Russia-linked actors target WhatsApp and Signal in phishing campaign

2026-03-23T02:51:51Z3c5a5ea41bb085c3ab5662f93ed2e1f43970a6c18f3b04a8c688183e8cb7ac90
Adobe CommerceAppleCISACVE-2026-21992Coruna Exploit Kit','DarkSword Exploit KitCraft CMSKnown Exploited VulnerabilitiesLaravel LivewireMagentoNaviaOracle Identity ManagerPolyShellRussia-linkedSignalWhatsAppWorldLeaksaccount takeovercritical vulnerabilitydata breachexploit kitsfile upload vulnerabilityphishingransomwareremote code executionweb defacement

What happened

Recent SecurityAffairs reporting highlights multiple high-impact incidents and vulnerabilities: Russia-linked actors are conducting targeted phishing to hijack WhatsApp and Signal accounts of officials and journalists; Oracle patched a critical unauthenticated RCE in Identity Manager/Web Services Manager (CVE-2026-21992, CVSS 9.8); CISA added Apple, Laravel Livewire and Craft CMS issues to its Known Exploited Vulnerabilities catalog; Sansec disclosed the “PolyShell” unauthenticated file-upload flaw affecting Magento/Adobe Commerce and a separate large-scale campaign has defaced 7,500+ Magento+

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
3c5a5ea41bb085c3ab5662f93ed2e1f43970a6c18f3b04a8c688183e8cb7ac90
Enrichment time
2026-03-23T02:51:51Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.