Russian Threat Actor Sednit Resurfaces With Sophisticated Toolkit

2026-03-10T20:51:42Z47ca756c00480da2a6809c19f2cf312ac3c3ff615b5ea08e12808790e7ef699e
AI-abuseAPTBlackSantaCiscoCisco SD-WANEDR-bypassOpenClawQualcommSednitTycoonVMware Ariacloud-securityexploit-in-the-wildmalvertisingmalwarenation-statephishing-as-a-servicezero-day

What happened

DarkReading digest highlights a surge in sophisticated nation-state and criminal activity plus multiple high-impact vulnerabilities. Notable items: Russia-linked Sednit returns with two advanced toolsets; 'BlackSanta' campaign bypasses EDR via HR workflow hijacking; multiple zero-days and exploits in the wild including a long-exploited Cisco SD‑WAN flaw and a Qualcomm Android memory-corruption zero-day; VMware Aria Operations command-injection exploitation; critical OpenClaw AI-agent vulnerability; widespread phishing-as-a-service takedown (Tycoon) and campaigns abusing AI (fake Claude code/mc

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
darkreading
Record identifier
47ca756c00480da2a6809c19f2cf312ac3c3ff615b5ea08e12808790e7ef699e
Enrichment time
2026-03-10T20:51:42Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.