no alarms and no surprises please..
-
At RSAC, the EU Leads While US Officials Are Sidelined
At RSAC, the EU Leads While US Officials Are Sidelined While US government sits out this year, EU officials are on the ground in San Francisco leading the conversations on today’s top cybersecurity challenges. Becky Bracken Go to gbhackers.com
-
Blame Game: Why Public Cyber Attribution Carries Risks
Blame Game: Why Public Cyber Attribution Carries Risks Publicly accusing an entity of a cyberattack could have negative consequences that organizations should consider before taking the plunge. Alexander Culafi Go to gbhackers.com
-
Phishers Pose as Palo Alto Networks’ Recruiters for Months in Job Scam
Phishers Pose as Palo Alto Networks’ Recruiters for Months in Job Scam A series of campaigns that began in August aim to defraud job candidates, using psychological tactics and data scraped from LinkedIn profiles. Elizabeth Montalbano Go to gbhackers.com
-
SANS: Top 5 Most Dangerous New Attack Techniques to Watch
SANS: Top 5 Most Dangerous New Attack Techniques to Watch For the first time, SANS Institute’s five top attack techniques all have one thing in common – AI. Becky Bracken Go to gbhackers.com
-
Why a ‘Near Miss’ Database Is Key to Improving Information Sharing
Why a ‘Near Miss’ Database Is Key to Improving Information Sharing Organizations disclose attack details, though information may be limited, following a breach, but what if they did the same with close calls? Arielle Waldman Go to gbhackers.com
-
AI-Native Security Is a Must to Counter AI-Based Attacks
AI-Native Security Is a Must to Counter AI-Based Attacks Attacks by artificial intelligence agents are a reality. Experts at Nvidia’s GTC conference say defenders need to use the same tools to fight them off. Agam Shah Go to gbhackers.com
-
F5 NGINX Plus & Open‑Source Flaw Lets Attackers Execute Code via MP4 File
F5 NGINX Plus & Open‑Source Flaw Lets Attackers Execute Code via MP4 File F5 has disclosed a high-severity vulnerability (CVE-2026-32647) in the NGINX ngx_http_mp4_module that allows attackers execute arbitrary code or cause a denial-of-service (DoS) using crafted MP4 files…. Go to gbhackers.com
-
Hackers Exploiting Magento Flaw to Execute Remote Code and Seize Full Account Access
Hackers Exploiting Magento Flaw to Execute Remote Code and Seize Full Account Access A critical vulnerability dubbed “PolyShell” is actively being exploited across Magento and Adobe Commerce platforms. Discovered by the Sansec Forensics Team and published on… Go to gbhackers.com
-
SmartApeSG ClickFix Campaign Spreads Remcos, NetSupport RAT, StealC, Sectop RAT
SmartApeSG ClickFix Campaign Spreads Remcos, NetSupport RAT, StealC, Sectop RAT A recent SmartApeSG campaign observed on March 24, 2026, highlights the growing sophistication of ClickFix-based attack chains, which deliver multiple remote access trojans (RATs)… Go to gbhackers.com
-
ClawHub Vulnerability Lets Attackers Manipulate Rankings to Become Top Skill
ClawHub Vulnerability Lets Attackers Manipulate Rankings to Become Top Skill Silverfort researchers recently uncovered a critical security flaw in ClawHub, the main public registry for the OpenClaw agent ecosystem. This vulnerability allowed attackers to… Go to gbhackers.com
-
New Study Reveals How Infostealer Infections Lead to Dark Web Exposure in Just 48…
New Study Reveals How Infostealer Infections Lead to Dark Web Exposure in Just 48… New research is shedding light on how infostealer malware turns a single careless click into full-blown credential exposure on dark web marketplaces in less… Go to gbhackers.com
-
Manager of botnet used in ransomware attacks gets 2 years in prison
Manager of botnet used in ransomware attacks gets 2 years in prison A Russian national has been sentenced to two years in prison after admitting that the phishing botnet he managed was used to launch BitPaymer ransomware attacks against 72 U.S. companies. […] Sergiu Gatlan Go to bleepingcomputer
-
PTC warns of imminent threat from critical Windchill, FlexPLM RCE bug
PTC warns of imminent threat from critical Windchill, FlexPLM RCE bug PTC Inc. is warning of a critical vulnerability in Windchill and FlexPLM, widely used product lifecycle management (PLM) solutions, that could allow remote code execution. […] Bill Toulas Go to bleepingcomputer
-
Popular LiteLLM PyPI package backdoored to steal credentials, auth tokens
