BT
Privacy ToolboxJournalProjectsResumeBookmarks
Feed
Privacy Toolbox
Journal
Projects
Resume
Bookmarks
Intel
CIPHER
The Vault
Threat Actors
Privacy Threats
Malware IoC
Dashboard
CVEs
Tags
Intel
CIPHERThe VaultThreat ActorsPrivacy ThreatsMalware IoCDashboardCVEsTags

Intel

  • Feed
  • Threat Actors
  • Privacy Threats
  • Dashboard
  • Privacy Toolbox
  • CVEs

Personal

  • Journal
  • Projects

Resources

  • Subscribe
  • Bookmarks
  • Developers
  • Tags
Cybersecurity News & Analysis
github
defconxt
•
© 2026
•
blacktemple.net
  1. Feed
  2. /CISA KEV Additions, TeamPCP Supply Chain Attacks, and Critical Infrastructure Under Fire

CISA KEV Additions, TeamPCP Supply Chain Attacks, and Critical Infrastructure Under Fire

criticalVulnerabilities & Exploits|March 28, 20263 min read

Originally reported by The Hacker News, Microsoft Security, SANS ISC, MSRC Security Updates

#cve#cisa-kev#supply-chain#citrix#f5#ios-exploits#pypi#teamPCP
Share

TL;DR

CISA confirmed active exploitation of a critical F5 BIG-IP vulnerability, while Citrix NetScaler faces reconnaissance for a CVSS 9.3 flaw. TeamPCP threat actors have expanded their supply chain campaign to target PyPI packages.

Why critical?

CISA added CVE-2025-53521 to the KEV catalog with confirmed active exploitation of F5 BIG-IP systems, and Citrix NetScaler is under active reconnaissance for a CVSS 9.3 vulnerability.

Critical Infrastructure Under Active Attack

F5 BIG-IP Exploitation Confirmed by CISA

CISA added CVE-2025-53521 (CVSS 9.3) to its Known Exploited Vulnerabilities catalog following confirmed active exploitation of F5 BIG-IP Access Policy Manager systems. The vulnerability enables remote code execution, representing a significant threat to enterprise network infrastructure. Federal agencies must patch affected systems by the mandated deadline.

Citrix NetScaler Under Active Reconnaissance

Defused Cyber and watchTowr report active reconnaissance against Citrix NetScaler ADC and Gateway systems targeting CVE-2026-3055 (CVSS 9.3). The memory overread vulnerability stems from insufficient input validation and could expose sensitive information. Organizations running affected NetScaler deployments should prioritize patching as threat actors map vulnerable targets.

Supply Chain Campaign Escalation

TeamPCP Targets Telnyx Python Package

The TeamPCP threat group has expanded their supply chain attack beyond Trivy, KICS, and litellm to compromise the Telnyx Python package. Versions 4.87.1 and 4.87.2 published to PyPI conceal credential harvesting capabilities within WAV audio files. The sophisticated obfuscation technique demonstrates the group's evolving tactics for evading detection in developer environments.

Open VSX Pipeline Vulnerability Patched

Researchers disclosed a now-patched vulnerability in Open VSX's pre-publish scanning pipeline that could allow malicious Visual Studio Code extensions to bypass security checks. The flaw involved ambiguous boolean return values that failed to distinguish between unconfigured scanners and scanner failures, potentially allowing malicious extensions into the registry.

State-Sponsored Mobile Targeting

Russian APT Deploys DarkSword iOS Exploit Kit

Proofpoint attributes a targeted spear-phishing campaign to TA446 (Callisto), a Russian state-sponsored group deploying the recently disclosed DarkSword iOS exploit kit. The campaign represents an escalation in mobile device targeting by nation-state actors, leveraging sophisticated zero-day exploitation capabilities against iOS devices.

Apple Issues Emergency Lock Screen Notifications

Apple has begun sending lock screen notifications to devices running outdated iOS and iPadOS versions, warning of active web-based exploits targeting unpatched systems. The unprecedented direct notification approach indicates serious ongoing exploitation of known vulnerabilities in older iOS versions.

Additional CVE Disclosures

Enterprise Software Vulnerabilities

Microsoft's security update guide published several new CVEs:

  • CVE-2026-33343: etcd nested transaction vulnerability bypassing RBAC authorization
  • CVE-2026-2369: libsoup buffer overread from integer underflow
  • CVE-2026-4673: Chromium WebAudio heap buffer overflow
  • CVE-2026-32187: Microsoft Edge defense-in-depth vulnerability

These vulnerabilities affect core enterprise infrastructure components and require assessment for applicable environments.

Microsoft Defender Enhancement

Microsoft detailed how Defender applies asset-aware protection using Security Exposure Management to defend high-value targets including domain controllers and identity infrastructure. The approach prioritizes protection based on asset criticality and attack likelihood.

Sources

  • https://thehackernews.com/2026/03/citrix-netscaler-under-active-recon-for.html
  • https://thehackernews.com/2026/03/cisa-adds-cve-2025-53521-to-kev-after.html
  • https://thehackernews.com/2026/03/ta446-deploys-leaked-darksword-ios.html
  • https://thehackernews.com/2026/03/apple-sends-lock-screen-alerts-to.html
  • https://thehackernews.com/2026/03/teampcp-pushes-malicious-telnyx.html
  • https://thehackernews.com/2026/03/open-vsx-bug-let-malicious-vs-code.html
  • https://www.microsoft.com/en-us/security/blog/2026/03/27/microsoft-defender-protects-high-value-assets/
  • https://isc.sans.edu/diary/rss/32838
  • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33343
  • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-2369
  • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-4673
  • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32187

Originally reported by The Hacker News, Microsoft Security, SANS ISC, MSRC Security Updates

Tags

#cve#cisa-kev#supply-chain#citrix#f5#ios-exploits#pypi#teamPCP

Threat Actors

🇷🇺Star Blizzard

Tracked Companies

🇺🇸Apple

Related Intelligence

  • CISA KEV Updates, APT28 Campaign, and Agentic AI Security Challenges

    criticalMar 10, 2026
  • CISA Adds FileZen to KEV as Multiple Critical Vulnerabilities Surface

    criticalFeb 25, 2026
  • Critical Zero-Day Roundup: Dell RecoverPoint Exploited Since 2024, VoIP Phones Under Attack

    criticalFeb 18, 2026

Related Knowledge

  • CIPHER Training: Vulnerability Research Deep Dive

    offensive
  • CIPHER Web Security Deep Dive — Training Knowledge Base

    offensive
  • CIPHER Offensive Security Deep Reference

    offensive

Explore

  • Dashboard
  • Privacy Threats
  • Threat Actors
← Back to the feed

Previous Article

← Data Breach Roundup: FBI Chief's Gmail Compromised, BreachForums Database Leaked