Ethical Hacking News
A new round of the weekly Security Affairs newsletter has arrived! In this edition, we delve into a myriad of pressing cybersecurity concerns that have been making headlines in recent times. From vulnerabilities in Magento and Adobe Commerce to data breaches and emerging threats, we provide an in-depth look at the current state of the global cybersecurity landscape.
The PolyShell flaw has exposed Magento and Adobe Commerce to file upload attacks, rendering them vulnerable.A global hacking campaign has left 7,500+ Magento sites defaced, highlighting the need for robust security measures.The Navia data breach has exposed nearly 2.7 million people to potential threats.Apple's urging for iPhone users to update their devices due to the Coruna and DarkSword exploit kits underscores the ongoing threat landscape.A global law enforcement operation targeting AISURU, Kimwolf, JackSkid botnet operators highlights collaborative efforts to combat cybersecurity threats.A French aircraft carrier was tracked via Strava activity in an OPSEC failure, demonstrating the importance of operational security measures.A critical Ubiquiti UniFi security flaw has been discovered, allowing potential account hijacking.The U.S. CISA has added a flaw in Cisco FMC and Cisco SCC Firewall Management to its Known Exploited Vulnerabilities catalog.Researchers have warned of an unpatched, critical Telnetd flaw affecting all versions.The emergence of CVE-2026-3888: Ubuntu Desktop 24.04+ vulnerable to Root exploit highlights the need for prompt attention to emerging threats.A data breach at robotic surgery firm Intuitive has left sensitive information exposed.The EU sanctions Chinese and Iranian actors over cyberattacks on critical infrastructure, emphasizing cooperation in combating cybersecurity threats.
The world of cybersecurity is a realm where the boundaries of technological advancements and human ingenuity are constantly being pushed to their limits. The rapid evolution of digital landscapes has created new avenues for malicious actors to exploit, further solidifying the need for robust security measures that protect not just individuals but also organizations and governments worldwide. In this edition of the Security Affairs newsletter, we delve into a myriad of pressing cybersecurity concerns that have been making headlines in recent times.
At the forefront of these concerns is the PolyShell flaw, which has exposed Magento and Adobe Commerce to file upload attacks, thereby rendering them vulnerable to exploitation by malicious actors. The sheer scale of the impact, with 7,500+ Magento sites being defaced globally, underscores the far-reaching implications of this vulnerability. This incident highlights the importance of vigilance in the face of technological advancements, as they often bring new avenues for attack.
Furthermore, a global hacking campaign has left its mark on 7,500+ Magento sites, further emphasizing the need for robust security measures to be implemented across these platforms. The sheer scale of this campaign underscores the level of sophistication and resources that malicious actors are willing to devote to such endeavors, serving as a stark reminder of the ongoing cat-and-mouse game between cybersecurity professionals and threat actors.
In a related development, the Navia data breach has left nearly 2.7 million people exposed to potential threats. This incident serves as a poignant reminder of the importance of robust security measures in protecting sensitive information and highlights the need for vigilance in the face of emerging threats.
The emergence of Apple's urging for iPhone users to update their devices due to the Coruna and DarkSword exploit kits has brought attention to the ongoing threat landscape. These exploit kits, which have been making headlines in recent times, underscore the constant evolution of malicious actors' tactics, further emphasizing the need for vigilance and robust security measures.
The global law enforcement operation targeting AISURU, Kimwolf, JackSkid botnet operators serves as a testament to the collaborative efforts being made worldwide to combat cybersecurity threats. This operation highlights the growing recognition of the importance of cooperation between governments and law enforcement agencies in tackling complex cybersecurity challenges.
In an interesting development, French aircraft carrier Charles de Gaulle was tracked via Strava activity in OPSEC failure, demonstrating the far-reaching implications of such incidents. This incident serves as a stark reminder of the ongoing importance of OPSEC (Operational Security) measures in protecting sensitive information and operations.
A critical Ubiquiti UniFi security flaw has been discovered, allowing potential account hijacking. This incident underscores the need for vigilance in the face of emerging threats and highlights the importance of robust security measures in protecting sensitive information and operations.
The U.S. CISA (Cybersecurity and Infrastructure Security Agency) has added a flaw in Cisco FMC and Cisco SCC Firewall Management to its Known Exploited Vulnerabilities catalog, further emphasizing the need for vigilance and robust security measures. This addition serves as a stark reminder of the ongoing importance of staying informed about emerging threats.
