Russia-linked actors target WhatsApp and Signal in phishing campaign
2026-03-23T02:51:51Z•3c5a5ea41bb085c3ab5662f93ed2e1f43970a6c18f3b04a8c688183e8cb7ac90
Adobe CommerceAppleCISACVE-2026-21992Coruna Exploit Kit','DarkSword Exploit KitCraft CMSKnown Exploited VulnerabilitiesLaravel LivewireMagentoNaviaOracle Identity ManagerPolyShellRussia-linkedSignalWhatsAppWorldLeaksaccount takeovercritical vulnerabilitydata breachexploit kitsfile upload vulnerabilityphishingransomwareremote code executionweb defacement
What happened
Recent SecurityAffairs reporting highlights multiple high-impact incidents and vulnerabilities: Russia-linked actors are conducting targeted phishing to hijack WhatsApp and Signal accounts of officials and journalists; Oracle patched a critical unauthenticated RCE in Identity Manager/Web Services Manager (CVE-2026-21992, CVSS 9.8); CISA added Apple, Laravel Livewire and Craft CMS issues to its Known Exploited Vulnerabilities catalog; Sansec disclosed the “PolyShell” unauthenticated file-upload flaw affecting Magento/Adobe Commerce and a separate large-scale campaign has defaced 7,500+ Magento+
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- 3c5a5ea41bb085c3ab5662f93ed2e1f43970a6c18f3b04a8c688183e8cb7ac90
- Enrichment time
- 2026-03-23T02:51:51Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.