New RFP Template for AI Usage Control and AI Governance
2026-03-04T23:54:04Z•6079c469d70384d4a1eda4a9d0fba985e81889df47347e0b97d55a8e81a9a40e
CVE-2026-0628CVE-2026-21385CVE-2026-21513CVE-2026-22719AI-securityAPTFortinetOAuth-redirect-abusecommand-and-controlcredential-theftin-the-wild-exploitationknown-exploited-vulnerabilitynpmpackage-manager-malwarepackagistphishingremote-access-trojansupply-chain-malwareweb-shells
What happened
Multiple active and high-risk threats reported: CISA added VMware Aria Operations command-injection flaw (CVE-2026-22719) to its KEV list amid in-the-wild exploitation; Google confirmed exploitation of a Qualcomm Android graphics bug (CVE-2026-21385); Chrome patched a WebView privilege-escalation flaw (CVE-2026-0628); and APT28 is linked to an MSHTML 0-day (CVE-2026-21513). Concurrent campaigns include malicious packages in Packagist and npm deploying cross-platform RATs and Pastebin-based C2, trojanized tools and Go modules delivering backdoors (Rekoobe), phishing and OAuth redirect abuse (St
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 6079c469d70384d4a1eda4a9d0fba985e81889df47347e0b97d55a8e81a9a40e
- Enrichment time
- 2026-03-04T23:54:04Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.