Isometric network nodes highlighting widespread cybersecurity flaws and AI weaponization.

Daily Cybersecurity News - March 24, 2026

Citrix Flaw Exposes Sensitive Memory

Critical

Executive Summary

A critical out-of-bounds read vulnerability, identified as CVE-2026-3055, affects Citrix NetScaler ADC and Gateway products. This flaw allows remote, unauthenticated attackers to read sensitive information from the appliance's memory, and though not yet exploited, security firms urge immediate patching due to the high likelihood of future attacks.

Vulnerability Details

  • Affected Product: NetScaler ADC and NetScaler Gateway versions 14.1 before 14.1-66.59, 13.1 before 13.1-62.23, and NetScaler ADC 13.1-FIPS/NDcPP before 13.1-37.262.
  • Identifier: CVE-2026-3055
  • CVSS Score: 9.3 (Critical)
  • Exploitation Status: No known exploitation in the wild; no public proof-of-concept is available.

Risk & Impact

  • Triage:Emergency. Organizations should prioritize upgrading to fixed versions immediately.
  • Attack Vector: An unauthenticated, remote attacker can exploit this vulnerability to leak sensitive information from the appliance's memory. The vulnerability only affects customer-managed systems configured as a SAML Identity Provider (IdP).
  • Ease of Exploit: Exploitation is considered likely once a proof-of-concept becomes public, drawing comparisons to previous widely exploited vulnerabilities like "CitrixBleed".

Action Plan

  • Immediate Action: Upgrade to NetScaler ADC and Gateway versions 14.1-66.59, 13.1-62.23, or 13.1.37.262 for FIPS/NDcPP releases.
  • Workaround: For builds 14.1-60.52 and 14.1-60.57, Global Deny List signatures can be used for mitigation via NetScaler Console.
  • Detection: Administrators can check if their appliance is configured as a vulnerable SAML IdP by searching the configuration for the string: "add authentication samlIdPProfile .*".

Relevant professional terms

Out-of-Bounds Read
A type of software vulnerability where a program reads data from outside the boundaries of an allocated memory buffer, which can lead to the disclosure of sensitive information, crashes, or other undefined behavior.
SAML Identity Provider (IdP)
In the Security Assertion Markup Language (SAML) standard for exchanging authentication data, an IdP is a service that creates, maintains, and manages identity information for users and provides authentication services to other applications.
Source: SecurityWeek

Ghost Campaign Infects NPM Packages

Executive Summary

A threat actor, using the alias "mikilanjillo," published malicious packages to the npm repository in a software supply chain attack dubbed the "Ghost campaign." The campaign's primary goal is to steal cryptocurrency wallets and other sensitive credentials from developers by deploying a Remote Access Trojan (RAT).

Key TTPs

  • Initial Access: Malicious code is introduced into development environments when users install compromised npm packages.
  • Execution: The malware prompts the user for their sudo password during a fake installation process to execute the final payload.
  • Defense Evasion: The packages display fake installation logs, including progress bars and random delays, to deceive the user into thinking a legitimate process is running.

Campaign Analysis

This campaign highlights the ongoing threat of software supply chain attacks, where threat actors exploit the trust developers place in open-source repositories. The use of social engineering during the installation process marks an evolution in tactics to gain elevated permissions.

Targeting & Infrastructure

  • Target Profile: Software developers using the npm package manager.
  • Infrastructure: The campaign leverages the official npm public repository to distribute its malicious packages.

Relevant Terms

  • npm: Node Package Manager, the default package manager for the JavaScript runtime environment Node.js. It is the world's largest software registry.
  • Remote Access Trojan (RAT): A type of malware that allows an attacker to gain unauthorized remote control over an infected computer.

TeamPCP Hijacks GitHub Scanner

Executive Summary

Threat actor TeamPCP executed a supply chain attack by compromising the Checkmarx KICS GitHub Action. The group hijacked dozens of version tags to inject credential-stealing malware into CI/CD pipelines that utilized the popular code scanner.

Key TTPs

  • Initial Access: Compromised a service account token to gain access to the code repository.
  • Execution: Injected malicious code by force-pushing updated tags that pointed to imposter commits, causing CI/CD workflows to execute the malware.
  • Defense Evasion: The attack mirrored a previous compromise of the Trivy scanner, using a typosquat domain for C2 communications to appear legitimate.

Campaign Analysis

This incident is part of a broader TeamPCP campaign targeting CI/CD infrastructure to steal credentials and propagate malware. The attack highlights the growing trend of threat actors targeting the software supply chain to achieve widespread impact.

Targeting & Infrastructure

  • Target Profile: Developers and organizations using the Checkmarx KICS GitHub Action in their CI/CD pipelines.
  • Infrastructure: The attack leveraged compromised GitHub service accounts and typosquatted domains for data exfiltration.

Actionable Intelligence

  • Domains: checkmarx[.]zone

Relevant Terms

  • Supply Chain Attack: An attack strategy that targets less-secure elements in a software supply network, such as third-party code libraries or development tools, to compromise a final product.
  • GitHub Actions: An automation tool within GitHub that allows developers to build, test, and deploy code directly from their repositories through automated workflows.
Source: Wiz

Russian Actors Hijack Messaging Apps

Executive Summary

The FBI and CISA have issued a joint alert on a global phishing campaign by Russian Intelligence Services targeting users of secure messaging apps like Signal and WhatsApp. The operation aims to hijack accounts by tricking users into revealing verification codes or PINs.

