7,500+ Magento sites defaced in global hacking campaign

2026-03-21T02:51:45Z962214eff668d8f736b9bc60f8b927d036f3bc31aab5726e65425d28c80b64e4
aisurucisacisco-fmccorunacve-2025-66376cve-2026-20131darksworddata-breachinterlock-ransomwareios-exploit-kitiot-botnetjackskidkimwolfknown-exploited-vulnerabilitylaw-enforcementmagentonaviastrava-opsecubiquiti-unifiweb-defacementxsszimbra

What happened

Collection of mid-March 2026 security incidents: a widespread opportunistic campaign defaced over 7,500 Magento sites (affecting ~15,000 hostnames); Navia Benefit Solutions disclosed a breach impacting ~2.7 million individuals; Apple warned of active exploit kits (Coruna, DarkSword) targeting outdated iPhones and urged updates; law enforcement disrupted C2 for multiple IoT botnets (AISURU, Kimwolf, JackSkid, Mossad); a Strava OPSEC leak exposed the French carrier Charles de Gaulle. Multiple critical vulnerabilities were highlighted: Ubiquiti patched a maximum-severity UniFi account-takeover flo

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
962214eff668d8f736b9bc60f8b927d036f3bc31aab5726e65425d28c80b64e4
Enrichment time
2026-03-21T02:51:45Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.