Navia data breach impacts nearly 2.7 Million people

2026-03-20T20:51:47Z0394a64ae644609cec2114f17959082959f8a57bcfde9656d92819d0e119926b
account-takeoveraisurubotnet-disruptioncisaciscocorunacve-2025-66376cve-2026-20131darksworddata-breachexploit-kitfmcinterlockios-exploitjackskid','mossad?','mossad'kimwolfknown-exploited-vulnerabilitieslookoutnaviaransomwaresccunifiu‑bitiqi‑unifixsszimbra

What happened

Multiple security incidents and disclosures: Navia Benefit Solutions disclosed a data breach exposing about 2.7 million individuals after attacker access from Dec 2025–Jan 2026. Apple warned of active iOS exploit kits (DarkSword and Coruna) targeting outdated iPhones; DarkSword is being used by multiple actors in global campaigns. Ubiquiti patched two UniFi flaws including a maximum-severity account-takeover issue. U.S. CISA added a critical Cisco Secure Firewall Management Center (FMC) / Security Cloud Control (SCC) flaw (CVE-2026-20131) to its Known Exploited Vulnerabilities catalog; the RCE

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
0394a64ae644609cec2114f17959082959f8a57bcfde9656d92819d0e119926b
Enrichment time
2026-03-20T20:51:47Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.