Ransomware gang exploits Cisco flaw in zero-day attacks since January March 18, 2026 The Interlock ransomware gang has been exploiting a maximum severity remote code execution (RCE) vulnerability in Cisco’s Secure Firewall Management
ConnectWise patches new flaw allowing ScreenConnect hijacking March 18, 2026 ConnectWise is warning ScreenConnect customers of a cryptographic signature verification vulnerability that could lead to unauthorized access and privilege escalation. The
CISA orders feds to patch Zimbra XSS flaw exploited in attacks March 18, 2026 CISA has ordered U.S. government agencies to secure their servers against an actively exploited vulnerability in the Zimbra Collaboration Suite
GlassWorm malware hits 400+ code repos on GitHub, npm, VSCode, OpenVSX March 18, 2026 The GlassWorm supply-chain campaign has returned with a new, coordinated attack that targeted hundreds of packages, repositories, and extensions on
Apple pushes first Background Security Improvements update to fix WebKit flaw March 18, 2026 Apple has released its first Background Security Improvements update to fix a WebKit flaw tracked as CVE-2026-20643 on iPhones, iPads,