RSAC 2026 Conference Announcements Summary (Pre-Event)

2026-03-24T07:24:08Z8461ec0ba7f86c5c92d90f963ef44ae836ddda023eb2e57958f1cb54df1f75a5
cve-2025-32975cve-2026-21992education-sectoridentity-managerincident-responseinitial-accesslaw-enforcementm-trendsoraclepwn2ownqnapquest-kaceransomwaresupply-chain-attacktrivytycoon-2fa

What happened

SecurityWeek roundup covering multiple 23–20 Mar 2026 stories: Oracle issued an emergency patch for a critical unauthenticated RCE in Identity Manager (CVE-2026-21992) that may be exploited in the wild; Quest KACE vulnerability (CVE-2025-32975) may have been used against education targets. Other highlights include a Trivy supply-chain compromise that published a malicious scanner release, a ransomware incident at Trio-Tech’s Singapore subsidiary, QNAP patching four Pwn2Own-exploited flaws, Mandiant’s M‑Trends finding that initial access handoffs can occur in seconds, and reports on Tycoon 2FA,

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityweek
Record identifier
8461ec0ba7f86c5c92d90f963ef44ae836ddda023eb2e57958f1cb54df1f75a5
Enrichment time
2026-03-24T07:24:08Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.