Sunday, April 5, 2026
← Back to digest
Cybersecurity & Privacy

Widespread Cybersecurity Vulnerabilities and Exploits

· 29 March 2026 · 7 sources

Multiple critical cybersecurity vulnerabilities and active exploits have been disclosed across widely used software and hardware platforms. Notably, Home Assistant's Map-card and History-graph card components suffer from stored Cross-Site Scripting (XSS) flaws allowing authenticated attackers to execute malicious scripts. The popular container scanning tool Trivy was compromised in a supply chain attack, leaking sensitive credentials from numerous pipelines. High-severity vulnerabilities in Citrix NetScaler and F5 BIG-IP APM appliances are under active reconnaissance and exploitation, risking remote code execution and data leaks. Additionally, a Russian state-sponsored group is deploying the DarkSword iOS exploit kit in targeted spear-phishing campaigns, highlighting ongoing advanced persistent threats. These developments underscore the urgent need for patching, vigilant monitoring, and supply chain security improvements to mitigate escalating cyber risks.

research →

Sources (7)

CVE-2026-33044: CVE-2026-33044: Stored Cross-Site Scripting in Home Assistant Map-Card Dev.to 28 Mar 2026, 19:10
CVE-2026-33045: CVE-2026-33045: Stored Cross-Site Scripting in Home Assistant History-Graph Card Dev.to 28 Mar 2026, 18:40
Your Security Scanner Was the Weapon: Inside the Trivy Supply Chain Attack Dev.to 28 Mar 2026, 17:40
GHSA-H8R8-WCCR-V5F2: GHSA-H8R8-WCCR-V5F2: Mutation-XSS via Re-Contextualization in DOMPurify Dev.to 28 Mar 2026, 16:10
Citrix NetScaler Under Active Recon for CVE-2026-3055 (CVSS 9.3) Memory Overread Bug The Hacker News (Security) 28 Mar 2026, 09:11
TA446 Deploys Leaked DarkSword iOS Exploit Kit in Targeted Spear-Phishing Campaign The Hacker News (Security) 28 Mar 2026, 07:07
CISA Adds CVE-2025-53521 to KEV After Active F5 BIG-IP APM Exploitation The Hacker News (Security) 28 Mar 2026, 07:07

More from Cybersecurity & Privacy

← Back to digest