Daily Briefing

CyberGeoDigest

Geopolitical cyber intelligence in 5 minutes
Friday, March 20, 2026 · 20 stories
Share this digest:

Russia's APT28 Exploits Zimbra Flaw in Ukrainian Gov Attacks (1 minute read)

GRU-linked APT28 is actively exploiting a Zimbra Collaboration Suite vulnerability against Ukrainian government targets.

BleepingComputer · 16h ago · Read full article →

🇷🇺 APT28 · Russia 🇷🇺 GRU · Russia

US Feds Monitor for Iranian Cyberattacks After Stryker Breach (1 minute read)

DOD and CISA officials report no visible surge in Iranian cyber activity following recent tensions, while responding to a Stryker breach.

CyberScoop · 13h ago · Read full article →

US Intelligence Community's Threat Assessment Centers on Iran (1 minute read)

The IC's latest global threat assessment heavily emphasizes Iran as a top priority. The focus reflects how the Iran conflict has reshuffled U.S. intelligence priorities.

Foreign Policy · 10h ago · Read full article →

Iran Built Resilient Cyberattack Infrastructure Before US Strikes (1 minute read)

Iran spent six months pre-positioning cyber infrastructure, including US-based shell companies, to survive kinetic strikes and sustain hacking operations.

SecurityWeek · 16h ago · Read full article →

US Military Struggles to Keep Pace With Drone Warfare Evolution (3 minute read)

Defense industry leaders warn the U.S. military's procurement processes are too slow to match rapidly evolving drone and counter-drone threats. Acquisition reform is now a battlefield necessity.

War on the Rocks · 23h ago · Read full article →

South Korean Weapons Now Active in Iran War Theater (1 minute read)

Seoul's arms exports are being used in the Iran conflict, exposing political risks the defense industry ignored. South Korea now faces diplomatic fallout from its weapons' battlefield use.

The Diplomat · 17h ago · Read full article →

Iran-Linked Attackers Wipe Stryker Data via Microsoft Intune (1 minute read)

Iran-linked hackers breached Stryker using Microsoft Intune—no malware, just legitimate device management tools used to wipe data. FBI and CISA warn Intune is an under-secured attack vector.

The Record · 15h ago · Read full article →

US Warns Companies to Lock Down Microsoft Intune After Stryker Breach (1 minute read)

Iran-linked attackers wiped Stryker employee devices by abusing Microsoft Intune's legitimate management capabilities. CISA and FBI urge organizations to harden Intune configurations immediately.

The Register Security · 15h ago · Read full article →

Donroe Doctrine Reshapes China's Economic Statecraft Options (3 minute read)

Trump-era interventionism in Iran and Venezuela, plus Greenland threats, are forcing Beijing to recalibrate economic statecraft ahead of a US-China summit. Europe is hedging by deepening China ties.

War on the Rocks · just now · Read full article →

Trump Praises Japan's Takaichi Over Iran War Support (1 minute read)

Trump lauded Japan's Takaichi for 'stepping up' on the Iran conflict, but Tokyo resists direct military involvement in the Strait of Hormuz.

Foreign Policy · 10h ago · Read full article →

Trump Backs Japan's Takaichi as Tokyo Stays Wary on Iran (1 minute read)

Trump praised Takaichi's support for the Iran war, but Japan remains reluctant to commit forces near the Strait of Hormuz.

Foreign Policy · 10h ago · Read full article →

Iran War Forces Japan to Confront Collective Self-Defense Limits (1 minute read)

The Iran-Israel-US conflict is testing whether Japan can legally deploy the SDF to the Strait of Hormuz. Tokyo's classification of the conflict is complicated by the U.S. having struck first.

The Diplomat · 19h ago · Read full article →

North Korea's Lazarus Group Hits Crypto Gift Card Platform Bitrefill (1 minute read)

Bitrefill attributes a recent cyberattack to North Korea's Bluenoroff subgroup of Lazarus. Lazarus continues targeting crypto platforms to fund regime operations.

BleepingComputer · 14h ago · Read full article →

🇰🇵 Lazarus · North Korea

Interlock Ransomware Exploited Cisco Firewall Zero-Day Before Patch (1 minute read)

Amazon reports Interlock ransomware used a Cisco firewall zero-day weeks before public disclosure. Pre-patch exploitation highlights the danger of undisclosed flaws in perimeter security hardware.

The Record · 17h ago · Read full article →

Tax Season Triggers Surge in Phishing and Malware Campaigns (1 minute read)

Microsoft Threat Intelligence documents threat actors exploiting tax deadlines via refund lures, fake payroll forms, and QR codes to deliver malware.

Microsoft Threat Intelligence · 16h ago · Read full article →

DarkSword iOS Exploit Kit Chains Six Flaws for Full Takeover (1 minute read)

Multiple threat actors, including commercial spyware vendors and state-sponsored groups, have deployed the DarkSword iOS exploit kit using three zero-days since November 2025.

The Hacker News · 22h ago · Read full article →

54 EDR Killers Abuse 35 Vulnerable Drivers to Blind Security Tools (1 minute read)

Analysis finds 54 EDR-killing tools use BYOVD techniques exploiting 35 signed vulnerable drivers to disable endpoint security before ransomware deployment.

The Hacker News · 12h ago · Read full article →

Unknown Attackers Exploit Critical Microsoft SharePoint Bug in Wild (1 minute read)

CISA warns unidentified threat actors are actively exploiting a critical SharePoint vulnerability to compromise servers.

The Register Security · 12h ago · Read full article →

CISA Warns of DoS Vulnerability in Schneider Electric PLCs (3 minute read)

Schneider Electric Modicon M241, M251, and M262 controllers contain a flaw enabling denial-of-service attacks. Unpatched industrial controllers remain high-value targets for infrastructure disruption.

CISA Alerts · 19h ago · Read full article →

CISA Flags Actively Exploited Cisco Firewall Deserialization Flaw (3 minute read)

CISA added CVE-2026-20131, a deserialization vulnerability in Cisco's Secure Firewall Management Center, to its KEV catalog. Federal agencies must patch immediately under BOD 22-01.

CISA Alerts · 19h ago · Read full article →

Get this in your inbox

Free daily briefing. No spam. Unsubscribe anytime.

Subscribe Now