Bring the Fight to the Edge: Turning Time Into an Advantage in OT Security

2026-03-04T21:27:13Z9b563c5f40ff8883c99bebbffcf1b580183c949676d8456070b2fa4e5a8f9519
CVE-2025-0921CVE-2026-1281CVE-2026-1340CVE-2026-1731azure-private-endpointbackdoorsbeyondtrustcloud-threat-detectiondosespionageivanti-epmmllm-assisted-attacksmuddled-libranotepadplusplusot-securitypalo-alto-unit42qr-phishingruntime-assemblyscadasparkratsupply-chainthreat-actorsvshellweb-shellszero-day

What happened

Unit 42 published multiple research posts describing active exploitation and emerging threat trends: a critical RCE in BeyondTrust (CVE-2026-1731) is being exploited to deploy VShell and SparkRAT; Ivanti EPMM zero-days (CVE-2026-1281, CVE-2026-1340) are widely exploited to install web shells and backdoors; a SCADA privileged file-system flaw (CVE-2025-0921) can cause DoS; nation-state actors compromised the Notepad++ supply chain; QR-code campaigns and LLM-augmented runtime-assembly JavaScript are being used for sophisticated phishing; Azure Private Endpoint behavior can be abused for DoS; and

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
paloalto_unit42
Record identifier
9b563c5f40ff8883c99bebbffcf1b580183c949676d8456070b2fa4e5a8f9519
Enrichment time
2026-03-04T21:27:13Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.