Device code phishing attacks 340+ Microsoft 365 organizations in 5 countries using OAuth exploitation

Cybersecurity researchers are calling attention to an active device code phishing campaign targeting Microsoft 365 IDs across more than 340 organizations in the United States, Canada, Australia, New Zealand, and Germany. According to Huntress, this activity was first discovered on February 19, 2026, and subsequent cases have been occurring at an accelerated pace since then. […]
FCC bans new foreign-made routers over supply chain and cyber risk concerns

Ravi LakshmananMarch 25, 2026Network security/data protection The Federal Communications Commission (FCC) announced Monday that it is banning the import of new foreign-made consumer routers, citing “unacceptable” risks to cyber and national security. FCC Chairman Brendan Carr said in a post on The development means new models of foreign-made routers will no longer be eligible for […]
TeamPCP backdoor LiteLLM versions 1.82.7 to 1.82.8 Likely due to Trivy CI/CD compromise

TeamPCP, the threat actor behind the recent Trivy and KICS breaches, compromised a popular Python package named litellm and pushed two malicious versions containing a credential harvester, a Kubernetes lateral movement toolkit, and a persistent backdoor. Multiple security vendors, including Endor Labs and JFrog, revealed that litellm versions 1.82.7 and 1.82.8 were released on March […]
Tax search ads use Huawei drivers to deliver ScreenConnect malware that disables EDR

Ravi LakshmananMarch 24, 2026Endpoint security/social engineering A large-scale malvertising campaign, active since January 2026, has been observed targeting individuals located in the United States searching for tax-related documents and serving fraudulent ConnectWise ScreenConnect installers. The installer drops a tool named HwAudKiller that uses Bring Your Vulnerable Driver (BYOVD) techniques to blind security programs. “This campaign […]
Hackers use fake resumes to steal corporate credentials and deploy Crypto Miner

Ravi LakshmananMarch 24, 2026Malware/Endpoint Security An ongoing phishing campaign targets French-speaking corporate environments using fake resumes that lead to the introduction of cryptocurrency miners and information thieves. “The campaign uses highly obfuscated VBScript files disguised as resumes/CV documents, delivered through phishing emails,” Securonix researchers Shikha Sangwan, Akshay Gaikwad, and Aaron Beardslee said in a report […]
Ghost Campaign uses 7 npm packages to steal cryptocurrency wallets and credentials

Cybersecurity researchers have discovered a series of malicious npm packages designed to steal cryptocurrency wallets and sensitive data. This activity is tracked by ReversingLabs as the Ghost campaign. The list of identified packages, all published by a user named mikilanjillo, can be found below. React Performance Suite React State Optimizer Core React Fast Utility sa […]
5 Learnings from the First-Ever Gartner Market Guide for Guardian Agents

On February 25, 2026, Gartner published its inaugural Market Guide for Guardian Agents, marking an important milestone for this emerging category. For those unfamiliar with the various Gartner report types, “a Market Guide defines a market and explains what clients can expect it to do in the short term. With the focus on early, more […]
TeamPCP hacks Checkmarx GitHub actions using stolen CI credentials

Two more GitHub Actions workflows became the latest vulnerabilities to be compromised by credential-stealing malware by a threat actor known as TeamPCP, the cloud-native cybercrime operation that was also behind the Trivy supply chain attack. Both workflows are maintained by supply chain security company Checkmarx and are listed below. Cloud security company Sysdig announced that […]
The hidden costs of cybersecurity specialization: loss of foundational skills

hacker newsMarch 24, 2026Security operations / network security Cybersecurity is changing rapidly. Roles are more specialized and tools are more sophisticated. In theory, this should make your organization more secure. But in reality, many teams are struggling with the same basic problems they faced years ago: unclear risk prioritization, misaligned tooling decisions, and difficulty explaining […]
US sentences Russian hacker to 6 years and 75 years in prison for involvement in $9 million worth of ransomware damage

Ravi LakshmananMarch 24, 2026Cybercrime/Network Security A 26-year-old Russian national has been sentenced to 6.75 years (81 months) in prison in the United States for helping major cybercrime groups, including the Yanluowang ransomware team, carry out numerous attacks on American companies and other organizations. According to the U.S. Department of Justice (DoJ), Aleksei Olegovich Volkov facilitated […]