Cyber Security Week in Review: March 13, 2026
In brief: Google fixes two Chrome zero-days, CISA updates its KEV list with four new entries, and more.
In brief: Google fixes two Chrome zero-days, CISA updates its KEV list with four new entries, and more.
The directory contained what appears to be a complete exploitation framework designed to target vulnerabilities in Roundcube.
The attackers combined social engineering with advanced evasion techniques to infiltrate corporate systems and steal data.
The company patched two publicly disclosed flaws; neither has been observed to be actively exploited in attacks.
The malware’s operators mainly exploit home and small-office networking equipment.
Attackers are exploiting recently disclosed vulnerabilities or weak credentials to gain access to FortiGate devices.
The threat actor has been using the BeardShell and Covenant custom malware implants since April 2024.
Organizations are recommended to patch the vulnerabilities as soon as possible.
Instead of relying on established off-the-shelf malware, the group is now creating disposable binaries across multiple programming languages.
The attackers are trying to obtain verification and PIN codes that protect accounts on the messaging platforms.
Showing elements 1 - 10