Apple pushes first Background Security Improvements update to fix WebKit flaw

2026-03-18T07:23:27Z4daa4abfb7e850b6ffaf8f07c84e9e6fb1759c3438d9ab7bea96b5080acff01e
AI securityAppleCVE-2026-20643ChinaClickFixDenoEU sanctionsGitHubGlassWormIranLeakNetMicrosoftOpenVSXStrykerVSCodeWebKitWing FTP Serveractive exploitdevice wipefont-rendering attacknpmprompt-hidingransomwareshadow AIsupply-chain

What happened

Multiple high-impact security developments: Apple issued a Background Security Improvements update to address a WebKit flaw (CVE-2026-20643) across iPhones, iPads and Macs without requiring full OS upgrades. The GlassWorm supply‑chain campaign resurfaced, compromising 400+ code repositories and packages across GitHub, npm and VSCode/OpenVSX ecosystems. CISA flagged an actively exploited Wing FTP Server vulnerability that may be chained to remote code execution. Ransomware group LeakNet is using ClickFix for initial access and a Deno‑based loader; a separate incident at Stryker involved a large

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
4daa4abfb7e850b6ffaf8f07c84e9e6fb1759c3438d9ab7bea96b5080acff01e
Enrichment time
2026-03-18T07:23:27Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Apple pushes first Background Security Improvements update to fix WebKit flaw · Baitaphish