A week in security (March 16 – March 22)
2026-03-23T08:51:59Z•3585713c25c4d5195e6aee686dc6525d839865a4530332a0a4e0a95201c05ab4
AI-manipulationAV-evasionCVE-2026-20643ClickFixDarkSwordPureHVNCSEO-poisoningVidarWebKitZombie-ZIPandroid-accessibility-abusebiometric-trackingcalendar-scamchrome-zero-daycrypto-phishingfake-shopsiPhone-exploitinfostealermalwarephishingremote-access-backdoortax-fraudweekly-roundup
What happened
Malwarebytes weekly roundup (Mar 16–22, 2026) covering multiple active threats and defenses: Apple patched a WebKit vulnerability (CVE-2026-20643); Google addressed two Chrome zero-days under active attack; researchers disclosed the DarkSword exploit chain used in state-level iPhone attacks; PureHVNC is spreading via fake job Google Forms; hacked WordPress sites are delivering the Vidar infostealer via fake "verify you are human" pages; the Zombie ZIP technique can evade first-pass antivirus scans; a large network of fake shops and phishing sites (including a fake Pudgy World site) are siphon‑
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- malwarebytes_labs
- Record identifier
- 3585713c25c4d5195e6aee686dc6525d839865a4530332a0a4e0a95201c05ab4
- Enrichment time
- 2026-03-23T08:51:59Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.