Researchers have warned of an unpatched, critical Telnetd flaw affecting all versions, thereby underscoring the need for prompt attention to such vulnerabilities. The severity of this vulnerability highlights the importance of regular software updates and patches in maintaining robust security measures.
The emergence of CVE-2026-3888: Ubuntu Desktop 24.04+ vulnerable to Root exploit serves as a poignant reminder of the ongoing importance of vigilance and robust security measures. This vulnerability underscores the need for prompt attention to emerging threats and highlights the importance of regular software updates and patches in maintaining robust security measures.
A data breach at robotic surgery firm Intuitive has left sensitive information exposed, serving as a stark reminder of the ongoing importance of robust security measures in protecting sensitive information. This incident highlights the need for vigilance in the face of emerging threats and underscores the importance of robust security measures in protecting sensitive information.
In a related development, tracking the Iran War: A Month of Escalation and Regional Impact has brought attention to the ongoing regional tensions surrounding the conflict. This incident serves as a poignant reminder of the far-reaching implications of such conflicts and highlights the need for vigilance and robust security measures in protecting sensitive information and operations.
The EU sanctions Chinese and Iranian actors over cyberattacks on critical infrastructure, further emphasizing the growing recognition of the importance of cooperation between governments and law enforcement agencies in tackling complex cybersecurity challenges. This development serves as a stark reminder of the ongoing importance of collaboration in combating emerging threats.
In conclusion, this edition of the Security Affairs newsletter underscores the pressing nature of various cybersecurity concerns that have been making headlines in recent times. These incidents serve as poignant reminders of the ongoing importance of vigilance and robust security measures in protecting sensitive information and operations.
Related Information:
https://www.ethicalhackingnews.com/articles/The-Global-Landscape-of-Cybersecurity-Threats-A-Weekly-Roundup-ehn.shtml
https://securityaffairs.com/189765/breaking-news/security-affairs-newsletter-round-568-by-pierluigi-paganini-international-edition.html
https://cybernoz.com/security-affairs-newsletter-round-567-by-pierluigi-paganini-international-edition/
https://www.bleepingcomputer.com/news/security/new-polyshell-flaw-allows-unauthenticated-rce-on-magento-e-stores/
https://thehackernews.com/2026/03/magento-polyshell-flaw-enables.html
https://www.bleepingcomputer.com/news/security/navia-discloses-data-breach-impacting-27-million-people/
https://www.hipaajournal.com/navia-benefit-solutions-data-breach/
https://cloud.google.com/blog/topics/threat-intelligence/coruna-powerful-ios-exploit-kit
https://www.forbes.com/sites/kateoflahertyuk/2026/03/07/new-powerful-ios-attack-warning-issued-to-millions-of-iphone-users/
https://time.com/article/2026/03/19/iphone-hack-spyware-malware-darksword-cyberattacks/
https://www.bleepingcomputer.com/news/security/new-darksword-ios-exploit-used-in-infostealer-attack-on-iphones/
https://www.bsi.bund.de/EN/Themen/Verbraucherinnen-und-Verbraucher/Cyber-Sicherheitslage/Methoden-der-Cyber-Kriminalitaet/Botnetze/Steckbriefe-aktueller-Botnetze/Steckbriefe/Aisuru/aisuru.html
https://www.bleepingcomputer.com/news/security/aisuru-kimwolf-jackskid-and-mossad-botnets-disrupted-in-joint-action/
https://krebsonsecurity.com/2026/01/the-kimwolf-botnet-is-stalking-your-local-network/
https://cyberscoop.com/botnet-disruption-aisuru-kimwolf-jackskid-mossad/
https://www.bleepingcomputer.com/news/security/ubiquiti-warns-of-unifi-flaw-that-may-enable-account-takeover/
https://cybersecuritynews.com/ubiquiti-unifi-vulnerabilities/
https://thehackernews.com/2026/03/interlock-ransomware-exploits-cisco-fmc.html
https://www.bleepingcomputer.com/news/security/interlock-ransomware-exploited-secure-fmc-flaw-in-zero-day-attacks-since-january/
https://cybersecuritynews.com/cisco-firewall-0-day-exploited/
https://cyberpress.org/telnetd-vulnerability/
https://cybersecuritynews.com/telnetd-vulnerability-enables-remote-attack/
Published: Sat Mar 21 21:13:50 2026 by llama3.2 3B Q4_K_M