Popular LiteLLM PyPI package backdoored to steal credentials, auth tokens The TeamPCP hacking group continues its supply-chain rampage, now compromising the massively popular “LiteLLM” Python package on PyPI and claiming to have stolen data from hundreds of thousands of devices during the attack. […] Lawrence Abrams Go to bleepingcomputer
-
FCC bans new routers made outside the USA over security risks
FCC bans new routers made outside the USA over security risks The Federal Communications Commission has updated its Covered List to include all consumer routers made in foreign countries, banning the sale of new models in the U.S. […] Bill Toulas Go to bleepingcomputer
-
Firefox now has a free built-in VPN with 50GB monthly data limit
Firefox now has a free built-in VPN with 50GB monthly data limit Mozilla released Firefox 149 with added privacy protection through a built-in VPN tool offering up to 50GB of monthly traffic. […] Bill Toulas Go to bleepingcomputer
-
LiteLLM Python Package With 95 Million Downloads Compromised by TeamPCP Hackers
LiteLLM Python Package With 95 Million Downloads Compromised by TeamPCP Hackers A widely used open-source Python library was compromised on the Python Package Index (PyPI). Versions 1.82.7 and 1.82.8 of the package, which route requests across various LLM providers and have over 95 million monthly downloads, were found to contain a sophisticated backdoor by security…
-
Kali Linux 2026.1 Released With 8 New Hacking Tools
Kali Linux 2026.1 Released With 8 New Hacking Tools Kali Linux 2026.1 has officially been released, marking the first major update of the year for the popular penetration testing distribution. Designed for professionals engaged in technical security research and vulnerability analysis, this update features modern aesthetic enhancements, notable advancements in mobile penetration testing, and a…
-
Aqua Security’s Trivy Scanner Compromised in Supply Chain Attack
Aqua Security’s Trivy Scanner Compromised in Supply Chain Attack A sophisticated supply chain attack targeting Aqua Security’s widely used open-source vulnerability scanner, Trivy. A threat actor leveraged compromised credentials to distribute malicious releases, turning a trusted security tool into a mechanism for large-scale credential theft across CI/CD pipelines. The incident remains an ongoing and evolving…
-
HackerOne Data Breach – Employees Data Stolen Following Navia Hack
HackerOne Data Breach – Employees Data Stolen Following Navia Hack HackerOne recently disclosed a data breach affecting 287 of its employees following a cyberattack on its U.S. benefits administrator, Navia Benefit Solutions. The breach stemmed from a Broken Object Level Authorization (BOLA) vulnerability in Navia’s API, which exposed the sensitive personal and health information of…
-
Dell Wyse Management Vulnerabilities Enables Complete System Compromise
Dell Wyse Management Vulnerabilities Enables Complete System Compromise A recent security analysis has revealed how chaining seemingly minor logic flaws in Dell Wyse Management Suite (WMS) On-Premises can result in a complete system compromise. Security researchers demonstrated that combining two distinct vulnerabilities allows an unauthenticated attacker to bypass security controls and achieve remote code execution…
-
Cloud workload security: Mind the gaps
Cloud workload security: Mind the gaps As IT infrastructure expands, visibility and control often lag behind – until an incident forces a reckoning Go to eset
-
TeamPCP Backdoors LiteLLM Versions 1.82.7–1.82.8 via Trivy CI/CD Compromise
TeamPCP Backdoors LiteLLM Versions 1.82.7–1.82.8 via Trivy CI/CD Compromise TeamPCP, the threat actor behind the recent compromises of Trivy and KICS, has now compromised a popular Python package named litellm, pushing two malicious versions containing a credential harvester, a Kubernetes lateral movement toolkit, and a persistent backdoor. Multiple security vendors, including Endor Labs and JFrog,…
-
Tax Search Ads Deliver ScreenConnect Malware Using Huawei Driver to Disable EDR
Tax Search Ads Deliver ScreenConnect Malware Using Huawei Driver to Disable EDR A large-scale malvertising campaign active since January 2026 has been observed targeting U.S.-based individuals searching for tax-related documents to serve rogue installers for ConnectWise ScreenConnect that drop a tool named HwAudKiller to blind security programs using the bring your own vulnerable driver (BYOVD)…
-
5 Learnings from the First-Ever Gartner Market Guide for Guardian Agents
