A week in security (March 16 – March 22)

2026-03-23T08:51:59Z3585713c25c4d5195e6aee686dc6525d839865a4530332a0a4e0a95201c05ab4
AI-manipulationAV-evasionCVE-2026-20643ClickFixDarkSwordPureHVNCSEO-poisoningVidarWebKitZombie-ZIPandroid-accessibility-abusebiometric-trackingcalendar-scamchrome-zero-daycrypto-phishingfake-shopsiPhone-exploitinfostealermalwarephishingremote-access-backdoortax-fraudweekly-roundup

What happened

Malwarebytes weekly roundup (Mar 16–22, 2026) covering multiple active threats and defenses: Apple patched a WebKit vulnerability (CVE-2026-20643); Google addressed two Chrome zero-days under active attack; researchers disclosed the DarkSword exploit chain used in state-level iPhone attacks; PureHVNC is spreading via fake job Google Forms; hacked WordPress sites are delivering the Vidar infostealer via fake "verify you are human" pages; the Zombie ZIP technique can evade first-pass antivirus scans; a large network of fake shops and phishing sites (including a fake Pudgy World site) are siphon‑

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
malwarebytes_labs
Record identifier
3585713c25c4d5195e6aee686dc6525d839865a4530332a0a4e0a95201c05ab4
Enrichment time
2026-03-23T08:51:59Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · A week in security (March 16 – March 22) · Baitaphish