Afternoon Review in IT Security — March 20, 2026
The cybersecurity landscape continues to face significant threats as law enforcement takes action against major botnet operations while new malware campaigns and zero-day exploits emerge across multiple sectors. Today's briefing covers critical disruptions, supply-chain attacks, and active exploitation campaigns affecting organizations worldwide.
DoJ Disrupts 3 Million-Device IoT Botnets Behind Record 31.4 Tbps Global DDoS Attacks
The U.S. Department of Justice announced a major law enforcement operation targeting command-and-control infrastructure used by several Internet of Things botnets including AISURU, Kimwolf, JackSkid, and Mossad. The coordinated effort involved authorities from Canada and Germany working alongside private sector partners to dismantle the networks responsible for record-breaking distributed denial-of-service attacks. The operation represents a significant blow to threat actors operating large-scale botnet infrastructure that has been leveraged for some of the most devastating DDoS campaigns on record.
Source: DoJ Disrupts 3 Million-Device IoT Botnets Behind Record 31.4 Tbps Global DDoS Attacks
New Stealit Campaign Abuses Node.js Single Executable Application
FortiGuard Labs has identified a new Stealit campaign that exploits Node.js Single Executable Application technology to deliver obfuscated malware payloads. The campaign demonstrates attackers' continued evolution in leveraging legitimate development frameworks to evade detection and distribute the Stealit RAT across target systems. The threat actors have registered domains including iloveanimals.shop and stealituptaded.lol to facilitate command and control operations, with communications originating from accounts associated with @deceptacle.
Source: New Stealit Campaign Abuses Node.js Single Executable Application | FortiGuard Labs
Critical Langflow Vulnerability Exploited Hours After Public Disclosure
A critical vulnerability in Langflow has been actively exploited in the wild within hours of its public disclosure, enabling unauthenticated remote code execution through attacker-supplied flow data in public flows. Tracked as CVE-2026-33017, the vulnerability poses an immediate threat to organizations running vulnerable instances of the open-source platform. Threat actors have already developed and deployed exploit toolkits targeting the flaw, demonstrating the rapid weaponization of publicly disclosed vulnerabilities.
Source: Critical Langflow Vulnerability Exploited Hours After Public Disclosure
Thousands of Magento Sites Hit in Ongoing Defacement Campaign
An ongoing defacement campaign targeting Magento e-commerce platforms has impacted thousands of sites globally, affecting e-commerce platforms, multinational brands, and government services since February 27. The attacks leverage multiple vulnerabilities including PolyShell and SessionReaper to compromise and deface affected websites. The campaign continues to expand, underscoring the persistent threat to organizations running vulnerable versions of popular e-commerce software.
Source: Thousands of Magento Sites Hit in Ongoing Defacement Campaign
Today's threat landscape reflects both the effectiveness of coordinated law enforcement action against established botnet infrastructure and the persistent challenge of rapidly weaponized vulnerabilities and supply-chain attacks. Organizations should prioritize immediate patching of known vulnerabilities, enhanced monitoring of Node.js deployments, and review of Magento security postures to mitigate current threats.
New Stealit Campaign Abuses Node.js Single Executable Application | FortiGuard Labs
Source: New Stealit Campaign Abuses Node.js Single Executable Application | FortiGuard Labs
A new Stealit campaign uses Node.js Single Executable Application (SEA) to deliver obfuscated malware. FortiGuard Labs details tactics and defenses. Learn more.