5 Learnings from the First-Ever Gartner Market Guide for Guardian Agents On February 25, 2026, Gartner published its inaugural Market Guide for Guardian Agents, marking an important milestone for this emerging category. For those unfamiliar with the various Gartner report types, “a Market Guide defines a market and explains what clients can expect it to…
-
Hackers Use Fake Resumes to Steal Enterprise Credentials and Deploy Crypto Miner
Hackers Use Fake Resumes to Steal Enterprise Credentials and Deploy Crypto Miner An ongoing phishing campaign is targeting French-speaking corporate environments with fake resumes that lead to the deployment of cryptocurrency miners and information stealers. “The campaign uses highly obfuscated VBScript files disguised as resume/CV documents, delivered through phishing emails,” Securonix researchers Shikha Sangwan, Akshay…
-
The Hidden Cost of Cybersecurity Specialization: Losing Foundational Skills
The Hidden Cost of Cybersecurity Specialization: Losing Foundational Skills Cybersecurity has changed fast. Roles are more specialized, and tooling is more advanced. On paper, this should make organizations more secure. But in practice, many teams struggle with the same basic problems they faced years ago: unclear risk priorities, misaligned tooling decisions, and difficulty explaining security issues…
-
Iran Hacktivists Make Noise but Have Little Impact on War
Iran Hacktivists Make Noise but Have Little Impact on War Iran-aligned groups are trying to make their mark in the Gulf, but the results have fallen short of remarkable. Nate Nelson Go to gbhackers.com
-
Team Mirai and Democracy
Team Mirai and Democracy Japan’s election last month and the rise of the country’s newest and most innovative political party, Team Mirai, illustrates the viability of a different way to do politics. In this model, technology is used to make democratic processes stronger, instead of undermining them. It is harnessed to root out corruption, instead…
-
ISC Stormcast For Wednesday, March 25th, 2026 https://isc.sans.edu/podcastdetail/9864, (Wed, Mar 25th)
ISC Stormcast For Wednesday, March 25th, 2026 https://isc.sans.edu/podcastdetail/9864, (Wed, Mar 25th) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu
-
SmartApeSG campaign pushes Remcos RAT, NetSupport RAT, StealC, and Sectop RAT (ArechClient2), (Wed, Mar 25th)
SmartApeSG campaign pushes Remcos RAT, NetSupport RAT, StealC, and Sectop RAT (ArechClient2), (Wed, Mar 25th) Introduction This diary provides indicators from the SmartApeSG (ZPHP, HANEYMANEY) campaign I saw on Tuesday, 2026-03-24. SmartApeSG is one of many campaigns that use the ClickFix technique. This past week, I’ve seen NetSupport RAT as follow-up malware from Remcos RAT…
-
Detecting IP KVMs, (Tue, Mar 24th)
Detecting IP KVMs, (Tue, Mar 24th) I have written about how to use IP KVMs securely, and recently, researchers at Eclypsium published yet another report on IP KVM vulnerabilities. But there is another issue I haven’t mentioned yet with IP KVMs: rogue IP KVMs. IP KVMs are often used by criminals. For example, North Koreans used KVMs…
-
Weekly Update 496
Weekly Update 496 Watching OpenClaw do its thing must be like watching the first plane take flight. It’s a bit rickety and stuck together with a lot of sticky tape, but squint and you can see the potential for agentic AI to change the world as we know it. And I don’t think that’s hyperbolic.…
-
Checkmarx KICS Code Scanner Targeted in Widening Supply Chain Hit
Checkmarx KICS Code Scanner Targeted in Widening Supply Chain Hit TeamPCP is the likely cyber threat actor behind attacks on Trivy, Checkmarx’s KICS and VS Code plug-ins, and the LiteLLM AI library — and all signs point to more attacks to come. Jai Vijayan Go to gbhackers.com
-
How AI Coding Tools Crushed the Endpoint Security Fortress
How AI Coding Tools Crushed the Endpoint Security Fortress Security vendors have spent years building up defenses around the endpoint, but one researcher says AI coding tools have brought the walls down. Rob Wright Go to gbhackers.com
-
GitHub ‘OpenClaw Deployer’ Repo Delivers Trojan Instead
GitHub ‘OpenClaw Deployer’ Repo Delivers Trojan Instead An AI-assisted campaign is spreading more than 300 poisoned packages for diverse assets ranging from developer tools to game cheats. Elizabeth Montalbano Go to gbhackers.com
-
How a Large Bank Uses AI Digital Twins for Threat Hunting
How a Large Bank Uses AI Digital Twins for Threat Hunting JPMorgan Chase uses digital fingerprints and digital twins to spot online attackers and malicious behaviors while also reducing pesky false alerts. Bree Fowler Go to gbhackers.com
