Skip to content
All resources
Cybersecurity Intel · № 06 · 16 – 29 March 2026

No endpoint required: APIs, phone calls and device codes did the work

An API authorisation flaw exposes 2.7 million benefits records over 24 quiet days. One hour of vishing access lifts 900,000 records from an identity-protection firm. And a commoditised iOS exploit chain with three zero-days spreads across multiple threat actors.

Published 30 March 2026 By Blacklight Threat Intelligence Classification TLP:CLEAR · Public
2.7M
People exposed via one broken-authorisation API flaw, read quietly for 24 days
1 hour
Of vished employee access lifted ~900,000 records at an identity-protection firm
3
Zero-days among six flaws chained in the commoditised DarkSword iOS kit
808
Organisations on ransomware leak sites in March, the year's highest month

Executive summary

  • Not one headline breach needed an endpoint compromise. A broken object-level authorisation flaw in a benefits API was read for 24 days, a single vishing call yielded an hour of access and 900,000 records, and attackers abused Microsoft device-code sign-in flows built for printers and TVs to take over hundreds of accounts.
  • Mobile zero-day capability is being commoditised. The DarkSword iOS exploit chain, six flaws with three zero-days for full device takeover, was found in use by multiple actors rather than one state operator, doing hit-and-run theft of credentials and wallet data within minutes.
  • Iran-nexus activity escalated on two fronts. A state-linked group industrialised exploitation of a critical Laravel Livewire flaw, while hacktivists made headline-grabbing mega-claims, including an unverified 375 TB claim against a defence prime, a reminder that claim inflation is itself a pressure tactic.

Key findings

18 March 2026 API · T1190

Benefits administrator's API flaw exposes 2.7 million people

Navia Benefit Solutions began notifying 2.7 million people after an attacker exploited a broken object-level authorisation flaw in its API, gaining read-only access to participant records for 24 days over the holiday period. Names, Social Security numbers and enrolment data were exposed; no malware, no endpoint, just an API answering questions it should have refused.

16 – 19 March 2026 ATT&CK T1566.004

One vishing call, one hour, 900,000 records at an identity-protection firm

Aura confirmed an attacker used a targeted voice-phishing call to compromise an employee account, holding access for roughly an hour before eviction and lifting about 900,000 marketing-database records. When the victim sells identity protection, the incident is the marketing pitch for helpdesk hardening.

18 – 19 March 2026 KEV · 3 zero-days

DarkSword iOS exploit chain commoditised across multiple actors

Coordinated research exposed a full-chain iOS exploit kit using six vulnerabilities, three of them zero-days, for complete device takeover via compromised legitimate websites. Multiple actors were observed using the kit against targets in several countries, with payloads stealing credentials and cryptocurrency-wallet data within minutes and cleaning up afterwards. Three of the flaws entered CISA KEV on 20 March with a two-week deadline.

20 – 21 March 2026 CVE-2025-54068 · KEV

State-linked group industrialises a critical Laravel Livewire flaw

The 20 March KEV batch included a CVSS-9.8 Laravel Livewire code-injection flaw whose exploitation researchers attribute to an Iranian state-sponsored group running an orchestration platform for automated mass campaigns against diplomatic and critical-infrastructure targets. The same batch carried a perfect-score Craft CMS flaw and the Apple entries from the DarkSword chain.

23 – 24 March 2026 Government · Exposure

French Education Ministry platform breach exposes 243,000 staff

France's Education Ministry disclosed that its COMPAS staff-management platform was breached, exposing names, home addresses, phone numbers and absence records of roughly 243,000 employees, with samples surfacing on resale markets before disclosure. Access was suspended and regulators notified. Home addresses of public servants are a safety issue, not just a privacy one.

The broader pattern

  • APIs are the unwatched front door. Broken object-level authorisation is boring, silent and read-only, and it just exposed 2.7 million people; put API query patterns under the same behavioural baseline as user logins.
  • Legacy sign-in flows are being weaponised. Device-code authentication built for input-constrained devices was abused to compromise hundreds of accounts across five sectors; disable or constrain flows your users do not need.
  • Verify before reacting to mega-claims. The fortnight's 375 TB defence-prime claim remains unverified by any researcher; extortion theatre is designed to force decisions faster than facts arrive.

