CISA Flags SolarWinds, Ivanti, and Workspace One Vulnerabilities as Actively Exploited

2026-03-10T07:24:16Zf9cf786790cf56b7128a00d94c63913b1b7cba31ce04c92010cd53fdb4e1d3cf
AirDropAnthropicCISAChrome_extension_hijackDust_SpecterFirefox_vulnerabilitiesKnown Exploited VulnerabilitiesLeakBaseLumma_StealerMimikatzMuddyWaterOpenAI_Codex_SecurityRATSD-WANTransparent_TribeTycoon_PhaaSUAT-9244UNC4899VOID#GEISTactive_exploitationcredential_theftmacOSnpm_malwaresupply_chainweb_server_exploits

What happened

A broad set of active threats and notable security developments: CISA added multiple vulnerabilities to its KEV catalog (including CVE-2021-22054 and high‑severity CVE-2017-7921), and Cisco confirmed active exploitation of Catalyst SD‑WAN Manager (CVE-2026-20122). Researchers reported supply‑chain and malware activity — a malicious npm package (@openclaw-ai/openclawai) delivering a RAT and stealing macOS credentials, multi-stage VOID#GEIST deliveries (XWorm/AsyncRAT/Xeno RAT), Chrome extensions turned malicious after ownership transfer enabling code injection and data theft, and the ClickFix/”

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
f9cf786790cf56b7128a00d94c63913b1b7cba31ce04c92010cd53fdb4e1d3cf
Enrichment time
2026-03-10T07:24:16Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.