-
How a Large Bank Uses AI Digital Twins for Threat Hunting
How a Large Bank Uses AI Digital Twins for Threat Hunting JPMorgan Chase uses digital fingerprints and digital twins to spot online attackers and malicious behaviors while also reducing pesky false alerts. Bree Fowler Go to gbhackers.com
-
Microsoft Proposes Better Identity, Guardrails for AI Agents
Microsoft Proposes Better Identity, Guardrails for AI Agents Companies need better controls to manage key threats rising from the growth of agentic AI. These new features provide a starting point. Robert Lemos Go to gbhackers.com
-
OpenAI rolls out ChatGPT Library to store your personal files
OpenAI rolls out ChatGPT Library to store your personal files OpenAI is rolling out a new feature called ‘Library’ for ChatGPT, which allows you to store your personal files or images on OpenAI’s cloud storage, so you can reference those items in a future chat. […] Mayank Parmar Go to bleepingcomputer
-
Mazda discloses security breach exposing employee and partner data
Mazda discloses security breach exposing employee and partner data Mazda Motor Corporation (Mazda) announced that information belonging to its employees and business partners had been exposed in a security incident detected last December. […] Bill Toulas Go to bleepingcomputer
-
Tycoon2FA phishing platform returns after recent police disruption
Tycoon2FA phishing platform returns after recent police disruption The Tycoon2FA phishing-as-a-service (PhaaS) platform that Europol and partners disrupted on March 4 has already returned to previously observed activity levels. […] Bill Toulas Go to bleepingcomputer
-
TeamPCP deploys Iran-targeted wiper in Kubernetes attacks
TeamPCP deploys Iran-targeted wiper in Kubernetes attacks The TeamPCP hacking group is targeting Kubernetes clusters with a malicious script that wipes all machines when it detects systems configured for Iran. […] Bill Toulas Go to bleepingcomputer
-
Crunchyroll probes breach after hacker claims to steal 6.8M users’ data
Crunchyroll probes breach after hacker claims to steal 6.8M users’ data Popular anime streaming platform Crunchyroll is investigating a breach after hackers claimed to have stolen personal information for approximately 6.8 million people. […] Lawrence Abrams Go to bleepingcomputer
-
Gcore Radar report reveals 150% surge in DDoS attacks year-on-year
Gcore Radar report reveals 150% surge in DDoS attacks year-on-year Luxembourg, Luxembourg, March 24th, 2026, CyberNewswire Gcore data highlights a threat landscape defined by newfound automated attack capabilities, scale, and frequency Gcore, the global infrastructure and software provider for AI, cloud, network, and security solutions, today announced the findings of its Q3-Q4 2025 Gcore Radar…
-
New Data Leak Site Uncovered Linked to Active Initial Access Broker on Underground Forums
New Data Leak Site Uncovered Linked to Active Initial Access Broker on Underground Forums The underground cybercriminal world saw a notable development on March 22, 2026, when a new Tor-based leak site called “ALP-001” appeared on the dark web, openly marketing itself as a “Data Leaks / Access Market.” The emergence of this platform points…
-
NIST Releases Quick-Start Guide on Cybersecurity, Risk, and Workforce Management
NIST Releases Quick-Start Guide on Cybersecurity, Risk, and Workforce Management The National Institute of Standards and Technology (NIST) has released NIST SP 1308, the “Cybersecurity, Enterprise Risk Management, and Workforce Management Quick-Start Guide”. Published in March 2026, this strategic document provides a structured methodology to integrate cybersecurity risk management (CSRM) into broader enterprise risk management…
-
Roundcube Webmail Security Updates Patches Multiple Critical Vulnerabilities
Roundcube Webmail Security Updates Patches Multiple Critical Vulnerabilities A widely used open-source web-based IMAP email client, Roundcube Webmail, has released version 1.6.14, delivering critical security patches to fix multiple severe vulnerabilities in the 1.6.x branch. The release resolves a complex range of security issues, spanning from pre-authentication arbitrary file write risks to cross-site scripting (XSS)…
-
Chrome Security Update Fixes 8 Vulnerabilities Allowing Remote Code Execution
