Coruna iOS Kit reuses 2023 Triangulation exploit code in new mass attack

Ravi LakshmananMarch 26, 2026Malware/Mobile Security New findings from Kaspersky Lab show that the recently discovered kernel exploits for two security vulnerabilities used in the Apple iOS exploit kit Coruna are updated versions of the same exploits used in the 2023 Operation Triangulation campaign. “When Coruna was first reported, the publicly available evidence was not enough […]
[Webinar] Stop guessing. Learn how to test your defenses against real attacks

hacker newsMarch 26, 2026Security testing/security automation Most teams have security tools in place. Alerts are firing, dashboards are looking clean, and threat information is flowing in. On the surface, everything feels like it’s under control. But there’s one question that usually doesn’t have an answer. The question is, can your defense actually stop an actual […]
WebRTC Skimmer bypasses CSP and steals payment data from e-commerce sites

Ravi LakshmananMarch 26, 2026Malware/Web Security Cybersecurity researchers have discovered a new payment skimmer that uses WebRTC data channels as a means to receive payloads and leak data, effectively bypassing security controls. “Instead of regular HTTP requests or image beacons, this malware uses WebRTC data channels to load its payload and exfiltrate stolen payment data,” Sansec […]
LeakBase administrator arrested in Russia over massively stolen credentials marketplace

Ravi LakshmananMarch 25, 2026Cybercrime/Dark Web The alleged administrator of the cybercrime forum Leakbase has been arrested by Russian law enforcement authorities, state media reported on Thursday. According to TASS news agency and MVD Media, a news website affiliated with Russia’s Ministry of Internal Affairs, the suspect is a resident of the city of Taganrog. The […]
GlassWorm malware uses Solana Dead Drops to deliver RAT and steal browser and encrypted data

Ravi LakshmananMarch 25, 2026Browser security/threat intelligence Cybersecurity researchers have warned of a new evolution in the GlassWorm campaign. The campaign provides a multi-stage framework capable of comprehensive data theft and installation of a remote access trojan (RAT) that deploys an information-stealing Google Chrome extension disguised as an offline version of Google Docs. “It logs keystrokes, […]
When AI agents are a threat, kill chains become obsolete

In September 2025, Anthropic revealed that state-sponsored threat actors used AI-coding agents to conduct autonomous cyber espionage against 30 targets around the world. The AI handled 80-90% of tactical operations on its own, performing reconnaissance, writing exploit code, and attempting lateral movement at machine speeds. While this incident is alarming, there are scenarios that should […]
Russian hacker sentenced to two years in prison for ransomware attack led by TA551 botnet

hacker newsMarch 25, 2026Cybercrime/Ransomware The US Department of Justice (DoJ) announced that a Russian national has been sentenced to two years in prison for managing a botnet used to launch ransomware attacks against US companies. Ilya Angelov, 40, of Tolyatchi, Russia, was also fined $100,000. Angelov, who operated under the online aliases Milano and Occult, […]
Device code phishing attacks 340+ Microsoft 365 organizations in 5 countries using OAuth exploitation

Cybersecurity researchers are calling attention to an active device code phishing campaign targeting Microsoft 365 IDs across more than 340 organizations in the United States, Canada, Australia, New Zealand, and Germany. According to Huntress, this activity was first discovered on February 19, 2026, and subsequent cases have been occurring at an accelerated pace since then. […]
FCC bans new foreign-made routers over supply chain and cyber risk concerns

Ravi LakshmananMarch 25, 2026Network security/data protection The Federal Communications Commission (FCC) announced Monday that it is banning the import of new foreign-made consumer routers, citing “unacceptable” risks to cyber and national security. FCC Chairman Brendan Carr said in a post on The development means new models of foreign-made routers will no longer be eligible for […]
TeamPCP backdoor LiteLLM versions 1.82.7 to 1.82.8 Likely due to Trivy CI/CD compromise

TeamPCP, the threat actor behind the recent Trivy and KICS breaches, compromised a popular Python package named litellm and pushed two malicious versions containing a credential harvester, a Kubernetes lateral movement toolkit, and a persistent backdoor. Multiple security vendors, including Endor Labs and JFrog, revealed that litellm versions 1.82.7 and 1.82.8 were released on March […]