Tax search ads use Huawei drivers to deliver ScreenConnect malware that disables EDR

Ravi LakshmananMarch 24, 2026Endpoint security/social engineering A large-scale malvertising campaign, active since January 2026, has been observed targeting individuals located in the United States searching for tax-related documents and serving fraudulent ConnectWise ScreenConnect installers. The installer drops a tool named HwAudKiller that uses Bring Your Vulnerable Driver (BYOVD) techniques to blind security programs. “This campaign […]
Hackers use fake resumes to steal corporate credentials and deploy Crypto Miner

Ravi LakshmananMarch 24, 2026Malware/Endpoint Security An ongoing phishing campaign targets French-speaking corporate environments using fake resumes that lead to the introduction of cryptocurrency miners and information thieves. “The campaign uses highly obfuscated VBScript files disguised as resumes/CV documents, delivered through phishing emails,” Securonix researchers Shikha Sangwan, Akshay Gaikwad, and Aaron Beardslee said in a report […]
Ghost Campaign uses 7 npm packages to steal cryptocurrency wallets and credentials

Cybersecurity researchers have discovered a series of malicious npm packages designed to steal cryptocurrency wallets and sensitive data. This activity is tracked by ReversingLabs as the Ghost campaign. The list of identified packages, all published by a user named mikilanjillo, can be found below. React Performance Suite React State Optimizer Core React Fast Utility sa […]
5 Learnings from the First-Ever Gartner Market Guide for Guardian Agents

On February 25, 2026, Gartner published its inaugural Market Guide for Guardian Agents, marking an important milestone for this emerging category. For those unfamiliar with the various Gartner report types, “a Market Guide defines a market and explains what clients can expect it to do in the short term. With the focus on early, more […]
TeamPCP hacks Checkmarx GitHub actions using stolen CI credentials

Two more GitHub Actions workflows became the latest vulnerabilities to be compromised by credential-stealing malware by a threat actor known as TeamPCP, the cloud-native cybercrime operation that was also behind the Trivy supply chain attack. Both workflows are maintained by supply chain security company Checkmarx and are listed below. Cloud security company Sysdig announced that […]
The hidden costs of cybersecurity specialization: loss of foundational skills

hacker newsMarch 24, 2026Security operations / network security Cybersecurity is changing rapidly. Roles are more specialized and tools are more sophisticated. In theory, this should make your organization more secure. But in reality, many teams are struggling with the same basic problems they faced years ago: unclear risk prioritization, misaligned tooling decisions, and difficulty explaining […]
US sentences Russian hacker to 6 years and 75 years in prison for involvement in $9 million worth of ransomware damage

Ravi LakshmananMarch 24, 2026Cybercrime/Network Security A 26-year-old Russian national has been sentenced to 6.75 years (81 months) in prison in the United States for helping major cybercrime groups, including the Yanluowang ransomware team, carry out numerous attacks on American companies and other organizations. According to the U.S. Department of Justice (DoJ), Aleksei Olegovich Volkov facilitated […]
Citrix asks to patch critical flaw in NetScaler that could lead to unauthenticated data leaks

Ravi LakshmananMarch 24, 2026Vulnerabilities / Enterprise Security Citrix has released security updates that address two vulnerabilities in NetScaler ADC and NetScaler Gateway that contain critical flaws that can be exploited to leak sensitive data from applications. The vulnerabilities are listed below – CVE-2026-3055 (CVSS score: 9.3) – Insufficient input validation leading to memory over-read CVE-2026-4368 […]
North Korean hackers exploit VS Code autorun tasks to deploy StoatWaffle malware

The North Korean threat actor behind the Contagious Interview campaign, also tracked as WaterPlum, is believed to be from the malware family tracked as StoatWaffle, which is distributed via malicious Microsoft Visual Studio Code (VS Code) projects. Using VS Code’s “tasks.json” to distribute malware is a relatively new tactic employed by threat actors since December […]
CI/CD Backdoor, FBI Buys Location Data, WhatsApp Ditches Numbers & More

Ravie LakshmananMar 23, 2026Cybersecurity / Hacking Another week, another reminder that the internet is still a mess. Systems people thought were secure are being broken in simple ways, showing many still ignore basic advisories. This edition covers a mix of issues: supply chain attacks hitting CI/CD setups, long-abused IoT devices being shut down, and exploits […]