Chrome Security Update Fixes 8 Vulnerabilities Allowing Remote Code Execution Google has rolled out an urgent security update for the Chrome browser to address eight high-severity vulnerabilities. These newly patched security flaws could allow threat actors to execute arbitrary code remotely, posing a significant risk to user data and system integrity. The stable channel is…
-
North Korean Hackers Abuse VS Code Auto-Run Tasks to Deploy StoatWaffle Malware
North Korean Hackers Abuse VS Code Auto-Run Tasks to Deploy StoatWaffle Malware The North Korean threat actors behind the Contagious Interview campaign, also tracked as WaterPlum, have been attributed to a malware family tracked as StoatWaffle that’s distributed via malicious Microsoft Visual Studio Code (VS Code) projects. The use of VS Code “tasks.json” to distribute…
-
⚡ Weekly Recap: CI/CD Backdoor, FBI Buys Location Data, WhatsApp Ditches Numbers & More
⚡ Weekly Recap: CI/CD Backdoor, FBI Buys Location Data, WhatsApp Ditches Numbers & More Another week, another reminder that the internet is still a mess. Systems people thought were secure are being broken in simple ways, showing many still ignore basic advisories. This edition covers a mix of issues: supply chain attacks hitting CI/CD setups,…
-
We Found Eight Attack Vectors Inside AWS Bedrock. Here’s What Attackers Can Do with Them
We Found Eight Attack Vectors Inside AWS Bedrock. Here’s What Attackers Can Do with Them AWS Bedrock is Amazon’s platform for building AI-powered applications. It gives developers access to foundation models and the tools to connect those models directly to enterprise data and systems. That connectivity is what makes it powerful – but it’s also…
-
Microsoft Warns IRS Phishing Hits 29,000 Users, Deploys RMM Malware
Microsoft Warns IRS Phishing Hits 29,000 Users, Deploys RMM Malware Microsoft has warned of fresh campaigns that are capitalizing on the upcoming tax season in the U.S. to harvest credentials and deliver malware. The email campaigns take advantage of the urgency and time-sensitive nature of emails to send phishing messages masquerading as refund notices, payroll…
-
Trivy Hack Spreads Infostealer via Docker, Triggers Worm and Kubernetes Wiper
Trivy Hack Spreads Infostealer via Docker, Triggers Worm and Kubernetes Wiper Cybersecurity researchers have uncovered malicious artifacts distributed via Docker Hub following the Trivy supply chain attack, highlighting the widening blast radius across developer environments. The last known clean release of Trivy on Docker Hub is 0.69.3. The malicious versions 0.69.4, 0.69.5, and 0.69.6 have…
-
NICKEL ALLEY strategy: Fake it ’til you make it
NICKEL ALLEY strategy: Fake it ’til you make it Victimizing software developers via fake companies, jobs, and code repositories to steal cryptocurrency Categories: Threat Research Tags: NICKEL ALLEY, Contagious Interview, North Korea, clickfix Go to sophos
-
Microsoft Xbox One Hacked
Microsoft Xbox One Hacked It’s an impressive feat, over a decade after the box was released: Since reset glitching wasn’t possible, Gaasedelen thought some voltage glitching could do the trick. So, instead of tinkering with the system rest pin(s) the hacker targeted the momentary collapse of the CPU voltage rail. This was quite a feat,…
-
ISC Stormcast For Tuesday, March 24th, 2026 https://isc.sans.edu/podcastdetail/9862, (Tue, Mar 24th)
ISC Stormcast For Tuesday, March 24th, 2026 https://isc.sans.edu/podcastdetail/9862, (Tue, Mar 24th) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu
-
Tool updates: lots of security and logic fixes, (Mon, Mar 23rd)
Tool updates: lots of security and logic fixes, (Mon, Mar 23rd) So, I’ve been slow to get on the Claude Code/OpenCode/Codex/OpenClaw bandwagon, but I had some time last week so I asked Claude to review (/security-review) some of my python scripts. He found more than I’d like to admit, so I checked in a bunch…
-
ISC Stormcast For Monday, March 23rd, 2026 https://isc.sans.edu/podcastdetail/9860, (Mon, Mar 23rd)
ISC Stormcast For Monday, March 23rd, 2026 https://isc.sans.edu/podcastdetail/9860, (Mon, Mar 23rd) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu
-
‘CanisterWorm’ Springs Wiper Attack Targeting Iran
‘CanisterWorm’ Springs Wiper Attack Targeting Iran A financially motivated data theft and extortion group is attempting to inject itself into the Iran war, unleashing a worm that spreads through poorly secured cloud services and wipes data on infected systems that use Iran’s time zone or have Farsi set as the default language. Experts say the…
-
AI in the SOC: What Could Go Wrong?
