AI-assisted Slopoly malware powers Hive0163’s ransomware campaigns

2026-03-13T14:51:43Zb7e2091e6def27fbae50e378a8d2706214ca0a2f59e3fa7a7a020e819a3e0454
Hive0163Slopolyai-assisted malwareally-pluginandroidapplebanking-trojanbeatbankerbell-ambulancechromecisacorunadata-breachenisahacktivismhandalaiosknown-exploited-vulnerabilityn8npackage-managersransomwaresql-injectionstrykerwordpresszero-day

What happened

The feed reports multiple high-impact security events: IBM X‑Force links Hive0163 to a new AI‑assisted malware framework (Slopoly) used to maintain persistence in ransomware campaigns; Google patched two actively exploited Chrome flaws (CVE‑2026‑3909, CVE‑2026‑3910); Apple issued emergency iOS/iPadOS fixes for Coruna‑linked exploits on legacy devices; an unauthenticated SQL injection in the Ally WordPress plugin (CVE‑2026‑2413, CVSS 7.5) threatens 400K+ sites; CISA added a critical n8n flaw (CVE‑2025‑68613, CVSS 10.0) to its KEV catalog; a Bell Ambulance breach exposed data for ~238K people; a

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
b7e2091e6def27fbae50e378a8d2706214ca0a2f59e3fa7a7a020e819a3e0454
Enrichment time
2026-03-13T14:51:43Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.