'BlackSanta' EDR Killer Targets HR Workflows

2026-03-10T14:51:45Z666b791a021f6cf681a596c0900f28aff5a425f94c4cb971f17db1dbd5397d47
AI-enabled-attacksAPTBlackSantaCiscoClaudeEDR-bypassGeminiOpenClawQualcommSD-WANTycoon-2FAVMwareactive-exploitationcloud-securityfirewall-vulnerabilitiesmalvertisingnation-statephishing-as-a-servicesupply-chain-riskzero-day

What happened

Batch of DarkReading reports highlights a surge in high-impact vulnerabilities and active exploitation, widespread nation-state and organized-crime activity, and an uptick in AI-enabled attack techniques. Notable technical issues include an exploited Qualcomm Android zero-day (CVE-2026-21385), a long-exploited Cisco SD‑WAN zero-day (CVE-2026-20127), and dozens of newly patched Cisco firewall flaws (some CVSS 10.0). VMware Aria Operations command-injection exploitation, a critical OpenClaw AI-agent flaw, and bugs in Google’s Gemini/AI panel and Claude-related tooling further raise supply-chain/

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
darkreading
Record identifier
666b791a021f6cf681a596c0900f28aff5a425f94c4cb971f17db1dbd5397d47
Enrichment time
2026-03-10T14:51:45Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.