CVE-2026-21643, CVE-2026-3098
IP Addresses:
3.5.1.34
Get tomorrow's brief in your inbox
Today: Fortinet FortiClient EMS is under active attack through CVE-2026-21643, a critical SQL injection flaw affecting 2,000+ exposed instances. F5 BIG-IP and Citrix NetScaler vulnerabilities are also being exploited in the wild. FBI Director Kash Patel's personal Gmail account was breached by Iranian hackers who leaked photos and documents.
Fortinet FortiClient EMS SQL Injection Under Active Exploitation (CVE-2026-21643)
Attackers are exploiting a critical SQL injection flaw in Fortinet's FortiClient EMS platform that allows unauthenticated remote code execution through malicious HTTP requests. CVE-2026-21643 (CVSS likely 9+) affects FortiClient EMS version 7.4.4 and allows attackers to smuggle SQL statements through the Site-header in HTTP requests targeting the web interface. Defused reports first exploitation occurred four days ago. Shadowserver tracks over 2,000 FortiClient EMS instances exposed online, with more than 1,400 IPs in the United States and Europe. This vulnerability is not yet listed on CISA KEV despite active exploitation. Fortinet products are frequently exploited in ransomware attacks and cyber espionage campaigns, with CISA having flagged 24 Fortinet vulnerabilities as actively exploited, 13 of which were used in ransomware attacks.
F5 BIG-IP Flaw Upgraded to Critical RCE, Now Exploited in Wild
A F5 BIG-IP vulnerability initially disclosed as a high-severity denial-of-service issue has been upgraded to a critical remote code execution flaw and is now being exploited in the wild. The vulnerability affects F5 BIG-IP systems and was reclassified after further analysis revealed the full scope of the issue. No CVE or specific version information was provided in the available reporting.
Citrix NetScaler Vulnerability Under Exploitation
A critical Citrix NetScaler vulnerability that leaks application memory is being exploited to obtain authenticated administrative session IDs. The flaw allows attackers to hijack administrator sessions and gain full control over NetScaler appliances.
ShinyHunters Claims European Commission Breach
The European Commission confirmed a data breach after its Europa.eu web platform was hacked in an attack claimed by the ShinyHunters extortion gang. The breach affects at least one of the Commission's AWS accounts, with the attacker claiming to have stolen over 350 GB of data before access was blocked. ShinyHunters released an archive of over 90GB of files allegedly stolen from the Commission's compromised cloud environment, claiming the data includes mail servers, databases, confidential documents, and contracts. Screenshots provided by the threat actor prove access to European Commission employee data. The Commission stated the attack did not disrupt Europa websites and that internal systems were not affected. ShinyHunters has also recently claimed breaches at Infinite Campus, CarGurus, Canada Goose, Panera Bread, Betterment, SoundCloud, PornHub, and Match Group. Some victims were breached in a large-scale voice phishing campaign targeting SSO accounts at Okta, Microsoft, and Google across more than 100 high-profile organizations.
Jackson County Sheriff's Department Hit by Ransomware
A ransomware attack crippled the entire IT network of the Sheriff's Department in Jackson County, Indiana. The attack took down all PCs, the WiFi network, and the police report filing system. The incident occurred last week and operations remain impacted.
CareCloud EHR Breach
Hackers breached EHR provider CareCloud in a security incident earlier this month, affecting one of the company's six electronic health record platforms. CareCloud reported to the SEC that an unauthorized third party temporarily accessed part of its CareCloud Health division on March 16, partially disrupting functionality and data access for approximately eight hours. The company evicted the attacker eight hours after the intruder gained access to the platform. All affected systems have been restored and the company believes the threat actor no longer has access. CareCloud continues to assess whether patient information or other data was accessed or exfiltrated. The company determined the incident is material due to the sensitivity of potentially affected information and potential remediation costs, legal matters, and effects on patients and reputation. CareCloud believes the incident is not reasonably likely to have a material impact on financial condition or results of operations.
