Security Highlights Of The Day [13/03/26]

Google Fixes Two Chrome Zero Days Exploited in the Wild
Google released security updates addressing two Chrome zero day vulnerabilities that were actively exploited in the wild. The flaws affect the Skia and V8 components of the browser. Both vulnerabilities were discovered and reported internally by Google on March 10, 2026, and technical details about their exploitation have not been disclosed to prevent further abuse by threat actors.
Source: The Hacker News

Storm 2561 Uses SEO Poisoning to Distribute Fake VPN Clients for Credential Theft
Microsoft identified a credential theft campaign distributing fake VPN clients through SEO poisoning. Users searching for legitimate enterprise software are redirected to malicious ZIP files hosted on attacker controlled websites, which deploy digitally signed trojans masquerading as trusted VPN clients while harvesting VPN credentials. Microsoft attributes the activity to the cybercriminal actor Storm 2561, active since May 2025.
Source: Microsoft Security Blog

400,000 WordPress Sites Impacted by SQL Injection in Ally Plugin
A SQL injection vulnerability affecting the Ally WordPress plugin, installed on more than 400,000 sites, could allow attackers to extract sensitive data from databases including password hashes. The vulnerability was reported through the Wordfence Bug Bounty Program only five days after the flaw was introduced into the code.
Source: Wordfence

Veeam Warns of Critical Flaws Exposing Backup Servers to RCE Attacks
Veeam released patches for multiple vulnerabilities in its Backup and Replication solution, including four critical remote code execution flaws. Three of the vulnerabilities allow low privileged domain users to execute remote code on vulnerable backup servers, creating a serious risk to systems responsible for protecting critical organizational data.
Source: BleepingComputer

Glassworm Returns With Invisible Unicode Attacks on GitHub and npm
Researchers observed a renewed wave of activity from the threat actor Glassworm, using hidden Unicode characters to compromise GitHub repositories, npm packages, and the VS Code ecosystem. The technique allows malicious code to remain visually hidden during code review while still executing in affected environments. Several notable repositories were reported as impacted.
Source: Aikido Security

Scroll to top