Apple pushes first Background Security Improvements update to fix WebKit flaw
2026-03-18T07:23:27Z•4daa4abfb7e850b6ffaf8f07c84e9e6fb1759c3438d9ab7bea96b5080acff01e
AI securityAppleCVE-2026-20643ChinaClickFixDenoEU sanctionsGitHubGlassWormIranLeakNetMicrosoftOpenVSXStrykerVSCodeWebKitWing FTP Serveractive exploitdevice wipefont-rendering attacknpmprompt-hidingransomwareshadow AIsupply-chain
What happened
Multiple high-impact security developments: Apple issued a Background Security Improvements update to address a WebKit flaw (CVE-2026-20643) across iPhones, iPads and Macs without requiring full OS upgrades. The GlassWorm supply‑chain campaign resurfaced, compromising 400+ code repositories and packages across GitHub, npm and VSCode/OpenVSX ecosystems. CISA flagged an actively exploited Wing FTP Server vulnerability that may be chained to remote code execution. Ransomware group LeakNet is using ClickFix for initial access and a Deno‑based loader; a separate incident at Stryker involved a large
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 4daa4abfb7e850b6ffaf8f07c84e9e6fb1759c3438d9ab7bea96b5080acff01e
- Enrichment time
- 2026-03-18T07:23:27Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.