No endpoint required: APIs, phone calls and device codes did the work
An API authorisation flaw exposes 2.7 million benefits records over 24 quiet days. One hour of vishing access lifts 900,000 records from an identity-protection firm. And a commoditised iOS exploit chain with three zero-days spreads across multiple threat actors.
Executive summary
- Not one headline breach needed an endpoint compromise. A broken object-level authorisation flaw in a benefits API was read for 24 days, a single vishing call yielded an hour of access and 900,000 records, and attackers abused Microsoft device-code sign-in flows built for printers and TVs to take over hundreds of accounts.
- Mobile zero-day capability is being commoditised. The DarkSword iOS exploit chain, six flaws with three zero-days for full device takeover, was found in use by multiple actors rather than one state operator, doing hit-and-run theft of credentials and wallet data within minutes.
- Iran-nexus activity escalated on two fronts. A state-linked group industrialised exploitation of a critical Laravel Livewire flaw, while hacktivists made headline-grabbing mega-claims, including an unverified 375 TB claim against a defence prime, a reminder that claim inflation is itself a pressure tactic.
Key findings
Benefits administrator's API flaw exposes 2.7 million people
Navia Benefit Solutions began notifying 2.7 million people after an attacker exploited a broken object-level authorisation flaw in its API, gaining read-only access to participant records for 24 days over the holiday period. Names, Social Security numbers and enrolment data were exposed; no malware, no endpoint, just an API answering questions it should have refused.
One vishing call, one hour, 900,000 records at an identity-protection firm
Aura confirmed an attacker used a targeted voice-phishing call to compromise an employee account, holding access for roughly an hour before eviction and lifting about 900,000 marketing-database records. When the victim sells identity protection, the incident is the marketing pitch for helpdesk hardening.
DarkSword iOS exploit chain commoditised across multiple actors
Coordinated research exposed a full-chain iOS exploit kit using six vulnerabilities, three of them zero-days, for complete device takeover via compromised legitimate websites. Multiple actors were observed using the kit against targets in several countries, with payloads stealing credentials and cryptocurrency-wallet data within minutes and cleaning up afterwards. Three of the flaws entered CISA KEV on 20 March with a two-week deadline.
State-linked group industrialises a critical Laravel Livewire flaw
The 20 March KEV batch included a CVSS-9.8 Laravel Livewire code-injection flaw whose exploitation researchers attribute to an Iranian state-sponsored group running an orchestration platform for automated mass campaigns against diplomatic and critical-infrastructure targets. The same batch carried a perfect-score Craft CMS flaw and the Apple entries from the DarkSword chain.
French Education Ministry platform breach exposes 243,000 staff
France's Education Ministry disclosed that its COMPAS staff-management platform was breached, exposing names, home addresses, phone numbers and absence records of roughly 243,000 employees, with samples surfacing on resale markets before disclosure. Access was suspended and regulators notified. Home addresses of public servants are a safety issue, not just a privacy one.
The broader pattern
- APIs are the unwatched front door. Broken object-level authorisation is boring, silent and read-only, and it just exposed 2.7 million people; put API query patterns under the same behavioural baseline as user logins.
- Legacy sign-in flows are being weaponised. Device-code authentication built for input-constrained devices was abused to compromise hundreds of accounts across five sectors; disable or constrain flows your users do not need.
- Verify before reacting to mega-claims. The fortnight's 375 TB defence-prime claim remains unverified by any researcher; extortion theatre is designed to force decisions faster than facts arrive.
Sector lens
Suggested priorities to consider
Based on this fortnight's public reporting, these are the areas we would review first. Weigh each against your own environment and risk profile.
Patch the 20 March KEV batch, Apple devices first. Three DarkSword-chain flaws, a CVSS-10 Craft CMS bug and the exploited Laravel Livewire flaw all carry the same two-week federal deadline; mirror it.
Test your public APIs for broken object-level authorisation. Enumerate whether one participant's token can read another's record; Navia's 24 quiet days show scanners and SIEMs rarely notice.
Constrain device-code authentication flows. Block or conditional-access-restrict device-code sign-in for users who never need it; it is a phishing flow with no password prompt to notice.
Run the vishing drill against your own helpdesk. One call and one hour was enough at an identity-protection firm; measure how long an impersonation call survives your process.
Pre-agree a verification protocol for extortion claims. Decide before the 375 TB headline lands with your name on it: who validates samples, who speaks, and what triggers notification.
These suggestions are general commentary based on publicly reported events, provided for information only. They are not tailored security advice and may not suit your environment; validate against your own risk assessment and change-control processes before acting.
A quiet API reading records it never touched before, a vished account working outside its pattern for one hour, a device-code sign-in from infrastructure no employee uses: none of these trip signature-based tools. Blacklight baselines behaviour per identity, per API and per application, so the deviation is investigated and contained in minutes, with the reasoning trail ready before the extortion email arrives.
Sources & methodology
Primary public sources this issue: CISA Known Exploited Vulnerabilities catalog (entries of 16 and 20 March 2026) · coordinated DarkSword research (Google Threat Intelligence, iVerify, Lookout, 18 – 19 March 2026) · vendor and state disclosures (Navia Benefit Solutions, Aura, French Education Ministry) · security-press reporting (SecurityWeek, HelpNetSecurity, databreaches.net), 16 – 29 March 2026 · Breachsense ransomware leak-site statistics, March 2026 · Germany KRITIS-Dachgesetz commentary · MITRE ATT&CK v15. The 375 TB defence-prime item is an unverified attacker claim and is reported strictly as such.