SANS Stormcast: Daily Cyber Security News · Johannes Ullrich

SANS Stormcast Friday, March 27th, 2026: TeamPCP Update; DarkSword vs Patches; LangFlow Exploited

March 27, 2026·6 min
The episode opens with Ulrich noting his upcoming attendance at the SANS spring conference in Orlando. The first topic is a follow-up on the TeamPCP supply chain compromise, drawing on a diary entry by SANS instructor Kenneth Hartman. A key new detail: the checkmarks compromise affected all 91 tags, broader than initially reported. Ulrich warns that underreporting is common in such incidents and stresses the importance of rotating credentials even on suspicion alone. He notes that TeamPCP appears to be behind in exploiting the stolen credentials, providing a brief window, but urges organizations to use this as an opportunity to practice routine credential rotation until it becomes reliable and non-disruptive. The second story covers LiteLLM, which was also affected by the same supply chain event. PyPI froze its repository; it has now been restored. LiteLLM announced it will not push new releases until it has completed a review of its CI/CD pipeline and release processes. The most recent clean version remains available. Ulrich endorses this pause as a responsible step. The third story addresses public confusion about the DarkSword exploit set and Apple's March update cycle. Ulrich defines DarkSword as browser-delivered exploits targeting unpatched Apple devices, tracing its roots to a government-sponsored campaign called Corona from July the prior year. He clarifies that this week's Apple updates do not patch DarkSword vulnerabilities; the relevant fixes appeared in iOS 26.3 (February) and older OS updates in early March. Users on iOS 26.3 or later are already protected. Ulrich nonetheless recommends keeping devices updated in case new campaigns target this week's patches, and points to a Google blog post with a detailed timeline of the exploit history. The final story is about Langflow, a visual AI pipeline builder, which had a vulnerability exploited within 20 hours of the patch being published. Sysdig blogged about the active exploitation. Ulrich attributes the speed to the open-source nature of Langflow making source-level diff analysis faster than binary analysis for commercial tools. He advises patching immediately and treating any unpatched Langflow installation as compromised, echoing the credential rotation advice given earlier.
Listen to the show on