Cybersecurity & Privacy — 2026-03-22

Russian Intelligence Targets Signal/WhatsApp; APT28 Zero-Click Zimbra Campaign Hits Ukraine; Langflow RCE Weaponized in 20 Hours

The FBI issued a public service announcement warning that Russian intelligence-linked threat actors are targeting Signal and WhatsApp users through phishing campaigns using malicious QR codes and verification code interception. Thousands of high-value government accounts have been compromised. Separately, APT28 launched 'Operation GhostMail,' a zero-click HTML XSS campaign exploiting Zimbra CVE-2025-66376 against Ukrainian government webmail. CISA added five actively exploited flaws to its KEV catalog including vulnerabilities in Apple, Craft CMS, and Laravel Livewire. Critical Langflow RCE (CVE-2026-33017) was weaponized within 20 hours of disclosure.

1 sources
  1. Cybersecurity News Daily Recap - 21 Mar 2026 - Hendry Adrian Cybersecurity

View in full brief →

UNCLASSIFIED // OPEN SOURCE