Citrix NetScaler memory overread bug under active investigation for CVE-2026-3055 (CVSS 9.3)

Ravi LakshmananMarch 28, 2026Vulnerability/Network Security According to Defused Cyber ​​and watchTowr, a critical security flaw affecting Citrix NetScaler ADC and NetScaler Gateway was recently uncovered and active reconnaissance activity has been witnessed. Vulnerability CVE-2026-3055 (CVSS score: 9.3) refers to a memory over-read caused by insufficient input validation, which could be exploited by an attacker to […]

CISA adds CVE-2025-53521 to KEV after active F5 BIG-IP APM exploit

Ravi LakshmananMarch 28, 2026Vulnerability/Network Security The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added a critical security flaw affecting the F5 BIG-IP Access Policy Manager (APM) to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerability in question is CVE-2025-53521 (CVSS v4 score: 9.3), which could allow an attacker […]

TA446 deploys DarkSword iOS exploit kit in targeted spear-phishing campaign

Ravi LakshmananMarch 28, 2026Mobile Security / Email Security Proofpoint has revealed details of a targeted email campaign in which Russian-linked attackers leveraged the recently revealed DarkSword exploit kit to target iOS devices. We have high confidence that this activity is the work of a Russian state-sponsored threat group known as TA446, and is also tracked […]

Apple uses web-based exploit to send lock screen alerts to older iPhones

Ravi LakshmananMarch 27, 2026Spyware/Mobile Security Apple is currently sending lock screen notifications to iPhones and iPads running older versions of iOS and iPadOS to warn users about web-based attacks and prompt them to install updates. This development was first reported by MacRumors. “Apple is aware of an attack targeting older iOS software, including the version […]

TeamPCP pushes malicious Telnyx version to PyPI and hides stealer in WAV files

TeamPCP, the threat actor behind supply chain attacks targeting Trivy, KICS, and litellm, compromised the Telnyx Python package by pushing two malicious versions to steal sensitive data. Two versions, 4.87.1 and 4.87.2, published to the Python Package Index (PyPI) repository on March 27, 2026, hid the credential harvesting functionality inside a .WAV file. Users are […]

Open bug in VSX allows malicious VS Code extensions to bypass pre-publication security checks

Ravi LakshmananMarch 27, 2026Software Security/DevSecOps Cybersecurity researchers have detailed a patched bug that affects Open VSX’s pre-publication scanning pipeline and allows the tool to bypass the review process and publish malicious Microsoft Visual Studio Code (VS Code) extensions to the registry. “The pipeline had a single Boolean return value that meant both ‘no scanners configured’ […]

AitM phishing uses Cloudflare turnstile bypass to target TikTok business accounts

Ravi LakshmananMarch 27, 2026Ransomware/Malware In a new campaign, threat actors are leveraging adversary-in-the-middle (AitM) phishing pages to seize control of TikTok for Business accounts, according to a report from Push Security. Business accounts associated with social media platforms are lucrative targets because they can be weaponized by malicious actors for malvertising and malware distribution. “TikTok […]

Bearlyfy attacks over 70 Russian companies with custom GenieLocker ransomware

Ravi LakshmananMarch 27, 2026Threat Intelligence/Vulnerability A pro-Ukrainian group called Bearlyfy has been implicated in more than 70 cyberattacks targeting Russian companies since first emerging into the threat world in January 2025, with the most recent attacks leveraging a custom Windows ransomware strain codenamed GenieLocker. Russian security vendor F6 said: “Bearlyfy (also known as Labubu) operates […]

LangChain, LangGraph flaw exposes files, secrets, and databases of widely used AI framework

Ravi LakshmananMarch 27, 2026Vulnerability / Artificial Intelligence Cybersecurity researchers have revealed three security vulnerabilities affecting LangChain and LangGraph. Successful exploitation could lead to the disclosure of filesystem data, environmental secrets, and conversation history. Both LangChain and LangGraph are open source frameworks used to build applications that leverage large-scale language models (LLMs). LangGraph is built on […]

China-linked Red Mensheng uses stealth BPF door implant to spy via communications network

A long-term, ongoing campaign attributed to threat actors linked to China has integrated communications networks to conduct espionage against government networks. This strategic location effort to embed and maintain stealth access mechanisms within critical environments is believed to be the work of Red Menshen, a threat cluster also tracked as Earth Bluecrow, DecisiveArchitect, and Red […]