2026-03-14: Threat actors are mass-distributing fake VPN clients via SEO poisoning to steal credentials episode artwork

EPISODE · Mar 14, 2026 · 22 MIN

2026-03-14: Threat actors are mass-distributing fake VPN clients via SEO poisoning to steal credentials

from Cyber Threat Brief

Show Notes - 2026-03-14 Stories Covered: - Today: - Google Chrome Vulnerabilities Added to CISA KEV (CVE-2026-3909, CVE-2026-3910) (https://www.cisa.gov/news-events/alerts/2026/03/13/cisa-adds-two-known-exploited-vulnerabilities-catalog) - Microsoft Patch Tuesday (79 Vulnerabilities, 2 Zero-Days) (https://www.sentinelone.com/blog/the-good-the-bad-and-the-ugly-in-cybersecurity-week-11-7/) - FortiGate Next-Gen Firewalls Exploited for Network Access (https://www.sentinelone.com/blog/the-good-the-bad-and-the-ugly-in-cybersecurity-week-11-7/) - Storm-2561 Campaign: Fake VPN Clients Steal Credentials (https://www.bleepingcomputer.com/news/security/fake-enterprise-vpn-downloads-used-to-steal-company-credentials/) - New ClickFix Variant Uses WebDAV Mapping (https://thehackernews.com/2026/03/investigating-new-click-fix-variant.html) - INTERPOL Operation Synergia III: 45,000 Malicious IPs Sinkholed (https://www.bleepingcomputer.com/news/security/police-sinkholes-45-000-ip-addresses-in-cybercrime-crackdown/) - SmartApeSG Campaign Pushes Remcos RAT via ClickFix (https://isc.sans.edu/diary/rss/32796) - FBI Investigation: Malicious Steam Games Spread Cryptodrainas and Infostealers (https://www.bleepingcomputer.com/news/security/fbi-seeks-victims-of-steam-games-used-to-spread-malware/) - Windows 11 February 2026 Updates Cause C:\ Drive Access Denial on Samsung PCs (https://www.bleepingcomputer.com/news/microsoft/microsoft-windows-11-users-cant-access-c-drive-on-some-samsung-pcs/) - BlackCat Insider Charged: Former DigitalMint Employee Conspired with Ransomware Group (https://www.sentinelone.com/blog/the-good-the-bad-and-the-ugly-in-cybersecurity-week-11-7/) - SocksEscort Cybercrime Proxy Network Dismantled (https://www.sentinelone.com/blog/the-good-the-bad-and-the-ugly-in-cybersecurity-week-11-7/) - Classic Outlook Bugs: Sync Issues, Connection Errors, Disappearing Mouse Pointer (https://www.bleepingcomputer.com/news/microsoft/microsoft-investigates-classic-outlook-sync-and-connection-issues/) - Poland's Nuclear Research Centre Targeted by Cyberattack (https://www.bleepingcomputer.com/news/security/polands-nuclear-research-centre-targeted-by-cyberattack/) - Meta to Discontinue Instagram End-to-End Encryption After May 2026 (https://thehackernews.com/2026/03/meta-to-shut-down-instagram-end-to-end.html) - GitHub Removes Premium Models from Free Copilot Student Plan (https://go.theregister.com/feed/www.theregister.com/2026/03/13/microsoft_github_removes_models_student_plan/) - CVE-2026-27171 (zlib CPU Consumption) (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-27171) - CVE-2026-31802 (node-tar Symlink Path Traversal) (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-31802) - CVE-2026-3381 (Perl Compress::Raw::Zlib) (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-3381) - CVE-2026-0385 (Microsoft Edge for Android Spoofing) (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-0385) - Multiple Chromium Vulnerabilities (Microsoft Edge) (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-3942) CVEs Referenced: CVE-2025-59718, CVE-2025-59719, CVE-2026-0385, CVE-2026-21262, CVE-2026-24858, CVE-2026-26127, CVE-2026-26144, CVE-2026-27171, CVE-2026-31802, CVE-2026-3381, CVE-2026-3909, CVE-2026-3910, CVE-2026-3926, CVE-2026-3929, CVE-2026-3930, CVE-2026-3931, CVE-2026-3939, CVE-2026-3941, CVE-2026-3942 Indicators of Compromise: Domains: 170[.]255, 170[.]155, 170[.]155. Full brief: https://carolinacleartech.com/brief/2026-03-14/

Episode metadata supplied by the publisher feed · Published Mar 14, 2026

Embed this episode

Show Notes - 2026-03-14 Stories Covered: - Today: - Google Chrome Vulnerabilities Added to CISA KEV (CVE-2026-3909, CVE-2026-3910) (https://www.cisa.gov/news-events/alerts/2026/03/13/cisa-adds-two-known-exploited-vulnerabilities-catalog) - Microsoft Patch Tuesday (79 Vulnerabilities, 2 Zero-Days) (

Distinct summary based on available episode metadata or transcript content.

Ready to play

2026-03-14: Threat actors are mass-distributing fake VPN clients via SEO poisoning to steal credentials

0:00 22:44

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

Frequently Asked Questions

How long is this episode of Cyber Threat Brief?

This episode is 22 minutes long.

When was this Cyber Threat Brief episode published?

This episode was published on March 14, 2026.

Can I download this Cyber Threat Brief episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!