Law Enforcement Dismantles SocksEscort Proxy Network in Operation Lightning
2026-03-13T14:52:17Z•72dac27016c881efe2e0642732c811359b4c436d52573b37d540ec76f0dd27df
android-trojanblackhat-activitycisacisco-sd-wandata-breachinfostealerlaw-enforcementllm-bypassmalwaremuddywatern8npix-paymentsproxy-serviceransomwareremote-code-executionsocksescorttakedownwordpress-compromisezero-clickzero-day
What happened
A wave of high-impact activity: international law enforcement carried out multiple takedowns (Operation Lightning/SocksEscort, Tycoon2FA, LeakBase) while attackers and researchers disclosed numerous critical vulnerabilities and active exploitation. Notable technical threats include a critical zero-click RCE in n8n (full server compromise), exploited Cisco SD‑WAN flaws that triggered a CISA emergency directive, FreeScout Mail2Shell zero‑click RCE, ContextCrush and LeakyLooker cloud/SQL issues, and the Coruna iPhone exploit kit. Active malware and campaigns include PixRevolution (Android trojan‑
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- infosecurity_magazine
- Record identifier
- 72dac27016c881efe2e0642732c811359b4c436d52573b37d540ec76f0dd27df
- Enrichment time
- 2026-03-13T14:52:17Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.