Dark Reading Confidential: This Threat Hunter Helped Cops Bust Up An African Cybercrime Syndicate
2026-03-04T20:40:21Z•f1297b330f91f979a438d811a9d03e2d30f19a10941fbc35929d16ccc5b2be49
CVE-2026-20127CVE-2026-21385ai-assisted-attacksandroid-exploitcisco-sd-wanfortigateopenclawqualcommransomwaresupply-chainthreat-actorszero-day
What happened
This Dark Reading digest highlights active, high-impact threats and vulnerabilities: a Qualcomm zero-day (CVE-2026-21385) is being exploited in targeted Android attacks (linked to commercial spyware or nation-state actors), and a long-exploited Cisco SD‑WAN zero-day (CVE-2026-20127) has been used in stealthy intrusions for years. Other notable items include a critical OpenClaw vulnerability and a supply-chain incident that pushed OpenClaw via a poisoned npm package, large-scale FortiGate compromises driven by generative AI tooling, exploitation tooling for React2Shell, and multiple ransomware/
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- darkreading
- Record identifier
- f1297b330f91f979a438d811a9d03e2d30f19a10941fbc35929d16ccc5b2be49
- Enrichment time
- 2026-03-04T20:40:21Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.