Apple pushes first Background Security Improvements update to fix WebKit flaw

2026-03-18T13:23:28Z75ba51beacf43a923d16a0a7b77d759ed09f8ffa4b33dfc1729134c470c780ec
AI prompt hidingApple Background Security ImprovementsCISACVE-2026-20643ClickFixCompanies House data exposureDeno runtimeEU sanctionsExchange Online outageGitHubGlassWormLeakNetMicrosoft 365 CopilotOpenVSXOutlook Teams add-in issueStryker device wipeVSCodeWebKitWindows hotpatchWing FTP Serveractive exploitationfont-rendering attacknpmransomwaresupply-chain

What happened

A cluster of high-impact security stories: Apple issued a Background Security Improvements update to patch a WebKit flaw (CVE-2026-20643) without a full OS upgrade; the GlassWorm supply-chain campaign resurfaced, infecting 400+ repositories and packages across GitHub, npm, VSCode and OpenVSX; CISA warned of an actively exploited Wing FTP Server vulnerability that may enable RCE; and the LeakNet ransomware group is leveraging ClickFix for initial access and a Deno-based loader. Other notable items include EU sanctions tied to cyberattacks, a new font-rendering technique that hides malicious/AI-

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
75ba51beacf43a923d16a0a7b77d759ed09f8ffa4b33dfc1729134c470c780ec
Enrichment time
2026-03-18T13:23:28Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Apple pushes first Background Security Improvements update to fix WebKit flaw · Baitaphish