Security Affairs newsletter Round 565 by Pierluigi Paganini – INTERNATIONAL EDITION

2026-03-04T21:43:29Z215931fe1647f92f2995ede29d23f1eac64f6d10fe44750f499f0e302fbed933
CVE-2026-21902.env-exposureAI-incident-responseAeternum-botnetCanadian-TireDefender-evasionIranJuniperLOLBinsManoManoMicrosoftPTX-routerPolygon-smart-contractsPowerShellRATRCEblockchain-C2data-breachinternet-blackoutmisconfigurationtrojanized-gaming-utilities

What happened

This SecurityAffairs digest highlights multiple high-impact incidents: two large retail breaches (Canadian Tire and ManoMano) exposing ~38 million accounts each; Juniper released an out-of-band patch for a critical PTX router RCE (CVE-2026-21902, CVSS 9.3); Microsoft warned of a campaign delivering a stealthy RAT via trojanized gaming utilities using PowerShell, LOLBins and Defender-evasion; Qrator Labs uncovered the Aeternum botnet using Polygon smart contracts for decentralized C2; NetBlocks reported a near-total Iran internet blackout amid strikes; Mysterium VPN found ~12M exposed .env file

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
215931fe1647f92f2995ede29d23f1eac64f6d10fe44750f499f0e302fbed933
Enrichment time
2026-03-04T21:43:29Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.