Russia-linked actors target WhatsApp and Signal in phishing campaign

2026-03-22T20:51:47Z78691050b67b1f8e69cae1aa639c6f8395beb1b3314d7267e4d6925d6a267236
Adobe-CommerceCISACVE-2026-21992CorunaDarkSwordKnown-Exploited-VulnerabilitiesMagentoNaviaOracle Identity ManagerPolyShellRussian-linked-actorsSignalWhatsAppWorldLeaksdata-breachexploit-kitsmessaging-app-hijackphishingransomwareweb-application-vulnerability

What happened

This SecurityAffairs roundup covers multiple high-impact incidents and vulnerabilities: Russia-linked actors are phishing to hijack WhatsApp and Signal accounts of officials and journalists; Oracle patched a critical unauthenticated RCE in Identity Manager/Web Services Manager (CVE-2026-21992, CVSS 9.8); CISA added several Apple, Laravel Livewire and Craft CMS flaws to its Known Exploited Vulnerabilities catalog; Sansec disclosed the “PolyShell” unauthenticated file-upload flaw affecting Magento/Adobe Commerce; a large-scale campaign defaced over 7,500 Magento sites; WorldLeaks ransomware hit,

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
78691050b67b1f8e69cae1aa639c6f8395beb1b3314d7267e4d6925d6a267236
Enrichment time
2026-03-22T20:51:47Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.