Key TTPs

  • Initial Access: Phishing messages are sent to targets, often impersonating automated support accounts from the messaging app.
  • Execution: Attackers use social engineering to deceive users into sharing SMS verification codes or account PINs, or scanning a malicious QR code. This allows the actors to register the victim's account on a device they control.

Campaign Analysis

This campaign bypasses strong end-to-end encryption by targeting the user, the weakest link in the security chain. The easily scalable social engineering tactics indicate a broad intelligence-gathering effort focused on high-value targets.

Targeting & Infrastructure

  • Target Profile: High-value individuals, including current and former government officials, military personnel, politicians, and journalists.
  • Infrastructure: The campaign leverages the legitimate infrastructure of commercial messaging applications (CMAs) for its operations.

Relevant Terms

  • Social Engineering: A manipulation technique used to trick individuals into divulging confidential information or performing specific actions.
  • Phishing: A type of social engineering where attackers send fraudulent messages designed to lure a victim into revealing sensitive information.
Source: Malwarebytes

Scammers Weaponize AI For Deepfake Calls

Executive Summary

Criminal scam compounds are using hired actors and AI-powered deepfake software to impersonate individuals on live video calls. This tactic is used to add legitimacy to romance and financial scams, manipulating victims into transferring funds by exploiting their trust in a familiar or convincing face.

Key TTPs

  • Initial Access: Scammers establish contact and build relationships through messaging apps, often posing as romantic interests or investment managers.
  • Execution: To close the scam, a live video call is initiated where deepfake software alters a hired actor's face to match the fake persona, thereby deceiving the target.
  • Defense Evasion: The use of real-time, AI-generated video and audio serves to bypass human skepticism and verification methods like requesting a video call.

Campaign Analysis

This marks a significant evolution from text-based scams to highly believable, interactive social engineering attacks. The accessibility of deepfake technology allows even low-skilled operators to execute sophisticated deception at scale, increasing the threat to individuals and corporations.

Targeting & Infrastructure

  • Target Profile: Individuals susceptible to romance scams, cryptocurrency fraud, and other investment schemes.
  • Infrastructure: Operations are run from large-scale "scam compounds" in Southeast Asia, utilizing commercially available deepfake software and hiring actors for video calls.

Relevant Terms

  • Deepfake: AI-generated synthetic media where a person's likeness is replaced with another's, often used in video calls to impersonate someone.
  • Social Engineering: The psychological manipulation of people into performing actions or divulging confidential information.
Source: Malwarebytes

AI Supercharges Ransomware Attacks

Executive Summary

Threat actors are leveraging Artificial Intelligence to automate and accelerate ransomware campaigns. By using AI to enhance social engineering and exploit valid credentials, attackers can bypass traditional security controls with unprecedented speed and scale.

Key Findings

  • Global ransomware attacks saw a 50% year-on-year increase in 2025, with AI-powered tools lowering the barrier for less technical cybercriminals.
  • AI is making phishing more effective, with 87% of organizations stating that AI-generated lures are more convincing.
  • Attackers are "logging in, not breaking in" by using compromised credentials, which were the initial entry point in roughly 1 in 5 breaches.
  • Despite 98% of organizations using Endpoint Detection and Response (EDR) tools, only 25% trust them to defend against modern ransomware threats.

The Bottom Line

The rise of AI-driven ransomware marks a fundamental shift from brute-force entry to stealthy infiltration. Attackers are now mimicking legitimate user behavior to bypass defenses, making perimeter-focused security obsolete. This new paradigm necessitates a strategic pivot towards identity-centric security models and advanced, real-time threat detection to counter adversaries who are already inside the network.

Relevant Terms

  • Threat Actor: An individual or group responsible for a malicious action that impacts the security of a digital device or network.
  • Endpoint Detection and Response (EDR): A cybersecurity solution that continuously monitors end-user devices (endpoints) to detect and respond to cyber threats like ransomware and malware.
Source: Dark Reading

Leaked Exploit Kit Targets iPhones

Executive Summary

DarkSword is a sophisticated exploit kit, now public on GitHub, that targets iPhones running older iOS versions. It chains multiple vulnerabilities to remotely compromise devices and deploy spyware for data exfiltration.

Key Features

  • Full Exploit Chain: Utilizes a chain of six vulnerabilities to achieve remote code execution, sandbox escape, and kernel-level access.
  • Drive-By Infection: Compromises devices through watering hole attacks, where a user is lured into visiting a malicious or compromised website in Safari. No further interaction is required beyond that initial navigation.
  • In-Memory Payload: Operates entirely in memory to steal sensitive data like messages, credentials, and cryptocurrency wallets before removing itself.

Use Case (The "So What?")

The public release of DarkSword lowers the barrier for less-skilled threat actors to target vulnerable devices. Red Teams can use it to simulate advanced threats against outdated mobile endpoints. Blue Teams and SOCs must prioritize patching vulnerable iOS versions (18.4-18.7) and monitor for signs of watering hole attacks and anomalous data exfiltration.

Availability

Open-source on GitHub.

Relevant Terms

  • Exploit Kit: A software toolkit that bundles multiple exploits, designed to identify and attack vulnerabilities on a target system, often through a web browser.
  • Watering Hole Attack: A cyberattack strategy where an attacker compromises a website that is frequently visited by a specific target group, rather than attacking the targets directly.
Source: TechCrunch