Bring the Fight to the Edge: Turning Time Into an Advantage in OT Security
2026-03-04T21:27:13Z•9b563c5f40ff8883c99bebbffcf1b580183c949676d8456070b2fa4e5a8f9519
CVE-2025-0921CVE-2026-1281CVE-2026-1340CVE-2026-1731azure-private-endpointbackdoorsbeyondtrustcloud-threat-detectiondosespionageivanti-epmmllm-assisted-attacksmuddled-libranotepadplusplusot-securitypalo-alto-unit42qr-phishingruntime-assemblyscadasparkratsupply-chainthreat-actorsvshellweb-shellszero-day
What happened
Unit 42 published multiple research posts describing active exploitation and emerging threat trends: a critical RCE in BeyondTrust (CVE-2026-1731) is being exploited to deploy VShell and SparkRAT; Ivanti EPMM zero-days (CVE-2026-1281, CVE-2026-1340) are widely exploited to install web shells and backdoors; a SCADA privileged file-system flaw (CVE-2025-0921) can cause DoS; nation-state actors compromised the Notepad++ supply chain; QR-code campaigns and LLM-augmented runtime-assembly JavaScript are being used for sophisticated phishing; Azure Private Endpoint behavior can be abused for DoS; and
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- paloalto_unit42
- Record identifier
- 9b563c5f40ff8883c99bebbffcf1b580183c949676d8456070b2fa4e5a8f9519
- Enrichment time
- 2026-03-04T21:27:13Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.