Speagle Malware Hijacks Cobra DocGuard to Steal Data via Compromised Servers
2026-03-20T01:24:07Z•b8906c64b7016623dfb69733ceef1e6c4442028aee1e2046688f3099b48cc9e6
androidbyovdcisadata-exfiltrationedr-bypassexploit-kitexploited-vulnerabilitiesioslinuxmalwaremobile-malwarenetwork-devicesofacransomwaresupply-chainzero-day
What happened
The feed summarizes a wave of active threats and high-severity vulnerabilities: new malware families and campaigns (Speagle hijacking Cobra DocGuard for stealthy exfiltration, Perseus Android banking malware, GlassWorm repository poisoning, LeakNet and ClickFix-based delivery, Konni/EndRAT, MacSync, DRILLAPP espionage), exploit tooling (DarkSword iOS full-chain exploit kit), and widespread abuse techniques (BYOVD abuse of 34 signed vulnerable drivers to disable EDR). Multiple critical vulnerabilities are being actively exploited or disclosed — notably Cisco FMC insecure deserialization (CVE-2
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- b8906c64b7016623dfb69733ceef1e6c4442028aee1e2046688f3099b48cc9e6
- Enrichment time
- 2026-03-20T01:24:07Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.