CISA orders feds to patch n8n RCE flaw exploited in attacks
2026-03-11T19:23:30Z•b67e32ea6b634c1c9a3f9f90e5434269d65d33908611e4d48d5a88eab32c37e0
AOS-CXASUS routersAndroid malwareArubaBeatBankerBlackSantaCISAEDR evasionHPEHandalaIvanti EPMKadNapMicrosoft Patch TuesdayPhantomRavenRCEStrykeradmin password resetbotnetmalicious apps','Zombie ZIP','evasion techniques','patching','v2n8nnpmremote code executionsupply-chainwiperzero-day
What happened
Multiple high-impact security developments: CISA ordered federal agencies to urgently patch an actively exploited n8n remote code execution (RCE) vulnerability; CISA also flagged an actively exploited Ivanti Endpoint Manager flaw. Microsoft released March 2026 Patch Tuesday updates (79 flaws, including two zero-days) and separate Windows 10/11 cumulative/extended updates. HPE patched critical Aruba AOS‑CX issues that could allow admin password resets. In incident activity, Stryker suffered an Iran‑linked Handala wiper attack; PhantomRaven supply‑chain waves pushed 88 malicious npm packages to偷
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- b67e32ea6b634c1c9a3f9f90e5434269d65d33908611e4d48d5a88eab32c37e0
- Enrichment time
- 2026-03-11T19:23:30Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.