CISA warns feds to patch iOS flaws exploited in crypto-theft attacks
2026-03-06T19:23:30Z•ee3bd37d7773397b7740b39e28e7592d2b3be75864bde0efd7facf6878f3fff7
Bing AICISACisco SD-WANCoruna exploit kitFBI breachGitHub supply-chainInstallFixJavaScript wormUAT-9244User Registration & Membership pluginWikipediaWordPressactive exploitationcrypto-theftiOSinfostealersprivilege escalationspywaresurveillance systemstelecomszero-day
What happened
A set of active and emerging threats across multiple sectors was reported: CISA ordered federal agencies to patch three iOS vulnerabilities exploited by the Coruna exploit kit in crypto-theft and espionage campaigns; WordPress sites are being compromised via a critical User Registration & Membership plugin flaw that creates admin accounts; Cisco flagged actively exploited SD‑WAN vulnerabilities; and a China-linked APT (UAT-9244) is targeting telcos with a new multi-platform toolkit. Other notable incidents include FBI investigation of a breach impacting surveillance/wiretap systems, self‑prop‑
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- ee3bd37d7773397b7740b39e28e7592d2b3be75864bde0efd7facf6878f3fff7
- Enrichment time
- 2026-03-06T19:23:30Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.