CISA Flags SolarWinds, Ivanti, and Workspace One Vulnerabilities as Actively Exploited
2026-03-10T07:24:16Z•f9cf786790cf56b7128a00d94c63913b1b7cba31ce04c92010cd53fdb4e1d3cf
AirDropAnthropicCISAChrome_extension_hijackDust_SpecterFirefox_vulnerabilitiesKnown Exploited VulnerabilitiesLeakBaseLumma_StealerMimikatzMuddyWaterOpenAI_Codex_SecurityRATSD-WANTransparent_TribeTycoon_PhaaSUAT-9244UNC4899VOID#GEISTactive_exploitationcredential_theftmacOSnpm_malwaresupply_chainweb_server_exploits
What happened
A broad set of active threats and notable security developments: CISA added multiple vulnerabilities to its KEV catalog (including CVE-2021-22054 and high‑severity CVE-2017-7921), and Cisco confirmed active exploitation of Catalyst SD‑WAN Manager (CVE-2026-20122). Researchers reported supply‑chain and malware activity — a malicious npm package (@openclaw-ai/openclawai) delivering a RAT and stealing macOS credentials, multi-stage VOID#GEIST deliveries (XWorm/AsyncRAT/Xeno RAT), Chrome extensions turned malicious after ownership transfer enabling code injection and data theft, and the ClickFix/”
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- f9cf786790cf56b7128a00d94c63913b1b7cba31ce04c92010cd53fdb4e1d3cf
- Enrichment time
- 2026-03-10T07:24:16Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.