Researchers disclose vulnerabilities in IP KVMs from four manufacturers
2026-03-17T20:51:58Z•de97891134ea48858a21256f0790dec311b5e8a97d121b07a591b8768adeb152
airsnitchasusbios_remote_accessbotnetcisagithubhttpsinvisible_unicodeiosiot_camerasip_kvmiranian_actorsknown_exploited_vulnerabilitiesllm_deanonymizationmerkle_tree_certificatespassword_manager_risk','vault_exposure','lumma_stealer','malwareprivacy_riskquantum_proofingremote_managementrouter_malwarestrykersupply_chain_attackunicode_bidiwifi_bypasswiper_attack
What happened
Batch of Ars Technica security reports (Mar 2026) covering multiple active threats and supply-chain issues: disclosed vulnerabilities in internet‑exposed IP KVMs (BIOS‑level remote access); an invisible-Unicode supply‑chain attack affecting GitHub and other repos; a destructive wiper attack that disrupted Stryker’s Windows network; ~14,000 routers (mostly Asus, US) infected by resilient malware; apparent Iranian operations targeting consumer security cameras; CISA adding three iOS flaws to its Known Exploited Vulnerabilities catalog; research showing LLMs can deanonymize pseudonymous users at‑
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- arstechnica_security
- Record identifier
- de97891134ea48858a21256f0790dec311b5e8a97d121b07a591b8768adeb152
- Enrichment time
- 2026-03-17T20:51:58Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.