Microsoft Patch Tuesday security updates for March 2026 fixed 84 bugs

2026-03-11T02:51:46Zf4956f58ce3ad79ed6e6a269498864cb80590787a402981db4877976a26436b6
2fa-phishingapt28aurainspectorbeardshellcisa-KEVcognizantconfiguration-theftcovenantericssonfbi-alertfortigatehealthcare-breachivantimicrosoftomnissapatch-tuesdayphishingrussia-linkedsalesforcesignalsolarwindsthird-party-breachtrizettotycoonwhatsapp

What happened

SecurityAffairs feed (Mar 9–10, 2026) covers multiple high-impact incidents: Microsoft’s March Patch Tuesday fixed 84 vulnerabilities across Windows, Office, Edge, Azure, SQL Server, Hyper‑V and ReFS (no known active exploitation reported). Attackers are exploiting FortiGate devices—via vulnerabilities or weak credentials—to exfiltrate configuration files containing service-account credentials and network details. ESET attributes long‑term espionage against Ukrainian forces to APT28, which used BEARDSHELL and COVENANT malware since April 2024. Threat actors are mass‑scanning Salesforce Sales /

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
f4956f58ce3ad79ed6e6a269498864cb80590787a402981db4877976a26436b6
Enrichment time
2026-03-11T02:51:46Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.