian Trojan Hijacks Payments

Executive Summary

The GoPix banking trojan targets Brazilian users of the PIX instant payment system through malvertising. It employs sophisticated, memory-only implants and clipboard hijacking to intercept and redirect financial transactions to attacker-controlled accounts.

Key TTPs

  • Initial Access: Malicious ads on search engines, often impersonating "WhatsApp Web," lead to fake download pages.
  • Execution: Injects payload into the legitimate 'svchost.exe' process using process hollowing.
  • Defense Evasion: Uses multiple obfuscation layers and checks for security software before deploying different payload versions.

Campaign Analysis

GoPix represents a significant evolution in Brazilian banking malware, adopting techniques from APT groups to enhance stealth and persistence. The malware uses short-lived C2 infrastructure and abuses legitimate anti-fraud services to filter its victims, indicating a targeted and sophisticated operation.

Targeting & Infrastructure

  • Target Profile: Users of Brazil's PIX payment system, including customers of financial institutions and cryptocurrency users.
  • Infrastructure: Abuses Google Ads for distribution and legitimate services like IPQualityScore to vet targets and evade analysis environments.

Relevant Terms

  • Process Hollowing: A defense evasion technique where an attacker creates a new process in a suspended state and replaces its legitimate code with malicious code.
  • Malvertising: The use of online advertising to spread malware, where malicious ads are placed on legitimate websites to redirect users to malware-hosting sites.

Scammers Weaponize LiveChat for Data Theft

Executive Summary

Threat actors are abusing the legitimate LiveChat SaaS platform in a social engineering campaign. By impersonating trusted brands like PayPal and Amazon, they engage victims in real-time chats to steal credentials, credit card details, and other sensitive personal information.

Key TTPs

  • Initial Access: Phishing emails with lures of refunds or pending orders contain links that direct users to a malicious LiveChat page.
  • Execution: A human operator, likely following a script, uses social engineering during the live chat to manipulate the victim into divulging financial and personal data.

Campaign Analysis

This campaign marks an evolution in phishing tactics by leveraging a trusted, real-time communication platform to build rapport and disarm victims. The interactive nature of the attack makes it harder to detect compared to traditional static phishing pages.

Targeting & Infrastructure

  • Target Profile: Customers of major brands such as PayPal and Amazon.
  • Infrastructure: The attack abuses legitimate LiveChat services, with phishing URLs often containing the domain lc[.]chat.

Relevant Terms

  • Social Engineering: A manipulation technique used to trick individuals into divulging confidential information or performing specific actions.
  • Phishing: A cybercrime where attackers impersonate legitimate organizations via email, text, or other channels to steal sensitive data like login credentials and credit card numbers.
Source: Dark Reading

Actors Poison Search to Steal Credentials

Executive Summary

The threat actor Storm-2561 is using SEO poisoning to lead users to malicious websites that distribute trojanized VPN client installers. The goal is to harvest VPN credentials from unsuspecting users searching for legitimate enterprise software.

Key TTPs

  • Initial Access: SEO poisoning redirects users searching for VPN software to attacker-controlled websites.
  • Execution: A malicious MSI installer side-loads a trojanized DLL (inspector.dll), a variant of the Hyrax infostealer.
  • Defense Evasion: The malware is digitally signed with a legitimate, now-revoked, certificate to appear trustworthy.

Campaign Analysis

This campaign abuses trust in search engine rankings and software branding to deliver malware. After stealing credentials, the malware displays a fake error and directs the user to the legitimate VPN software, reducing suspicion of compromise.

Targeting & Infrastructure

  • Target Profile: Users of enterprise VPN software from vendors like Ivanti (Pulse Secure), Fortinet, and Cisco.
  • Infrastructure: Malicious ZIP files were hosted on GitHub and distributed via spoofed domains.

Actionable Intelligence

  • IPs: 194.76.226[.]93
  • Domains: vpn-fortinet[.]com, ivanti-vpn[.]org

Relevant Terms

  • SEO Poisoning: The technique of manipulating search engine results to promote malicious websites to the top of rankings for specific keywords.
  • DLL Side-Loading: An attack where a legitimate application is tricked into loading a malicious Dynamic Link Library (DLL), allowing the malware to execute under the trusted application's process.
Source: SecurityWeek