Apple Adds ClickFix Warning to macOS Terminal
Apple silently added a security feature to macOS 26.4 that warns users about possible ClickFix attacks. The feature shows a popup whenever a user tries to copy-paste commands from a browser into the Terminal window. ClickFix is an attack technique where threat actors use websites with fake errors or broken CAPTCHAs that instruct users to copy and paste code in command-line terminals. The code typically contains encoded or masked commands that download and install malware. Attacks initially targeted Windows but expanded with macOS and Linux variants in 2025. ClickFix became particularly popular against macOS towards the end of 2025. Security firm Huntress reported more than half of malware incidents tracked last year originated from a ClickFix-related delivery point. The popup does not block users from pasting commands but raises awareness among less technical users.
Iranian Hackers Breach FBI Director's Personal Email (CVE Not Applicable)
Iranian hackers associated with the Handala group breached FBI Director Kash Patel's personal Gmail account and published photos and documents extracted from the inbox. The FBI confirmed the compromise, stating that the stolen data was not recent and did not include government information. The Handala hackers claimed they compromised Patel's personal email in response to FBI domain seizures and a $10 million reward offered by the U.S. government for information on the group's members. The threat actor published watermarked personal photos, documents, and email correspondence from before Patel became FBI director. Handala, also known as Handala Hack, Hatef, and Hamsa, is a hacktivist persona carrying out cyber activities for Iran's Ministry of Intelligence and Security (MOIS). The group previously breached medical technology giant Stryker and wiped nearly 80,000 devices.
Tax-Themed Phishing Campaigns Deliver RMM Tools
Proofpoint tracked over 100 tax-themed campaigns in 2026 delivering malware, remote monitoring and management (RMM) payloads, fraud, and credential phishing. Tax-themed campaigns this year show increased use of RMM payloads, activity from newly identified threat actors, and broader social engineering lures. Threat actors impersonate the IRS, tax agencies, government entities, company HR departments, and claim expired tax documents or tax violations. The most common payloads are legitimate RMMs including Datto, N-Able, RemotePC, Zoho Assist, and ScreenConnect. RMMs fly under the radar because they are legitimate, authoritatively signed software. In some cases, threat actors use one RMM for initial access and drop another as a follow-on payload. Campaign volumes vary from a handful of messages to tens of thousands. Most campaigns target the United States, with recent activity also targeting Canada, Australia, Switzerland, and Japan.
BreachForums v5 Hacked Days After Revival
The fifth incarnation of BreachForums was hacked days into its revival. ShinyHunters leaked the registration data and private messages of more than 340,000 users. The group promised to hack and leak any new iteration of BreachForums. This is the fourth BreachForum version or clone to be leaked according to D3Lab.
Microsoft Pulls KB5079391 Windows Update Over Install Issues
Microsoft pulled Windows 11 non-security preview update KB5079391 to investigate a known issue triggering 0x80073712 errors during installation. The optional cumulative update started rolling out Thursday to Windows 11 24H2 and 25H2 systems with 29 changes including Smart App Control and Display improvements. Affected devices see errors stating "Some update files are missing or have problems. We'll try to download the update again later. Error code: (0x80073712)." Microsoft stopped the KB5079391 rollout but has not shared a timeline for when a fix will be available. This will likely happen before April 14 Patch Tuesday cumulative updates to allow customers to test new features and fixes. One week ago, Microsoft released an emergency update to address an issue triggered by March 2026 Windows updates that broke sign-ins with Microsoft accounts across Teams, Edge, Microsoft 365 Copilot, and OneDrive.
White House Mobile App Contains Multiple Critical Security Flaws
Security researcher Thereallo decompiled the official White House mobile app launched March 28, 2026, and found multiple critical security and privacy violations. Findings include GPS tracking every 4.5 minutes, JavaScript injection into every website visited through the app, loading code from random GitHub Pages, additional third-party code execution, and data sharing with non-government entities. The issues violate basic cybersecurity principles and federal government security standards. The app collects location data continuously, can inject arbitrary code into web pages, and loads unverified code from external sources.
