Apple uses web-based exploit to send lock screen alerts to older iPhones

Ravi LakshmananMarch 27, 2026Spyware/Mobile Security Apple is currently sending lock screen notifications to iPhones and iPads running older versions of iOS and iPadOS to warn users about web-based attacks and prompt them to install updates. This development was first reported by MacRumors. “Apple is aware of an attack targeting older iOS software, including the version […]
TeamPCP pushes malicious Telnyx version to PyPI and hides stealer in WAV files

TeamPCP, the threat actor behind supply chain attacks targeting Trivy, KICS, and litellm, compromised the Telnyx Python package by pushing two malicious versions to steal sensitive data. Two versions, 4.87.1 and 4.87.2, published to the Python Package Index (PyPI) repository on March 27, 2026, hid the credential harvesting functionality inside a .WAV file. Users are […]
Open bug in VSX allows malicious VS Code extensions to bypass pre-publication security checks

Ravi LakshmananMarch 27, 2026Software Security/DevSecOps Cybersecurity researchers have detailed a patched bug that affects Open VSX’s pre-publication scanning pipeline and allows the tool to bypass the review process and publish malicious Microsoft Visual Studio Code (VS Code) extensions to the registry. “The pipeline had a single Boolean return value that meant both ‘no scanners configured’ […]
AitM phishing uses Cloudflare turnstile bypass to target TikTok business accounts

Ravi LakshmananMarch 27, 2026Ransomware/Malware In a new campaign, threat actors are leveraging adversary-in-the-middle (AitM) phishing pages to seize control of TikTok for Business accounts, according to a report from Push Security. Business accounts associated with social media platforms are lucrative targets because they can be weaponized by malicious actors for malvertising and malware distribution. “TikTok […]
Bearlyfy attacks over 70 Russian companies with custom GenieLocker ransomware

Ravi LakshmananMarch 27, 2026Threat Intelligence/Vulnerability A pro-Ukrainian group called Bearlyfy has been implicated in more than 70 cyberattacks targeting Russian companies since first emerging into the threat world in January 2025, with the most recent attacks leveraging a custom Windows ransomware strain codenamed GenieLocker. Russian security vendor F6 said: “Bearlyfy (also known as Labubu) operates […]
LangChain, LangGraph flaw exposes files, secrets, and databases of widely used AI framework

Ravi LakshmananMarch 27, 2026Vulnerability / Artificial Intelligence Cybersecurity researchers have revealed three security vulnerabilities affecting LangChain and LangGraph. Successful exploitation could lead to the disclosure of filesystem data, environmental secrets, and conversation history. Both LangChain and LangGraph are open source frameworks used to build applications that leverage large-scale language models (LLMs). LangGraph is built on […]
China-linked Red Mensheng uses stealth BPF door implant to spy via communications network

A long-term, ongoing campaign attributed to threat actors linked to China has integrated communications networks to conduct espionage against government networks. This strategic location effort to embed and maintain stealth access mechanisms within critical environments is believed to be the work of Red Menshen, a threat cluster also tracked as Earth Bluecrow, DecisiveArchitect, and Red […]
Flaw in Claude extension enabled zero-click XSS prompt injection via arbitrary websites

Ravi LakshmananMarch 26, 2026Browser security/vulnerabilities Cybersecurity researchers have revealed a vulnerability in Anthropic’s Claude Google Chrome extension that could be exploited to display a malicious prompt simply by visiting a web page. The flaw “allowed any website to silently insert a prompt into its assistant, as if the user had written the prompt,” Koi Security […]
How hackers and art forgers perfected the art of deception

Unmasking fraudsters is a challenge the art world has faced for decades, and Ermil de Holy’s work offers valuable lessons that can be applied to the world of defensive cybersecurity. In the 1960s, de Hory gained notoriety as a leading forger, passing masterpiece forgeries by Picasso, Matisse, and Renoir to unsuspecting collectors and prestigious museums. […]
PQC Push, AI Vuln Hunting, Pirated Traps, Phishing Kits & 20 More Stories

Ravie LakshmananMar 26, 2026Cybersecurity / Hacking News Some weeks in security feel loud. This one feels sneaky. Less big dramatic fireworks, more of that slow creeping sense that too many people are getting way too comfortable abusing things they probably shouldn’t even be touching. There’s a little bit of everything in this one, too. Weird […]