CISA warns feds to patch iOS flaws exploited in crypto-theft attacks

2026-03-06T19:23:30Zee3bd37d7773397b7740b39e28e7592d2b3be75864bde0efd7facf6878f3fff7
Bing AICISACisco SD-WANCoruna exploit kitFBI breachGitHub supply-chainInstallFixJavaScript wormUAT-9244User Registration & Membership pluginWikipediaWordPressactive exploitationcrypto-theftiOSinfostealersprivilege escalationspywaresurveillance systemstelecomszero-day

What happened

A set of active and emerging threats across multiple sectors was reported: CISA ordered federal agencies to patch three iOS vulnerabilities exploited by the Coruna exploit kit in crypto-theft and espionage campaigns; WordPress sites are being compromised via a critical User Registration & Membership plugin flaw that creates admin accounts; Cisco flagged actively exploited SD‑WAN vulnerabilities; and a China-linked APT (UAT-9244) is targeting telcos with a new multi-platform toolkit. Other notable incidents include FBI investigation of a breach impacting surveillance/wiretap systems, self‑prop‑

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
ee3bd37d7773397b7740b39e28e7592d2b3be75864bde0efd7facf6878f3fff7
Enrichment time
2026-03-06T19:23:30Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.