FCC Foreign Router Ban Criticized as Industrial Policy
Milton Mueller, Professor at the University of Georgia's School of Public Policy, criticized the United States ban on foreign-made SOHO routers as "industrial policy disguised as cybersecurity." The FCC justified the ban with references to CISA and FBI analysis of Volt Typhoon and Salt Typhoon attacks targeting SOHO routers, and Department of Commerce findings that 85 percent of consumer router supply chains in China creates systemic vulnerability. Mueller argues the ban ignores that routers use globally developed software components regardless of assembly location. The Typhoon gangs exploited unpatched bugs, unchanged default credentials, and bad design, not backdoors. The ban focuses on new equipment authorizations while leaving vulnerable legacy devices in place. By banning newest Wi-Fi 7 and Wi-Fi 8 routers from foreign manufacturers, the FCC forces consumers to pay more for upgraded equipment or keep older, more vulnerable devices longer, increasing the total attack surface.
AI-Assisted Malware Development Reaches Operational Maturity
Check Point Research reports AI-assisted malware development has reached operational maturity. VoidLink framework, a modular and professionally engineered Linux malware, was built by a single developer using a commercial AI-powered IDE within a compressed timeframe. The framework features eBPF and LKM rootkits, cloud and container enumeration, and more than 30 post-exploitation plugins. VoidLink was initially assessed as the work of a coordinated team based on architecture and implementation quality. The development method was exposed through an operational security failure, not from analyzing the malware itself. Check Point notes that actors of varying skill levels are investing in self-hosted and open-source AI models to avoid commercial platform restrictions, but underground discussions reveal local models still underperform and commercial models remain the productive choice. Jailbreaking is shifting from direct prompt engineering toward agentic-architecture abuse, specifically misuse of AI agent configuration mechanisms and project files that redefine agent behavior.
China-Linked Clusters Target Southeast Asian Government
Three threat activity clusters aligned with China targeted a government organization in Southeast Asia in a complex and well-resourced operation deploying multiple malware families including HIUPAN, PUBLOAD, EggStremeFuel, MASOL RAT, PoshRAT, TrackBak Stealer, and FluffyGh0st. The campaigns have been attributed to Mustang Panda (June-August 2025), CL-STA-1048 overlapping with Earth Estries and Crimson Palace (March-September 2025), and CL-STA-1049 overlapping with Unfading Sea Haze (April and August 2025). Significant overlap in TTPs suggests the clusters have a common target of interest and are potentially coordinating efforts. The attackers' methodology indicates intent to gain long-term, persistent access to sensitive government networks, not just to cause disruption.
Smart Slider 3 WordPress Plugin File Read Vulnerability (CVE-2026-3098)
A vulnerability in the Smart Slider 3 WordPress plugin allows subscriber-level authenticated users to read arbitrary files on the server. CVE-2026-3098 (EPSS 0.000, 7th percentile) received a medium severity score due to requiring authentication but affects websites with membership or subscription features. The plugin is active on more than 800,000 websites. The vulnerability stems from missing capability checks in the plugin's AJAX export actions, allowing any authenticated user to invoke them. The actionExportAll function lacks file type and source validation, allowing arbitrary server files including wp-config.php to be read and added to export archives. An attacker could access database credentials, keys, and salts for cryptographic security. Nextendweb patched the issue on March 24 with Smart Slider version 3.5.1.34. According to WordPress.org stats, the plugin was downloaded 303,428 times over the past week, meaning at least 500,000 WordPress sites are running a vulnerable version.
Active exploitation dominates today's threat landscape with Fortinet, F5, and Citrix vulnerabilities all being targeted in the wild. The European Commission breach and FBI Director email compromise demonstrate that cloud accounts and personal email remain soft targets even for high-profile organizations. Tax season phishing continues to leverage legitimate RMM tools to evade detection, requiring allow-listing controls rather than signature-based detection.