Unknown attackers exploit yet another critical SharePoint bug

2026-03-20T07:24:09Z0d0a959b8735b514f058ea735430c61857c107e1f010b52e1dca2d4c69473951
AI-enabled cybercrimeCVE-2026-20131Chrome zero-dayCisco Secure FirewallDarkswordIntuneIranMicrosoftNorth KoreaSharePointShinyHuntersStorm-2561StrykerTelusactive exploitationcredential theftfake VPN clientsiOS exploitnation-stateransomwarespywarezero-day

What happened

A cluster of active, high-impact cyber incidents and vulnerabilities was reported: unknown attackers are exploiting a newly disclosed critical Microsoft SharePoint bug; ransomware actors abused a maximum-severity zero-day in Cisco Secure Firewall Management Center (CVE-2026-20131) prior to patching; Google rushed Chrome updates to fix multiple zero-days already under active attack; and the Darksword iOS exploit kit is being used by spyware vendors and suspected state actors. Separately, an Iran-linked campaign abused Microsoft Intune in the Stryker intrusion prompting US guidance to harden Int

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
theregister_security
Record identifier
0d0a959b8735b514f058ea735430c61857c107e1f010b52e1dca2d4c69473951
Enrichment time
2026-03-20T07:24:09Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.