Oracle released an emergency fix for CVE-2026-21992, a critical (CVSS 9.8) flaw enabling unauthenticated remote code execution in Oracle Identity Manager via HTTP. Security researchers warn the bug may already be exploited, making internet-exposed and unpatched instances high-risk. Organizations should patch immediately, audit for suspicious activity, and restrict external access where possible.
Source: SecurityWeek
Trivy supply-chain incident seeds malicious Docker images with infostealer, worm, and Kubernetes wiper
Following a compromise tied to Trivy, malicious images on Docker Hub propagated an infostealer and triggered worm-like behavior and a Kubernetes-targeting wiper, researchers report. The last known clean Trivy image tag is 0.69.3; malicious 0.69.4–0.69.6 were removed, but downstream clones and cached pulls may persist. Teams should verify image provenance, pin to trusted digests, rotate credentials, and scan clusters for indicators of compromise.
Source: The Hacker News
Actively exploited CVSS 10.0 flaw hits Quest KACE SMA—unpatched systems hijacked
Threat actors are exploiting CVE-2025-32975 (CVSS 10.0) in Quest KACE Systems Management Appliance, with activity observed from the week of March 9 against internet-exposed, unpatched instances. Successful exploitation enables takeover of the appliance, a high-value pivot point in many IT environments. Urgently apply vendor patches, isolate the SMA from the internet, and review logs for anomalous administrative actions.
Source: The Hacker News
FBI/CISA: Russian intelligence-linked actors phishing Signal users to seize high-value accounts
U.S. authorities warn that Russian intelligence-associated hackers are impersonating support on commercial messaging platforms—especially Signal—to phish targets including officials, journalists, and others with sensitive access. The campaign has likely compromised thousands of accounts across messaging apps, leveraging victims’ false sense of security on encrypted platforms. Enable robust account protections, verify support contacts, and train users to spot out-of-band reset scams.
Source: Help Net Security
NIST overhauls DNS security guidance (SP 800-81r3) after more than a decade
NIST released SP 800-81r3, a comprehensive update to the Secure Domain Name System Deployment Guide, modernizing best practices for the first time since 2013. The guidance covers using DNS as a security control, hardening the protocol itself (e.g., DNSSEC, resolver security), and protecting DNS infrastructure operations. Security teams should align controls and architecture reviews with the new recommendations to reduce DNS-based risks and visibility gaps.
Source: Help Net Security
Tycoon 2FA phishing service rebounds to full strength despite takedown
Researchers say Tycoon 2FA—a service criminals use to bypass two-factor authentication in phishing campaigns—is fully operational again, with attack volumes back to pre-disruption levels. Adversary tactics appear unchanged, underscoring the resilience of phishing-as-a-service ecosystems. Organizations should prioritize phishing-resistant authentication (e.g., FIDO2), conditional access, and real-time detection of adversary-in-the-middle proxies.
Source: SecurityWeek
CISA adds Apple, Laravel Livewire, Craft CMS bugs to Known Exploited Vulnerabilities
CISA expanded its KEV catalog with exploited flaws affecting Apple products, Laravel Livewire, and Craft CMS, signaling active threat activity against widely deployed platforms. Federal agencies must remediate by deadlines, and all enterprises should prioritize patching and apply compensating controls where fixes aren’t possible. Mapping assets against KEV entries remains a reliable way to triage real-world risk.
Source: Security Affairs
You May Also Be Interested In...
Global Crackdown Dismantles 4 Botnets Behind Major DDoS Attacks (HackRead)Iran-linked Actors Use Telegram as C2 in Campaigns Targeting Dissidents (Security Affairs)
Visualize Hidden Kubernetes Access Paths with Zero Networks’ Access Matrix (Help Net Security)