Dark Reading Confidential: This Threat Hunter Helped Cops Bust Up An African Cybercrime Syndicate

2026-03-04T20:40:21Zf1297b330f91f979a438d811a9d03e2d30f19a10941fbc35929d16ccc5b2be49
CVE-2026-20127CVE-2026-21385ai-assisted-attacksandroid-exploitcisco-sd-wanfortigateopenclawqualcommransomwaresupply-chainthreat-actorszero-day

What happened

This Dark Reading digest highlights active, high-impact threats and vulnerabilities: a Qualcomm zero-day (CVE-2026-21385) is being exploited in targeted Android attacks (linked to commercial spyware or nation-state actors), and a long-exploited Cisco SD‑WAN zero-day (CVE-2026-20127) has been used in stealthy intrusions for years. Other notable items include a critical OpenClaw vulnerability and a supply-chain incident that pushed OpenClaw via a poisoned npm package, large-scale FortiGate compromises driven by generative AI tooling, exploitation tooling for React2Shell, and multiple ransomware/

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
darkreading
Record identifier
f1297b330f91f979a438d811a9d03e2d30f19a10941fbc35929d16ccc5b2be49
Enrichment time
2026-03-04T20:40:21Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Dark Reading Confidential: This Threat Hunter Helped Cops Bust Up An African Cybercrime Syndicate · Baitaphish