Trivy Security Scanner GitHub Actions Compromised, Hijacks 75 Tags and Steals CI/CD Secrets

Trivy, a popular open source vulnerability scanner managed by Aqua Security, has been compromised for the second time in less than a month to distribute malware that steals sensitive CI/CD secrets. The latest incident affected GitHub Actions ‘aquasecurity/trivy-action’ and ‘aquasecurity/setup-trivy’. These are used to scan Docker container images for vulnerabilities and configure GitHub Actions workflows […]
Langflow critical flaw CVE-2026-33017 triggers attacks within 20 hours of publication

The critical security flaw affecting Langflow was being actively exploited within 20 hours of publication, highlighting the speed with which threat actors weaponize newly disclosed vulnerabilities. This security flaw, tracked as CVE-2026-33017 (CVSS score: 9.3), could result in remote code execution through a combination of missing authentication and code injection. According to Langflow’s advisory for […]
Google adds 24-hour wait for sideloading unverified apps to reduce malware and fraud

Ravi LakshmananMarch 20, 2026Data privacy/mobile security Google on Thursday announced a new “advanced flow” for Android sideloading that requires a 24-hour waiting period to install apps from unverified developers in an effort to balance openness and security. The new changes come on the back of the developer verification mandate the tech giant announced last year, […]
The importance of behavioral analysis in cyber attacks using AI

hacker newsMarch 20, 2026Artificial intelligence/data protection Artificial intelligence (AI) is changing the way individuals and organizations conduct many activities, including the way cybercriminals conduct phishing attacks and iterate malware. Cybercriminals are now using AI to generate personalized phishing emails, deepfakes, and malware to evade traditional detection by impersonating normal user activity and bypassing traditional security […]
Magento PolyShell flaw allows unauthorized uploads, RCEs, and account takeover

Ravi LakshmananMarch 20, 2026Web security/vulnerabilities Sansec warns that Magento’s REST API has a critical security flaw that could allow an unauthenticated attacker to upload arbitrary executable files and perform code execution or account takeover. This vulnerability was codenamed PolyShell by Sansec due to the fact that the attack relies on disguising malicious code as an […]
Department of Justice thwarts IoT botnet of 3 million devices behind record 31.4 Tbps global DDoS attack

The U.S. Department of Justice (DoJ) announced Thursday that it has disrupted command and control (C2) infrastructure used by several Internet of Things (IoT) botnets, including AISURU, Kimwolf, JackSkid, and Mossad, as part of a court-authorized law enforcement operation. In this effort, authorities in Canada and Germany are also targeting the operators behind these botnets, […]
Apple warns that older iPhones are vulnerable to Coruna and DarkSword exploit kit attacks

Ravi LakshmananMarch 20, 2026Mobile security/malware Apple is reminding users still running older versions of iOS to update their iPhones to protect against web-based attacks carried out through powerful exploit kits such as Coruna and DarkSword. These attacks leverage malicious web content to target older versions of iOS, triggering infection chains that lead to the theft […]
Speagle malware hijacks Cobra DocGuard and steals data via compromised servers

Ravi LakshmananMarch 19, 2026Cyber espionage/threat intelligence Cybersecurity researchers have reported a new malware called Speagle that hijacks the functionality and infrastructure of a legitimate program called Cobra DocGuard. “Speagle is designed to covertly collect sensitive information from infected computers and send it to a Cobra DocGuard server that has been compromised by an attacker, masking […]
54 EDR killers use BYOVD to exploit 34 signed vulnerability drivers to disable security

A new analysis of endpoint detection and response (EDR) killers reveals that 54 of them leverage a technique known as bring-your-own-vulnerable-driver (BYOVD), for a total of 34 vulnerable drivers. EDR killer programs are common in ransomware intrusions because they provide a way for affiliates to neutralize security software before deploying file-encrypting malware. This is done […]
FortiGate RaaS, Citrix Exploits, MCP Abuse, LiveChat Phish & More

Ravie LakshmananMar 19, 2026Cybersecurity / Hacking News ThreatsDay Bulletin is back on The Hacker News, and this week feels off in a familiar way. Nothing loud, nothing breaking everything at once. Just a lot of small things that shouldn’t work anymore but still do. Some of it looks simple, almost sloppy, until you see how […]