Google’s March update fixes 129 Android vulnerabilities, including CVE-2026-21385, a Qualcomm graphics component bug confirmed to be exploited in the wild. It’s the largest monthly Android patch batch since 2018 and underscores the need to fast-track updates on fleet devices. Prioritize the March security patch levels across OEMs and tighten MDM/EDR monitoring for post-patch exploitation attempts.
Source: CyberScoop
Chrome flaw let malicious extensions hijack Gemini Live and exfiltrate local files
Google patched CVE-2026-0628, an insufficient policy enforcement bug that allowed extensions to take over Chrome’s Gemini Live side panel, spy on users, and steal local files. The issue has been fixed since early January, but impacted users may still have risky extensions installed. Audit and remove untrusted extensions, update Chrome, and enforce extension allowlists for managed endpoints.
Source: SecurityWeek
OpenClaw “ClawJacked” bug let websites seize AI agents via localhost brute force
A high-severity OpenClaw flaw enabled malicious sites to open a WebSocket to the local gateway, brute-force credentials, and commandeer AI agents for silent data theft. The issue is fixed in version 2026.2.26. Update immediately and isolate local agent ports, enforce strong credentials, and consider browser/network controls that block website access to localhost services.
Source: SecurityWeek
APT28 exploited MSHTML CVE-2026-21513 before February’s patch Tuesday
Russia-linked APT28 is tied to pre-patch exploitation of CVE-2026-21513, a high-severity MSHTML security feature bypass. The activity highlights continued targeting of legacy IE/MSHTML components to enable downstream code execution chains. Ensure February 2026 cumulative updates are applied, reduce MSHTML exposure, and monitor for suspicious HTML/Office document activity.
Source: The Hacker News
North Korean APT targets air‑gapped networks with LNK-based toolchains
A recent ScarCruft/APT campaign used Windows shortcut files to deploy a new implant, loader, a propagation utility, and two backdoors, explicitly aiming to reach air-gapped systems. The operation underscores persistent use of removable media and cloud dead drops to bridge offline environments. Lock down LNK execution, harden USB media policies, and scrutinize unusual file system and process activity on isolated hosts.
Source: SecurityWeek
UK NCSC urges immediate hardening amid risk of Iranian cyber spillover
Following escalation in the Middle East, the UK’s NCSC advises organizations to review and strengthen controls against likely Iranian-linked phishing, DDoS, and disruptive ops. Recommended actions include patching exposed services, enforcing MFA, rehearsing incident response, and elevating spear-phish detection. Expect opportunistic targeting and potential supply-chain or third-party exposure.
Source: NCSC UK
Microsoft warns of OAuth redirect abuse delivering malware to government targets
Ongoing phishing campaigns use OAuth consent prompts and URL redirection to bypass traditional email and browser defenses, landing victims on attacker infrastructure without stealing tokens. Government and public-sector entities are in scope. Tighten cloud app consent policies, restrict user-authorized apps, monitor risky OAuth grants, and use conditional access to constrain high-risk flows.
Source: The Hacker News
You May Also Be Interested In...
Google Working Towards Quantum-Safe Chrome HTTPS CertificatesWireshark 4.6.4 Released
A fake FileZilla site hosts a malicious download