AI in the SOC: What Could Go Wrong? Two cybersecurity leaders tested out AI in their respective SOCs for six months — and here’s what they learned. Becky Bracken Go to gbhackers.com
-
Trivy Supply Chain Attack Targets CI/CD Secrets
Trivy Supply Chain Attack Targets CI/CD Secrets A threat actor used the open source security tool to deploy an infostealer into CI/CD workflows and steal cloud credentials, SSH keys, tokens, and other sensitive secrets. Jai Vijayan Go to gbhackers.com
-
CISOs Debate Human Role in AI-Powered Security
CISOs Debate Human Role in AI-Powered Security The idea of a “human in the loop” in AI deployment was challenged during a security executive panel at the RSAC 2026 Conference this week. Alexander Culafi Go to gbhackers.com
-
Attackers Hide Infostealer in Copyright Infringement Notices
Attackers Hide Infostealer in Copyright Infringement Notices A phishing campaign targeting healthcare, government, hospitality, and education sectors in various countries uses several evasion techniques to avoid detection. Elizabeth Montalbano Go to gbhackers.com
-
AI Dominates RSAC Innovation Sandbox
AI Dominates RSAC Innovation Sandbox The 10 finalists will each have three minutes to make their case for being the most innovative, promising young security company of the year. Dark Reading Staff Go to gbhackers.com
-
511,000+ End-of-Life IIS Instances Found Online, Raising Security Risks
511,000+ End-of-Life IIS Instances Found Online, Raising Security Risks Security researchers at The Shadowserver Foundation have identified a massive internet-facing attack surface, discovering more than 511,000 End-of-Life Microsoft Internet Information Services (IIS) instances… Go to gbhackers.com
-
MioLab MacOS Stealer Expands With ClickFix, Wallet Theft, Team APIs
MioLab MacOS Stealer Expands With ClickFix, Wallet Theft, Team APIs As Apple’s macOS footprint grows in both consumer and enterprise environments, dedicated infostealers like MioLab (aka Nova) show that Macs are no longer a… Go to gbhackers.com
-
Hackers Exploit Quest KACE SMA Flaw to Harvest Credentials
Hackers Exploit Quest KACE SMA Flaw to Harvest Credentials Security Researchers have detected active exploitation targeting unpatched Quest KACE Systems Management Appliance (SMA) instances. Starting the week of March 9, 2026, threat actors… Go to gbhackers.com
-
CISA Warns of Craft CMS Code Injection Flaw Exploited in Active Attacks
CISA Warns of Craft CMS Code Injection Flaw Exploited in Active Attacks The Cybersecurity and Infrastructure Security Agency (CISA) has officially added a critical vulnerability affecting Craft CMS to its Known Exploited Vulnerabilities (KEV) catalog. Tracked… Go to gbhackers.com
-
Oblivion RAT Masquerades as Play Store Update to Spy on Android Users
Oblivion RAT Masquerades as Play Store Update to Spy on Android Users A newly discovered Android remote access trojan (RAT) called Oblivion RAT is raising concerns across the mobile threat landscape. Marketed as a malware-as-a-service (MaaS)… Go to gbhackers.com
-
FBI warns of Handala hackers using Telegram in malware attacks
FBI warns of Handala hackers using Telegram in malware attacks The U.S. Federal Bureau of Investigation (FBI) warned network defenders that Iranian hackers linked to the country’s Ministry of Intelligence and Security (MOIS) are using Telegram in malware attacks. […] Sergiu Gatlan Go to bleepingcomputer
-
CISA orders feds to patch DarkSword iOS flaws exploited attacks
CISA orders feds to patch DarkSword iOS flaws exploited attacks CISA ordered U.S. government agencies to patch three iOS vulnerabilities targeted in cryptocurrency theft and cyberespionage attacks using the DarkSword exploit kit. […] Sergiu Gatlan Go to bleepingcomputer
-
New KB5085516 emergency update fixes Microsoft account sign-in
New KB5085516 emergency update fixes Microsoft account sign-in Microsoft has released an emergency update to address a major issue that breaks sign-ins with Microsoft accounts across multiple Microsoft apps, including Teams and OneDrive. […] Sergiu Gatlan Go to bleepingcomputer
-
VoidStealer malware steals Chrome master key via debugger trick
VoidStealer malware steals Chrome master key via debugger trick An information stealer called VoidStealer uses a new approach to bypass Chrome’s Application-Bound Encryption (ABE) and extract the master key for decrypting sensitive data stored in the browser. […] Bill Toulas Go to bleepingcomputer
-
New CanisterWorm Steals npm Tokens and Spreads Through Compromised Publisher Accounts
New CanisterWorm Steals npm Tokens and Spreads Through Compromised Publisher Accounts A new wave of supply chain attacks is hitting the npm ecosystem through a self-propagating malware campaign known as CanisterWorm. The threat, linked to a group tracked as “TeamPCP,” compromises legitimate publisher namespaces and pushes poisoned package versions, effectively turning trusted developer tools into…
-
CISA Warns of Apple Vulnerabilities Linked to DarkSword iOS Exploit Chain Exploited in Attacks
