AI Agents: The Next Wave Identity Dark Matter - Powerful, Invisible, and Unmanaged
2026-03-04T22:33:25Z•0b3ffc3a629cdaedf396b1d5dd6f976cc319c420de77d2f35c60fdd4d6af5540
CVE-2026-0628CVE-2026-20127CVE-2026-21385CVE-2026-21513APT28AitMChrome WebViewCisco SD-WANGemini API key exposureGo module malwareMFA-bypassMSHTMLNuGetOAuth redirect abuseOpenClaw/AI agent flawQualcomm Androidactive exploitationblockchain C2botnetmalicious packagesnpmphishingremote code executionsupply-chain riskweb shellszero-day
What happened
This collection of The Hacker News reports highlights a surge of high-impact vulnerabilities, active exploitation campaigns, and abuse of trust services. Notable technical issues include a Cisco SD‑WAN authentication bypass (CVE-2026-20127, CVSS 10.0) under active exploitation, a Qualcomm graphics buffer over‑read used in the wild (CVE-2026-21385), a Chrome WebView privilege-escalation flaw (CVE-2026-0628), and an MSHTML feature-bypass 0‑day tied to APT28 (CVE-2026-21513). Threat activity spans MFA-bypassing AitM phishing (Starkiller), OAuth redirect abuse targeting government orgs, supply‑and
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 0b3ffc3a629cdaedf396b1d5dd6f976cc319c420de77d2f35c60fdd4d6af5540
- Enrichment time
- 2026-03-04T22:33:25Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.