Speagle Malware Hijacks Cobra DocGuard to Steal Data via Compromised Servers

2026-03-20T01:24:07Zb8906c64b7016623dfb69733ceef1e6c4442028aee1e2046688f3099b48cc9e6
androidbyovdcisadata-exfiltrationedr-bypassexploit-kitexploited-vulnerabilitiesioslinuxmalwaremobile-malwarenetwork-devicesofacransomwaresupply-chainzero-day

What happened

The feed summarizes a wave of active threats and high-severity vulnerabilities: new malware families and campaigns (Speagle hijacking Cobra DocGuard for stealthy exfiltration, Perseus Android banking malware, GlassWorm repository poisoning, LeakNet and ClickFix-based delivery, Konni/EndRAT, MacSync, DRILLAPP espionage), exploit tooling (DarkSword iOS full-chain exploit kit), and widespread abuse techniques (BYOVD abuse of 34 signed vulnerable drivers to disable EDR). Multiple critical vulnerabilities are being actively exploited or disclosed — notably Cisco FMC insecure deserialization (CVE-‍2

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
b8906c64b7016623dfb69733ceef1e6c4442028aee1e2046688f3099b48cc9e6
Enrichment time
2026-03-20T01:24:07Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.