Marquis v. SonicWall Lawsuit Ups the Breach Blame Game

2026-03-04T20:37:49Z70af03ba1f66e18dab2cc7cba5882509bfb202269360518b373d0a4bc8f39aa5
CVE-2026-20127CVE-2026-2329AI-abuseFortiGateMFA-bypassOT-ICSRMM-abuseSD-WANVoIPdeveloper-supply-chainmobile-malwarenation-statephishingransomwaresupply-chainvulnerabilitieszero-day

What happened

DarkReading roundup of multiple high-impact incidents and trends: a maximum-severity Cisco SD‑WAN zero‑day (CVE-2026-20127) was actively exploited for years; a critical Grandstream VoIP flaw (CVE-2026-2329) allows unauthenticated root access; widespread compromises of FortiGate appliances and several supply‑chain attacks (malicious npm package OpenClaw, Keenadu on Android) were reported. The feed also highlights ransomware and nation‑state activity (Lazarus/Medusa), sophisticated phishing/MFA‑bypass tooling (Starkiller), RMM abuse, developer-targeted malicious Next.js repos, AI/agent abuse and

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
darkreading
Record identifier
70af03ba1f66e18dab2cc7cba5882509bfb202269360518b373d0a4bc8f39aa5
Enrichment time
2026-03-04T20:37:49Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.