CISA Warns of Apple Vulnerabilities Linked to DarkSword iOS Exploit Chain Exploited in Attacks An urgent warning regarding three critical Apple vulnerabilities that threat actors are actively exploiting in the wild. These security flaws, officially tracked as CVE-2025-31277, CVE-2025-43510, and CVE-2025-43520, were recently added to CISA’s Known Exploited Vulnerabilities (KEV) catalog. Security researchers have linked…
-
Copyright-Themed Lures Deliver Multi-Stage PureLog Stealer in New Credential Theft Campaign
Copyright-Themed Lures Deliver Multi-Stage PureLog Stealer in New Credential Theft Campaign A new malware campaign is targeting organizations across healthcare, government, education, and hospitality sectors using cleverly disguised copyright violation notices to deliver PureLog Stealer, a powerful information-stealing malware. The campaign, first analyzed in March 2026, tricks victims into executing a malicious file that looks…
-
Microsoft Emergency Out-of-Band Update for Windows 11 to Fix Microsoft Account Sign-In Failure
Microsoft Emergency Out-of-Band Update for Windows 11 to Fix Microsoft Account Sign-In Failure Microsoft has issued an out-of-band (OOB) update for Windows 11 versions 25H2 and 24H2, identified as KB5085516, addressing a critical sign-in bug introduced by the March 2026 Patch Tuesday release. The update carries OS builds 26200.8039 and 26100.8039 and was made available…
-
Crunchyroll Data Breach — Threat Actor Claims Exfiltration of 100 GB of User Data
Crunchyroll Data Breach — Threat Actor Claims Exfiltration of 100 GB of User Data A threat actor has allegedly exfiltrated approximately 100 GB of personally identifiable information (PII) from Crunchyroll, the Sony-owned anime streaming giant, after gaining access through a compromised employee at the platform’s outsourcing partner, Telus. The breach, which reportedly occurred on March…
-
Hackers Exploit CVE-2025-32975 (CVSS 10.0) to Hijack Unpatched Quest KACE SMA Systems
Hackers Exploit CVE-2025-32975 (CVSS 10.0) to Hijack Unpatched Quest KACE SMA Systems Threat actors are suspected to be exploiting a maximum-severity security flaw impacting Quest KACE Systems Management Appliance (SMA), according to Arctic Wolf. The cybersecurity company said it observed malicious activity starting the week of March 9, 2026, in customer environments that’s consistent with…
-
Trivy vulnerability scanner breach pushed infostealer via GitHub Actions
Trivy vulnerability scanner breach pushed infostealer via GitHub Actions The Trivy vulnerability scanner was compromised in a supply-chain attack by threat actors known as TeamPCP, which distributed credential-stealing malware through official releases and GitHub Actions. […] Lawrence Abrams Go to bleepingcomputer
-
Google adds ‘Advanced Flow’ for safe APK sideloading on Android
Google adds ‘Advanced Flow’ for safe APK sideloading on Android Google has announced a new mechanism in Android called Advanced Flow that will allow sideloading APKs from unverified developers for power users in a more secure way. […] Bill Toulas Go to bleepingcomputer
-
Microsoft Azure Monitor alerts abused for callback phishing attacks
Microsoft Azure Monitor alerts abused for callback phishing attacks Microsoft Azure Monitor alerts are being abused to send callback phishing emails that impersonate warnings from the Microsoft Security Team about unauthorized charges on your account. […] Lawrence Abrams Go to bleepingcomputer
-
Hackers Compromise Trivy Scanner to Inject malicious Scripts and Steal Login Credentials
Hackers Compromise Trivy Scanner to Inject malicious Scripts and Steal Login Credentials A sophisticated supply chain attack targeting the official Trivy GitHub Action (aquasecurity/trivy-action) has compromised continuous integration and continuous deployment (CI/CD) pipelines globally. Disclosed in late March 2026, this incident marks the second distinct compromise affecting the Trivy ecosystem within a single month. Threat…
-
FBI Warns Russian Hackers Target Signal, WhatsApp in Mass Phishing Attacks
FBI Warns Russian Hackers Target Signal, WhatsApp in Mass Phishing Attacks Threat actors affiliated with Russian Intelligence Services are conducting phishing campaigns to compromise commercial messaging applications (CMAs) like WhatsApp and Signal to seize control of accounts belonging to individuals with high intelligence value, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) and Federal Bureau…
-
Oracle Patches Critical CVE-2026-21992 Enabling Unauthenticated RCE in Identity Manager
Oracle Patches Critical CVE-2026-21992 Enabling Unauthenticated RCE in Identity Manager Oracle has released security updates to address a critical security flaw impacting Identity Manager and Web Services Manager that could be exploited to achieve remote code execution. The vulnerability, tracked as CVE-2026-21992, carries a CVSS score of 9.8 out of a maximum of 10.0. “This…
-
Trivy Supply Chain Attack Triggers Self-Spreading CanisterWorm Across 47 npm Packages
Trivy Supply Chain Attack Triggers Self-Spreading CanisterWorm Across 47 npm Packages The threat actors behind the supply chain attack targeting the popular Trivy scanner are suspected to be conducting follow-on attacks that have led to the compromise of a large number of npm packages with a previously undocumented self-propagating worm dubbed CanisterWorm. The name is…
