International police Operation Alice take down 373,000 dark web sites exploiting children

2026-03-23T08:51:43Zf3305bfe501cefda81f80a9227f8b00b20785892971983b2c530bec1b521da0a
Adobe CommerceAppleCISACVE-2026-21992Craft CMSIdentity ManagerKnown Exploited VulnerabilitiesLaravel LivewireMagentoOraclePolyShellRCERussiaSignalWhatsAppWorldLeaks Group','data breach','Navia','PII exposurechild exploitationdark webfile upload vulnerabilitylaw enforcementmass defacementnation-statephishingransomwareweb compromise

What happened

Multiple high-impact security developments: International law enforcement Operation Alice dismantled a vast dark‑web scam hosting ~373,000 fake sites that lured users seeking child sexual abuse material. Russia-linked threat actors ran phishing campaigns to hijack high-value WhatsApp and Signal accounts of officials and journalists. Oracle released a patch for a critical unauthenticated RCE in Identity Manager and Web Services Manager (CVE-2026-21992, CVSS 9.8). CISA added several vulnerabilities (including Apple, Laravel Livewire, and Craft CMS flaws) to its Known Exploited Vulnerabilities (K

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
f3305bfe501cefda81f80a9227f8b00b20785892971983b2c530bec1b521da0a
Enrichment time
2026-03-23T08:51:43Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.