Researchers disclose vulnerabilities in IP KVMs from four manufacturers

2026-03-17T20:51:58Zde97891134ea48858a21256f0790dec311b5e8a97d121b07a591b8768adeb152
airsnitchasusbios_remote_accessbotnetcisagithubhttpsinvisible_unicodeiosiot_camerasip_kvmiranian_actorsknown_exploited_vulnerabilitiesllm_deanonymizationmerkle_tree_certificatespassword_manager_risk','vault_exposure','lumma_stealer','malwareprivacy_riskquantum_proofingremote_managementrouter_malwarestrykersupply_chain_attackunicode_bidiwifi_bypasswiper_attack

What happened

Batch of Ars Technica security reports (Mar 2026) covering multiple active threats and supply-chain issues: disclosed vulnerabilities in internet‑exposed IP KVMs (BIOS‑level remote access); an invisible-Unicode supply‑chain attack affecting GitHub and other repos; a destructive wiper attack that disrupted Stryker’s Windows network; ~14,000 routers (mostly Asus, US) infected by resilient malware; apparent Iranian operations targeting consumer security cameras; CISA adding three iOS flaws to its Known Exploited Vulnerabilities catalog; research showing LLMs can deanonymize pseudonymous users at‑

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
arstechnica_security
Record identifier
de97891134ea48858a21256f0790dec311b5e8a97d121b07a591b8768adeb152
Enrichment time
2026-03-17T20:51:58Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.