Marquis v. SonicWall Lawsuit Ups the Breach Blame Game
2026-03-04T20:37:49Z•70af03ba1f66e18dab2cc7cba5882509bfb202269360518b373d0a4bc8f39aa5
CVE-2026-20127CVE-2026-2329AI-abuseFortiGateMFA-bypassOT-ICSRMM-abuseSD-WANVoIPdeveloper-supply-chainmobile-malwarenation-statephishingransomwaresupply-chainvulnerabilitieszero-day
What happened
DarkReading roundup of multiple high-impact incidents and trends: a maximum-severity Cisco SD‑WAN zero‑day (CVE-2026-20127) was actively exploited for years; a critical Grandstream VoIP flaw (CVE-2026-2329) allows unauthenticated root access; widespread compromises of FortiGate appliances and several supply‑chain attacks (malicious npm package OpenClaw, Keenadu on Android) were reported. The feed also highlights ransomware and nation‑state activity (Lazarus/Medusa), sophisticated phishing/MFA‑bypass tooling (Starkiller), RMM abuse, developer-targeted malicious Next.js repos, AI/agent abuse and
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- darkreading
- Record identifier
- 70af03ba1f66e18dab2cc7cba5882509bfb202269360518b373d0a4bc8f39aa5
- Enrichment time
- 2026-03-04T20:37:49Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.