Russian Threat Actor Sednit Resurfaces With Sophisticated Toolkit
2026-03-10T20:51:42Z•47ca756c00480da2a6809c19f2cf312ac3c3ff615b5ea08e12808790e7ef699e
AI-abuseAPTBlackSantaCiscoCisco SD-WANEDR-bypassOpenClawQualcommSednitTycoonVMware Ariacloud-securityexploit-in-the-wildmalvertisingmalwarenation-statephishing-as-a-servicezero-day
What happened
DarkReading digest highlights a surge in sophisticated nation-state and criminal activity plus multiple high-impact vulnerabilities. Notable items: Russia-linked Sednit returns with two advanced toolsets; 'BlackSanta' campaign bypasses EDR via HR workflow hijacking; multiple zero-days and exploits in the wild including a long-exploited Cisco SD‑WAN flaw and a Qualcomm Android memory-corruption zero-day; VMware Aria Operations command-injection exploitation; critical OpenClaw AI-agent vulnerability; widespread phishing-as-a-service takedown (Tycoon) and campaigns abusing AI (fake Claude code/mc
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- darkreading
- Record identifier
- 47ca756c00480da2a6809c19f2cf312ac3c3ff615b5ea08e12808790e7ef699e
- Enrichment time
- 2026-03-10T20:51:42Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.