Multiple vendors published security advisories covering unrelated vulnerabilities across enterprise, mobile, and industrial products. The notices include ABB flaws affecting AWIN GW100 rev.2, AWIN GW120, and AC500 V3 industrial control products, with issues including embedded webserver vulnerabilities tracked as CVE-2025-13777, CVE-2025-13778, CVE-2025-13779, and a stack buffer overflow in Cryptographic Message Syntax tracked as CVE-2025-15467. Other advisories cover HPE Compute Scale-up Server 3200 systems prior to v1.70.74 for an Intel firmware local privilege escalation issue tied to INTEL-SA-01396, GitHub Enterprise Server versions across the 3.14.x to 3.19.x branches, and Splunk Enterprise, Splunk Cloud Platform, and multiple Splunk AppDynamics components.
Apple also released security updates for older supported mobile operating system branches, including iOS and iPadOS versions prior to 16.7.15 and 15.8.7. Separately, a post highlighting iPhone and iPad approval for handling information up to the NATO Restricted level is not part of the same event stream and is primarily a certification/announcement item rather than a vulnerability disclosure or incident report. Taken together, the material reflects a routine set of unrelated vendor advisories rather than a single coherent cybersecurity incident or disclosure campaign.

See real exploitation activity before you spend the cycle.
6 events from the most recent confirmed update back to the earliest known activity.
On 2026-03-12, HPE published a security advisory for a vulnerability affecting HPE Compute Scale-up Server 3200 versions prior to v1.70.74. The issue was linked to Intel processor firmware advisory INTEL-SA-01396 describing a local escalation of privilege condition.
On 2026-03-12, ABB disclosed a stack buffer overflow vulnerability in Cryptographic Message Syntax affecting the AC500 V3 product line. The flaw, tracked as CVE-2025-15467, specifically affected AC500 V3 firmware version 3.9.0.
On 2026-03-11, Splunk published security advisories addressing vulnerabilities across Splunk Enterprise, Splunk Cloud Platform, and several Splunk AppDynamics components. The advisories included minimum fixed versions for affected AppDynamics agents and the Enterprise Console.
On 2026-03-11, Apple published security updates to address vulnerabilities affecting iOS and iPadOS devices. The updates applied to versions prior to 16.7.15 and prior to 15.8.7.
On 2026-03-11, ABB published a security advisory for multiple vulnerabilities in the embedded webserver of AWIN GW100 rev.2 and AWIN GW120 products. The issues were tracked as CVE-2025-13777, CVE-2025-13778, and CVE-2025-13779.
On 2026-03-10, GitHub published security advisories for multiple vulnerabilities affecting GitHub Enterprise Server. Affected releases included 3.19.x before 3.19.3, 3.18.x before 3.18.6, 3.17.x before 3.17.12, 3.16.x before 3.16.15, 3.15.x before 3.15.19, and 3.14.x before 3.14.24.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
6 references tracked. Mallory keeps watching after this page renders.
cyber.gc.ca
Open sourcecyber.gc.ca
Open sourcecyber.gc.ca
Open sourcecyber.gc.ca
Open sourcecyber.gc.ca
Open sourcecyber.gc.ca
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.