Sector lens

Healthcare & benefits
The Navia flaw sat in a benefits API serving state employee programmes. Third-party administrators with SSN-rich records need API-level assurance, and 24 days of quiet reads is a detection question to put to every vendor.
Government
243,000 education staff with home addresses exposed, and Germany's KRITIS critical-facilities act entering force on 17 March: the exposure and the regulatory expectation are rising together.
Education
Staff-management platforms hold the same identity-theft raw material as HR systems; the COMPAS breach shows they get the attacker attention without the HR-grade controls.
Financial services
DarkSword's payloads went for credentials and wallet data in minutes, and device-code abuse hit finance hardest; mobile and legacy-auth surfaces belong in your threat model, not just desktops.

Suggested priorities to consider

Based on this fortnight's public reporting, these are the areas we would review first. Weigh each against your own environment and risk profile.

01

Patch the 20 March KEV batch, Apple devices first. Three DarkSword-chain flaws, a CVSS-10 Craft CMS bug and the exploited Laravel Livewire flaw all carry the same two-week federal deadline; mirror it.

02

Test your public APIs for broken object-level authorisation. Enumerate whether one participant's token can read another's record; Navia's 24 quiet days show scanners and SIEMs rarely notice.

03

Constrain device-code authentication flows. Block or conditional-access-restrict device-code sign-in for users who never need it; it is a phishing flow with no password prompt to notice.

04

Run the vishing drill against your own helpdesk. One call and one hour was enough at an identity-protection firm; measure how long an impersonation call survives your process.

05

Pre-agree a verification protocol for extortion claims. Decide before the 375 TB headline lands with your name on it: who validates samples, who speaks, and what triggers notification.

These suggestions are general commentary based on publicly reported events, provided for information only. They are not tailored security advice and may not suit your environment; validate against your own risk assessment and change-control processes before acting.

How Blacklight handles this

A quiet API reading records it never touched before, a vished account working outside its pattern for one hour, a device-code sign-in from infrastructure no employee uses: none of these trip signature-based tools. Blacklight baselines behaviour per identity, per API and per application, so the deviation is investigated and contained in minutes, with the reasoning trail ready before the extortion email arrives.

Book a Demo

Sources & methodology

Primary public sources this issue: CISA Known Exploited Vulnerabilities catalog (entries of 16 and 20 March 2026) · coordinated DarkSword research (Google Threat Intelligence, iVerify, Lookout, 18 – 19 March 2026) · vendor and state disclosures (Navia Benefit Solutions, Aura, French Education Ministry) · security-press reporting (SecurityWeek, HelpNetSecurity, databreaches.net), 16 – 29 March 2026 · Breachsense ransomware leak-site statistics, March 2026 · Germany KRITIS-Dachgesetz commentary · MITRE ATT&CK v15. The 375 TB defence-prime item is an unverified attacker claim and is reported strictly as such.

Methodology. Findings are compiled from public reporting and Blacklight Threat Intelligence monitoring for the stated window, mapped to MITRE ATT&CK where applicable. Aggregate platform observations, where cited, are anonymised across the Blacklight customer base and never identify a customer environment. Corrections: intel@blacklightai.com.

Related reading

Blacklight AI · Cybersecurity Intel · № 06 TLP:CLEAR
Get started

See what truly predictive
security looks like.

Sixty minutes, under your control. See the platform run on a pre-loaded, anonymised environment, watch one real incident handled end to end, and map it to your sector, without connecting a single data source.

A typical demo
  • 01 A live tour on a pre-loaded, anonymised environment, running from minute one, not slides.
  • 02 One real incident, detected, investigated and contained, written up as a regulator-ready report.
  • 03 Mapped to your world: your sources, your sector's threats and your regulators.
  • 04 The questions your board will ask: deployment, residency, security, integrations and TCO.

No connectors or data required from you. A proof-of-value on your own telemetry is the next step, never the ask on a first call.