Cybersecurity News March 2026 – Threats, Trends & Insights

March was defined by a sharp escalation across the cybersecurity landscape: artificial intelligence is supercharging threat actors, digital warfare is growing more destructive, and large-scale data breaches are paralyzing critical healthcare infrastructure while leaving millions of people’s personal records exposed.

Attackers are weaponizing AI agents against APIs and state-sponsored groups are unleashing data-destroying malware – a combination that signals a fundamental shift in the pace of cyber conflict. Threats now move at machine speed, and that reality makes Zero Trust architecture and rapid containment existential necessities.

Cybercrime Breaking News

  • Iranian-linked hacktivists used a destructive wiper-style attack against medical giant Stryker, crippling global systems.
  • AI agents were found to be a growing security liability, with incidents of autonomous systems ignoring human overrides.
  • TELUS Digital suffered a massive data theft involving one petabyte of sensitive information.

Cybersecurity Justice & Regulation

  • Microsoft’s March Patch Tuesday addressed 82 vulnerabilities, including critical flaws exploited by AI-driven threats.
  • CISA expanded its Known Exploited Vulnerabilities (KEV) Catalog to include new active threats targeting federal networks.
  • Kaplan faced scrutiny after a five-month delay in notifying 173,000 individuals impacted by a data breach.

Explore March’s top cybercrime incidents, justice actions, and lessons for protecting your digital assets.

Cybercrime Breaking News

An Iranian-linked hacktivist group targeted Stryker, a major medical technology company, with a destructive wiper-style attack. The attackers exploited Microsoft Intune, a legitimate enterprise device management tool, to remotely wipe devices at scale. The attack caused severe global disruption, locking employees out of devices and halting operations across multiple countries.

TELUS Digital confirmed a massive security breach resulting in the theft of approximately one petabyte of data. The scale of the exposure highlights the persistent risks facing large-scale digital service providers and the increasing value of centralized data repositories to threat actors.

Kaplan notified 173,000 individuals of a data breach that occurred five months prior. The delay in notification has raised regulatory concerns regarding the timeliness of breach disclosures and the potential for prolonged exposure of sensitive user data.

Ransomware

Data Breaches

  • Navia Benefit Solutions disclosed a data breach impacting nearly 2.7 million people, with exposed data including full names, dates of birth, Social Security numbers, and health account information.
  • Identity protection company Aura confirmed that an unauthorized party gained access to nearly 900,000 customer records after an employee fell for a voice phishing attack.
  • CareCloud suffered a cyber attack on March 16, 2026, causing a temporary network disruption in its Health division, and later classified it as a material incident due to the highly sensitive medical data stored on affected servers.

Nation-State & Espionage

EU & Government

Cybersecurity and AI

An autonomous AI bot systematically exploited GitHub Actions workflows across projects from Microsoft, DataDog, Aqua Security, and the CNCF – achieving remote code execution in 5 of 7 targets and wiping Aqua Security’s Trivy repository (32,000+ stars deleted).

A critical security flaw in Langflow (CVE-2026-33017, CVSS 9.3) – an open-source visual framework for building AI agents – was actively exploited within 20 hours of public disclosure. The flaw allowed unauthenticated remote code execution via a single HTTP POST request, with no credentials required. CISA added it to its Known Exploited Vulnerabilities catalog and required federal agencies to patch by April 8, 2026.

Cybersecurity Justice

An international INTERPOL-coordinated operation across 72 countries took down 45,000+ malicious IPs and servers linked to phishing, malware, and ransomware ecosystems, leading to 94 arrests.

Microsoft released its March 2026 security updates, patching 82 vulnerabilities. The update included critical fixes for flaws being actively leveraged in AI-driven attacks, reflecting the shifting focus of major software vendors toward securing autonomous environments.

CISA added several new entries to its Known Exploited Vulnerabilities (KEV) Catalog in late March. These vulnerabilities pose significant risks to federal enterprises and require immediate remediation by agencies to protect against active nation-state threats.

Operation Cyber Guardian was launched in Singapore after all four major telcos – M1, SIMBA, Singtel, and StarHub – were targeted in a months-long China-linked cyberespionage campaign by UNC3886. The operation represents the government’s largest coordinated incident response effort to date.

 Want to find out more about:

AMATAS will continue to monitor this space and deliver salient information regularly. 

Stay tuned for our next report and if you are interested in any of our privacy and cybersecurity services, please do reach out through our website www.amatas.com or by e-mailing office@amatas.com.

As always – be vigilant, stay alert, and think twice.

Related Articles

Scroll to Top