'BlackSanta' EDR Killer Targets HR Workflows
2026-03-10T14:51:45Z•666b791a021f6cf681a596c0900f28aff5a425f94c4cb971f17db1dbd5397d47
AI-enabled-attacksAPTBlackSantaCiscoClaudeEDR-bypassGeminiOpenClawQualcommSD-WANTycoon-2FAVMwareactive-exploitationcloud-securityfirewall-vulnerabilitiesmalvertisingnation-statephishing-as-a-servicesupply-chain-riskzero-day
What happened
Batch of DarkReading reports highlights a surge in high-impact vulnerabilities and active exploitation, widespread nation-state and organized-crime activity, and an uptick in AI-enabled attack techniques. Notable technical issues include an exploited Qualcomm Android zero-day (CVE-2026-21385), a long-exploited Cisco SD‑WAN zero-day (CVE-2026-20127), and dozens of newly patched Cisco firewall flaws (some CVSS 10.0). VMware Aria Operations command-injection exploitation, a critical OpenClaw AI-agent flaw, and bugs in Google’s Gemini/AI panel and Claude-related tooling further raise supply-chain/
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- darkreading
- Record identifier
- 666b791a021f6cf681a596c0900f28aff5a425f94c4cb971f17db1dbd5397d47
- Enrichment time
- 2026-03-10T14:51:45Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.