1 min read

Monthly Security Bulletin – March 2026

This month’s bulletin covers several major trends:

  • Advanced malware delivery chains: Campaigns like the XWorm phishing operation use Excel exploits, obfuscated HTA and PowerShell, and fileless .NET loaders to inject RAT payloads directly into trusted Windows processes, leaving almost no artifacts on disk.
  • Defense‑evasive ransomware: New ransomware families such as Reynolds embed “bring your own vulnerable driver” (BYOVD) components directly into the payload to kill EDR processes and security tools before encryption even starts.
  • Abuse of trusted platforms and formats: Threat actors increasingly weaponize familiar tools and services – from IPFS‑hosted virtual hard disks and NGINX configurations to Outlook add‑ins and Notepad Markdown links – to deliver malware or hijack web traffic in ways that appear legitimate at first glance.
  • Critical vulnerabilities and active exploitation: The bulletin tracks actively exploited flaws in products like SolarWinds Web Help Desk, FreePBX, GitLab, Microsoft Configuration Manager (SCCM), and Windows Notepad (CVE‑2026‑20841), underscoring the need for rapid patching and continuous exposure management.
  • High‑impact data breaches and identity exposure: Large‑scale incidents such as the Odido customer data breach, as well as the growing industrial “infostealer” economy, show how quickly stolen credentials and personal data are repurposed for account takeover, fraud, and ransomware initial access.

For security teams, the bulletin reinforces several priorities: harden email and endpoint controls against fileless and script‑based attacks, monitor for abnormal driver and process activity, close patch gaps on internet‑facing systems, and treat identity and session data as high‑value assets that require continuous protection and monitoring

 

Read the full report: