Microsoft Patch Tuesday security updates for March 2026 fixed 84 bugs
2026-03-11T02:51:46Z•f4956f58ce3ad79ed6e6a269498864cb80590787a402981db4877976a26436b6
2fa-phishingapt28aurainspectorbeardshellcisa-KEVcognizantconfiguration-theftcovenantericssonfbi-alertfortigatehealthcare-breachivantimicrosoftomnissapatch-tuesdayphishingrussia-linkedsalesforcesignalsolarwindsthird-party-breachtrizettotycoonwhatsapp
What happened
SecurityAffairs feed (Mar 9–10, 2026) covers multiple high-impact incidents: Microsoft’s March Patch Tuesday fixed 84 vulnerabilities across Windows, Office, Edge, Azure, SQL Server, Hyper‑V and ReFS (no known active exploitation reported). Attackers are exploiting FortiGate devices—via vulnerabilities or weak credentials—to exfiltrate configuration files containing service-account credentials and network details. ESET attributes long‑term espionage against Ukrainian forces to APT28, which used BEARDSHELL and COVENANT malware since April 2024. Threat actors are mass‑scanning Salesforce Sales /
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- f4956f58ce3ad79ed6e6a269498864cb80590787a402981db4877976a26436b6
- Enrichment time
- 2026-03-11T02:51:46Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.