Episode Summary: Episode 8 of The Defensive Line Weekly covers a week dominated by the cyber dimension of the Iran conflict, with MuddyWater pre-positioned in U.S. critical infrastructure and physical drone strikes on A.W.S data centres. We also examine InstallFix — a ClickFix evolution targeting developers via cloned tool installation pages — and a Microsoft oh-auth protocol abuse that turns legitimate Entra ID endpoints into phishing launchers. Notable mentions cover the Coruna iOS exploit kit, record zero-day exploitation data from Google's GTIG, the LexisNexis cloud breach, and a vulnerability roundup.
Main Stories
1. Iran Conflict Cyber Update — MuddyWater, Camera Exploitation, and AWS Strikes
Iran-linked threat group MuddyWater (attributed to Iran’s MOIS) has been embedded in multiple U.S. organisations since early February 2026, deploying the Dindoor and Fakeset backdoors and exfiltrating data via Rclone to Wasabi cloud storage. Check Point Research reported exploitation of patched Hikvision and Dahua camera CVEs across the Middle East. Drone strikes physically damaged four AWS data centres in the UAE and Bahrain.
Sources:
* Symantec/Carbon Black — Iran Cyber Threat Activity
* Check Point Research — Iranian IP Camera Targeting
* BleepingComputer — AWS Data Centre Drone Strikes
* BleepingComputer — NCSC UK Advisory
* AttackIQ — Operation Epic Fury Emulation
2. ClickFix Evolves into InstallFix — Developer Tool Lures Deliver Infostealers and Ransomware
Push Security disclosed InstallFix, a ClickFix variant that clones legitimate developer tool installation pages (e.g., Claude Code) to trick developers into pasting malicious install commands. Distribution is via Google Ads malvertising, hosted on legitimate platforms (Cloudflare Pages, Squarespace). Payloads include Amatera, Lumma, and macOS SHub infostealers. Ransomware group Velvet Tempest (Termite) has adopted the technique to deploy CastleRAT.
Sources:
* Push Security — InstallFix Disclosure
* BleepingComputer — Fake Claude Code Install Guides
* Malwarebytes — Fake CleanMyMac / SHub Stealer
* BleepingComputer — Termite / CastleRAT ClickFix
* DeliverTo — Claude Code InstallFix Test Payload
3. Microsoft OAuth Error-Flow Abuse — Trusted Login URLs Redirect to Phishing and Malware
Microsoft Defender researchers disclosed a campaign abusing the OAuth 2.0 error redirection mechanism to redirect victims from legitimate Microsoft Entra ID endpoints to attacker infrastructure. Lures include e-signature requests, meeting invitations, and password resets. Outcomes include AitM credential theft (EvilProxy) and malware delivery via ZIP/LNK/HTML smuggling. Targeting government and public-sector organisations.
Sources:
* Microsoft — OAuth Redirection Abuse
* BleepingComputer — Microsoft OAuth Error-Flow
* Malwarebytes — OAuth Redirect Analysis
Notable Mentions
Coruna — Spyware-Grade iOS Exploit Kit Enters Criminal Use
Google GTIG disclosed Coruna, a 23-exploit iOS kit (covering iOS 13.0–17.2.1). The kit has moved from a surveillance vendor customer to Russian espionage (UNC6353, Ukraine watering-hole attacks) to Chinese financially motivated actors (UNC6691, crypto theft). CISA added three exploited CVEs to KEV on 5 March 2026. Coruna does not work on iOS 17.3+.
Sources:
* Google GTIG — Coruna iOS Exploit Kit
* BleepingComputer — Coruna Crypto Theft
* iVerify — Coruna Tracking
* BleepingComputer — CISA KEV Coruna
Shrinking Patch Windows — GTIG Zero-Day Report and Zero Day Clock
Google GTIG tracked 90 zero-days exploited in 2025 (up 15%), with enterprise appliances and edge devices representing a record 48%. Zero Day Clock shows mean time-to-exploit has crossed the one-week threshold; 67.2% of exploited CVEs in 2026 are zero-days.
Sources:
* Google GTIG — 2025 Zero-Day Review
* Zero Day Clock
* BleepingComputer — Zero-Day Record
LexisNexis Data Breach — React2Shell Exploited to Pillage AWS
Threat actor FulcrumSec exploited an unpatched React frontend (React2Shell) to pivot into LexisNexis’s AWS environment. A single ECS task role with broad Secrets Manager read access enabled exfiltration of 53 secrets, 3.9 million records, and ~400,000 cloud user profiles including ~118 .gov accounts.
Sources:
* BleepingComputer — LexisNexis Data Breach
* The Register — LexisNexis Breach Details
Vulnerability Roundup
* Cisco Catalyst SD-WAN — CVE-2026-20122 and CVE-2026-20128 now actively exploited (continuation from last week’s CVE-2026-20127, CVSS 10.0). ACSC Hunt Guide | Cisco Advisory
* VMware Aria Operations — CVE-2026-22719, unauthenticated RCE, CISA KEV, CVSS 8.1. Workaround script available. BleepingComputer | Broadcom Advisory
* Qualcomm Android Zero-Day — CVE-2026-21385, integer overflow in Qualcomm Graphics, 235 chipsets affected, under limited active exploitation. Prioritise 2026-03-05 patch level. BleepingComputer
Watchlist: Signed Malware via Stolen EV Certificate
Microsoft reported malware signed with a stolen Extended Validation code-signing certificate, impersonating workplace apps to deploy RMM tools as persistent backdoors.
Source: Microsoft
Subscribe
* Podcast: Available on all major podcast platforms — search The Defensive Line Weekly
* Newsletter: thedefensiveline.substack.com
This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit thedefensiveline.substack.com