← HOME LIVE FEED
--:-- CT
--
⚡ CRITICAL: CVE-2025-32975 Quest KACE SMA actively exploited /// ⚡ Trivy GitHub Actions supply chain attack by TeamPCP /// 🔴 Oracle Identity Manager CVE-2026-21992 CVSS 9.8 — patch now /// ⚡ Citrix NetScaler ADC/Gateway dual CVE patch released /// 📡 FBI: Iranian-linked Handala abusing Telegram as C2 /// 🌐 INTERPOL takes down 45,000+ malicious IPs across 72 countries /// 🛡 Magento defacement hits ~15,000 hostnames incl. Toyota, FedEx, ASUS
Top stories — 26 march 2026
Active CVEs requiring immediate action
⚡ Hot Vulnerabilities — March 26, 2026
CVE-2026-21992
CVSS 9.8
Oracle Identity Manager unauthenticated RCE. Emergency out-of-band patch issued. Update immediately.
Severity
CVE-2025-32975
CVSS 10.0
Quest KACE SMA authentication bypass allowing full admin account takeover. Actively exploited in wild.
Severity
CVE-2026-3055
CVSS 9.3
Citrix NetScaler ADC/Gateway — insufficient input validation causing memory overread of sensitive data.
Severity
CVE-2026-33634
CVSS 9.4
Trivy GitHub Actions supply chain compromise. Force-pushed malicious tags steal CI/CD secrets and cloud credentials.
Severity
Breaking & Developing
Nation-State

FBI Warns: Iranian Handala Group Abusing Telegram as Malware C2

The FBI issued a warning that Iranian-linked threat groups including Handala are abusing Telegram as command-and-control infrastructure to deliver Windows malware targeting journalists, dissidents, and political opponents. Attacks have included Intune-based remote device wipes, rendering victims' devices inoperable. The advisory urges organizations to restrict Telegram on managed endpoints.

Supply Chain

29+ npm Packages Backdoored via Compromised Publisher Accounts

Attackers compromised legitimate npm publisher credentials to republish over 29 packages under the @emilgroup namespace and @teale.io/eslint-config with malicious payloads. Altered releases install a Linux backdoor through systemd user services and use an Internet Computer canister as a rotating channel for follow-on payload delivery, making takedowns difficult.

Ransomware

Stryker Rebuilds After Iranian Actors Wipe 80,000 Devices via Intune

Medical technology company Stryker continues recovery after a cyberattack attributed to pro-Iranian actors who gained access via a compromised Intune admin account, triggering remote wipes across roughly 80,000 devices. Up to 50TB of data may have been exfiltrated in the incident. The attack highlights the danger of management plane tools (MDM, Intune) as high-value targets.

Infrastructure

INTERPOL Dismantles 45,000+ Malicious IPs Across 72 Nations, 94 Arrests

In a major coordinated action, INTERPOL and partners across 72 countries seized infrastructure behind phishing, malware, and ransomware ecosystems, taking down over 45,000 malicious IPs and servers and arresting 94 individuals. The scale of the takedown signals that criminal cyber infrastructure has reached industrial levels of specialization and automation.

Web Security

Mass Magento Defacement Hits 15,000 Hostnames Including Toyota, FedEx, ASUS

An ongoing defacement campaign active since February 27 has compromised roughly 15,000 hostnames across 7,500 Magento domains. High-profile victims include Toyota, ASUS, FedEx, Yamaha, and Lindt, as well as regional governments and universities. Attackers exploit an unauthenticated file upload path in exposed Magento environments to deploy plaintext defacement files.

Threat Intel

SILENTCONNECT Loader Uses Fake Invitations & PowerShell to Deploy ScreenConnect

A newly identified .NET loader dubbed SILENTCONNECT, active since March 2025, uses phishing lures disguised as meeting invitations to deliver ScreenConnect RMM software. The chain downloads C# source from Google Drive, compiles and executes it in memory via PowerShell, adds a Windows Defender exclusion, and bypasses UAC via the CMSTPLUA COM interface. It uses PEB masquerading to impersonate winhlp32.exe to evade detection.

Live World Threat Map
Active Attack Origins — Loading...
LIVE FEED
Fetching live threat intel...
RU · APT28 IR · Handala CN · State KP · UNC1069 UA · TeamPCP SEA · Botnet GB · npm Supply US TARGET EQUATOR
Nation-State (RU · IR · CN · KP)
Ransomware / Botnet
Supply Chain
Known Target
Hover dots for details
01
Nation-State

APT28 OPSEC Failure Exposes 2,800+ Exfiltrated Government Emails & 11,500 Contacts

A critical operational security failure exposed the C2 infrastructure of APT28 (FancyBear), leaking 2,800+ exfiltrated government and military emails, 240+ credential and TOTP sets, and over 11,500 harvested contacts spanning Ukraine, Romania, Bulgaria, Greece, and Serbia. The exposure provides rare intelligence into the scale of Russian state-sponsored espionage campaigns targeting Eastern European nations.

02
Gov Advisory

FBI & CISA: Russian Intelligence Hijacking Signal Accounts for Espionage & Follow-On Phishing

A joint FBI/CISA advisory warns that Russian intelligence actors are conducting campaigns to hijack commercial messaging apps — particularly Signal — to take over accounts, monitor communications in real time, and enable further targeted phishing. The advisory urges users to verify linked devices in Signal settings and enable registration lock features immediately.

03
Policy

WEF Global Cybersecurity Outlook 2026: 87% of Leaders See AI Vulnerabilities as Fastest-Growing Risk

The World Economic Forum's Global Cybersecurity Outlook 2026, based on data from 800 global leaders, finds that while AI security assessments before deployment have nearly doubled (37% to 64%), 87% of respondents flag AI-related vulnerabilities as the fastest-growing cyber threat category. The report highlights widening "cyber equity" gaps, geopolitical fragmentation, and diverging risk priorities between CEOs (fraud/phishing) and CISOs (ransomware).

04
IoT / Botnet

Aisuru, Kimwolf, JackSkid & Mossad Botnets Seized After Compromising 3M+ IoT Devices

International authorities seized infrastructure behind four IoT botnets — Aisuru, Kimwolf, JackSkid, and Mossad — which collectively compromised over three million devices and were responsible for record-breaking DDoS attacks. The coordinated takedown marks a significant blow to the for-hire DDoS ecosystem, though operators are likely to reconstitute using fresh infrastructure.