The Good, the Bad and the Ugly in Cybersecurity – Week 12
2026-03-20T20:51:52Z•3bc2fcbe49c3d0147cc03df0d9c8806500ac5b0250cf9074717c26fc8e924d16
active-directoryai-securityautonomous-agentscisco-zero-dayclaude-codeclawseccybercrimedarksworddependency-hijackdspmexfiltrationfortigateinterlockinterpoliosirannation-statentds.ditoneclawrmmsentinellabssentinelonessosupply-chainzero-day
What happened
SentinelOne blog roundup highlighting multiple high-risk developments: Interpol disrupted cybercrime networks; DarkSword is stealing iOS personal data; an actor named “Interlock” is exploiting a Cisco zero-day to breach enterprise firewalls; and FortiGate SSO flaws are being abused to steal device configs, harvest Active Directory credentials, deploy RMM tooling, and exfiltrate NTDS (deep AD compromise). The feed also includes an intelligence brief warning of elevated Iran-linked activity, and a set of posts on AI/agent security (OneClaw, ClawSec), supply-chain risk from AI coding plugins (a “
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sentinelone_blog
- Record identifier
- 3bc2fcbe49c3d0147cc03df0d9c8806500ac5b0250cf9074717c26fc8e924d16
- Enrichment time
- 2026-03-20T20:51:52Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.