Citrix asks to patch critical flaw in NetScaler that could lead to unauthenticated data leaks

Ravi LakshmananMarch 24, 2026Vulnerabilities / Enterprise Security Citrix has released security updates that address two vulnerabilities in NetScaler ADC and NetScaler Gateway that contain critical flaws that can be exploited to leak sensitive data from applications. The vulnerabilities are listed below – CVE-2026-3055 (CVSS score: 9.3) – Insufficient input validation leading to memory over-read CVE-2026-4368 […]

North Korean hackers exploit VS Code autorun tasks to deploy StoatWaffle malware

The North Korean threat actor behind the Contagious Interview campaign, also tracked as WaterPlum, is believed to be from the malware family tracked as StoatWaffle, which is distributed via malicious Microsoft Visual Studio Code (VS Code) projects. Using VS Code’s “tasks.json” to distribute malware is a relatively new tactic employed by threat actors since December […]

CI/CD Backdoor, FBI Buys Location Data, WhatsApp Ditches Numbers & More

Ravie LakshmananMar 23, 2026Cybersecurity / Hacking Another week, another reminder that the internet is still a mess. Systems people thought were secure are being broken in simple ways, showing many still ignore basic advisories. This edition covers a mix of issues: supply chain attacks hitting CI/CD setups, long-abused IoT devices being shut down, and exploits […]

Microsoft attacks 29,000 users with IRS phishing, deploys RMM malware and warns

Ravi LakshmananMarch 23, 2026Email security / cloud security Microsoft has warned of new campaigns taking advantage of the upcoming tax season in the US to harvest credentials and distribute malware. This email campaign takes advantage of the urgent and time-sensitive nature of email to send phishing messages disguised as refund notices, payroll forms, filing reminders, […]

Trivy Hack spreads Infostealer via Docker and triggers worm and Kubernetes Wiper

Ravi LakshmananMarch 23, 2026Cloud security/DevOps Cybersecurity researchers discovered malicious artifacts distributed via Docker Hub after the Trivy supply chain attack, highlighting the growing scope of the explosion across developer environments. The latest known clean release of Trivy on Docker Hub is 0.69.3. Malicious versions 0.69.4, 0.69.5, and 0.69.6 have since been removed from the container […]

Hackers exploit CVE-2025-32975 (CVSS 10.0) to hijack unpatched Quest KACE SMA systems

Ravi LakshmananMarch 23, 2026Vulnerabilities / Endpoint Security According to Arctic Wolf, attackers are suspected of exploiting a maximum severity security flaw affecting the Quest KACE Systems Management Appliance (SMA). The cybersecurity firm said it observed malicious activity in customer environments starting the week of March 9, 2026, consistent with the exploitation of CVE-2025-32975 on unpatched […]

FBI warns Russian hackers are targeting Signal, WhatsApp in massive phishing attack

Rabi LakshmananMarch 21, 2026Cyber ​​espionage/threat intelligence The U.S. Cybersecurity and Infrastructure Security Agency (CISA) and the Federal Bureau of Investigation (FBI) announced Friday that attackers affiliated with Russian intelligence agencies are conducting a phishing campaign to compromise commercial messaging applications (CMAs) such as WhatsApp and Signal and take control of the accounts of individuals with […]

CISA flags Apple, Craft CMS, KEV’s Laravel bug and orders patching by April 3, 2026

Ravi LakshmananMarch 21, 2026Vulnerability/Threat Intelligence The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added five security flaws affecting Apple, Craft CMS, and Laravel Livewire to its Known Exploited Vulnerabilities (KEV) catalog, requiring federal agencies to patch them by April 3, 2026. The vulnerabilities being exploited are as follows: CVE-2025-31277 (CVSS Score: 8.8) – […]

Trivy supply chain attack causes CanisterWorm to self-spread across 47 npm packages

Ravi LakshmananMarch 21, 2026Malware/Threat Intelligence The attackers behind the supply chain attack targeting the popular Trivy scanner are suspected of carrying out a follow-up attack that led to the compromise of numerous npm packages with a previously undocumented self-propagating worm called CanisterWorm. The name comes from the fact that the malware uses an ICP canister, […]