-
CISA Flags Apple, Craft CMS, Laravel Bugs in KEV, Orders Patching by April 3, 2026
CISA Flags Apple, Craft CMS, Laravel Bugs in KEV, Orders Patching by April 3, 2026 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added five security flaws impacting Apple, Craft CMS, and Laravel Livewire to its Known Exploited Vulnerabilities (KEV) catalog, urging federal agencies to patch them by April 3, 2026. The vulnerabilities…
-
GSocket Backdoor Delivered Through Bash Script, (Fri, Mar 20th)
GSocket Backdoor Delivered Through Bash Script, (Fri, Mar 20th) Yesterday, I discovered a malicious Bash script that installs a GSocket backdoor on the victim’s computer. I don’t know the source of the script not how it is delivered to the victim. GSocket[1] is a networking tool, but also a relay infrastructure, that enables direct, peer-to-peer–style…
-
Oracle Fixes High-Severity RCE Vulnerability Affecting Identity and Web Services Platforms
Oracle Fixes High-Severity RCE Vulnerability Affecting Identity and Web Services Platforms Oracle recently issued an urgent security alert regarding a critical Remote Code Execution (RCE) flaw that impacts both Oracle Identity Manager and Oracle Web… Go to gbhackers.com
-
Trivy Vulnerability Scanner Compromised to Inject Malicious Scripts That Steal Credentials
Trivy Vulnerability Scanner Compromised to Inject Malicious Scripts That Steal Credentials A highly sophisticated supply chain attack has successfully compromised the official Trivy GitHub Actions repository, severely impacting continuous integration environments. Discovered on March 19,… Go to gbhackers.com
-
FBI and CISA Flag Russian Cyber Operations Targeting Select Individuals via Signal
FBI and CISA Flag Russian Cyber Operations Targeting Select Individuals via Signal The Federal Bureau of Investigation (FBI) and the Cybersecurity and Infrastructure Security Agency (CISA) have recently released a joint cybersecurity advisory regarding a widespread… Go to gbhackers.com
-
Copyright Complaint Lures Linked to New PureLog Stealer Credential Theft Wave
Copyright Complaint Lures Linked to New PureLog Stealer Credential Theft Wave Threat actors are actively distributing the PureLog Stealer through a sophisticated, multi-stage attack campaign disguised as legal copyright violation notices. This information-stealing malware is… Go to gbhackers.com
-
Chrome Security Update Fixes 26 Vulnerabilities Enabling Remote Malicious Code Execution
Chrome Security Update Fixes 26 Vulnerabilities Enabling Remote Malicious Code Execution Google has released a critical security update for its Chrome desktop web browser, addressing 26 distinct vulnerabilities that could enable attackers to execute malicious… Go to gbhackers.com
-
FBI links Signal phishing attacks to Russian intelligence services
FBI links Signal phishing attacks to Russian intelligence services The FBI has issued a public service announcement warning that Russian intelligence-linked threat actors are actively targeting users of encrypted messaging apps such as Signal and WhatsApp in phishing campaigns that have already compromised thousands of accounts. […] Lawrence Abrams Go to bleepingcomputer
-
Oracle pushes emergency fix for critical Identity Manager RCE flaw
Oracle pushes emergency fix for critical Identity Manager RCE flaw Oracle has released an out-of-band security update to fix a critical unauthenticated remote code execution vulnerability in Identity Manager and Web Services Manager tracked as CVE-2026-21992. […] Lawrence Abrams Go to bleepingcomputer
-
Police take down 373,000 fake CSAM sites in Operation Alice
Police take down 373,000 fake CSAM sites in Operation Alice An international law enforcement action called Operation Alice has shut down over 373,000 dark web sites that offered fake CSAM packages. […] Bill Toulas Go to bleepingcomputer
-
CISA orders feds to patch max-severity Cisco flaw by Sunday
CISA orders feds to patch max-severity Cisco flaw by Sunday The Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch a maximum-severity vulnerability, CVE-2026-20131, in Cisco Secure Firewall Management Center (FMC) by Sunday, March 22. […] Bill Toulas Go to bleepingcomputer
-
How CISOs Can Survive the Era of Geopolitical Cyberattacks
How CISOs Can Survive the Era of Geopolitical Cyberattacks Geopolitical tensions are driving destructive cyberattacks designed to disrupt operations, not demand ransom. CISOs must limit lateral movement and contain breaches to reduce the impact of wiper campaigns. […] Sponsored by Zero Networks Go to bleepingcomputer
-
FBI, CISA Warn Russian Hackers Are Targeting High-Value Individuals Through Signal
FBI, CISA Warn Russian Hackers Are Targeting High-Value Individuals Through Signal The Federal Bureau of Investigation (FBI) and the Cybersecurity and Infrastructure Security Agency (CISA) have recently released a joint cybersecurity advisory regarding a widespread phishing campaign. The alert warns that Russian Intelligence Services are actively targeting users of encrypted messaging applications, primarily Signal. The…