New RFP Template for AI Usage Control and AI Governance

2026-03-04T23:54:04Z6079c469d70384d4a1eda4a9d0fba985e81889df47347e0b97d55a8e81a9a40e
CVE-2026-0628CVE-2026-21385CVE-2026-21513CVE-2026-22719AI-securityAPTFortinetOAuth-redirect-abusecommand-and-controlcredential-theftin-the-wild-exploitationknown-exploited-vulnerabilitynpmpackage-manager-malwarepackagistphishingremote-access-trojansupply-chain-malwareweb-shells

What happened

Multiple active and high-risk threats reported: CISA added VMware Aria Operations command-injection flaw (CVE-2026-22719) to its KEV list amid in-the-wild exploitation; Google confirmed exploitation of a Qualcomm Android graphics bug (CVE-2026-21385); Chrome patched a WebView privilege-escalation flaw (CVE-2026-0628); and APT28 is linked to an MSHTML 0-day (CVE-2026-21513). Concurrent campaigns include malicious packages in Packagist and npm deploying cross-platform RATs and Pastebin-based C2, trojanized tools and Go modules delivering backdoors (Rekoobe), phishing and OAuth redirect abuse (St

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
6079c469d70384d4a1eda4a9d0fba985e81889df47347e0b97d55a8e81a9a40e
Enrichment time
2026-03-04T23:54:04Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.