Daily Digest

Trivy Supply Chain Attack Escalates, Oracle Issues Critical RCE Patch, and CISA Adds Actively Exploited Flaws to KEV Catalog

Trivy Supply Chain Attack Escalates, Oracle Issues Critical RCE Patch, and CISA Adds Actively Exploited Flaws to KEV Catalog

March 23, 2026
9 articles (9 new)
27 min read

Summary

This intelligence brief for March 23, 2026, covers a rapidly escalating supply chain attack against the Trivy security scanner, with attackers publishing new malicious Docker images and re-establishing access. Oracle has issued an emergency out-of-band patch for a critical 9.8 CVSS RCE vulnerability in its Identity Manager. CISA has added actively exploited flaws in Apple, Laravel, and Craft CMS to its KEV catalog, mandating federal patching. Other major incidents include a data breach at Navia Benefit Solutions affecting 2.7 million individuals, a ransomware attack on the City of Los Angeles by the WorldLeaks group, and an international takedown of massive DDoS botnets that infected over 3 million IoT devices.

Filter by Category

New Articles (9)

📢 Share This Publication

Help others stay informed about cybersecurity threats

📅 Daily Edition

Curated and deduplicated every day from dozens of trusted sources — giving you one clean, consolidated view of what matters in cybersecurity.

🔢 Deduplication Applied

Related stories are merged into a single evolving article rather than repeated as separate entries — cutting through noise so you only read what's new.

🔗 Full Articles Linked

Every entry links to its full enriched article — complete with MITRE ATT&CK mappings, extracted IOCs, and actionable detection and mitigation guidance.