It’s yet another week proving the internet remains insecure. Systems assumed to be safe are easily compromised, highlighting a continued disregard for essential security advice.
This update includes a range of issues: attacks on software supply chains targeting CI/CD systems, the takedown of long-exploited IoT devices, and rapid weaponization of newly disclosed vulnerabilities. Additionally, clever new malware tactics reveal attackers’ increasing patience and ingenuity.
We’re seeing a mix of recurring, unresolved problems and emerging, harder-to-spot methods. These include covert nation-state operations, data breaches from unsecured directories, growing mobile threats, and a constant stream of zero-day exploits and quickly issued patches.
Grab some coffee and quickly review the CVE list. You don’t want to learn about some of these *after* an incident.
Supply Chain Attack Hits Trivy Vulnerability Scanner — Attackers compromised the popular open-source Trivy scanner by inserting a backdoor that steals credentials. This malware was included in official releases and GitHub Actions used in thousands of CI/CD workflows. This breach led to further supply chain issues as affected projects and organizations failed to rotate secrets, distributing a self-replicating worm called CanisterWorm. Aqua Security’s Trivy is a widely used scanner, boasting over 32,000 GitHub stars and over 100 million Docker Hub downloads. This incident joins a trend of attacks focused on GitHub Actions and developers. GitHub has modified pull_request_target workflows by default in December 2025 to enhance security.
- DoJ Dismantles DDoS Botnets — A group of IoT botnets responsible for some of the largest DDoS attacks on recordâAISURU, Kimwolf, JackSkid, and Mossadâwere taken offline in a law enforcement operation. These botnets commonly spread through routers, IP cameras, and digital video recorders with weak default credentials and infrequent patching. Authorities took control of the command servers used to manage the infected devices. The four botnets collectively controlled over 3 million devices, access to which was sold to cybercriminals for DDoS attacks, disrupting websites and masking other malicious activities. Some of these attacks targeted U.S. Department of Defense systems and other sensitive targets. While no arrests were made, two suspects involved with AISURU/Kimwolf are believed to be in Canada and Germany. These botnets are based on Mirai, whose source code was leaked in 2016 and served as a base for other botnets. According to the U.S. Justice Department, victims of these DDoS attacks incurred hundreds of thousands of dollars in recovery costs or paid ransoms to stop the attacks.
- Google Improves Android Sideloading Security — Google’s updated Android sideloading process for apps from unverified developers now introduces more steps to reduce fraud and malware. Designed for advanced users, the new process includes a one-time setup followed by a 24-hour delay and more verification. This added friction is meant to prevent attackers from coercing targets into installing unsafe software by creating a sense of urgency that bypasses security warnings.
- Critical Langflow Vulnerability Actively Exploited — A critical flaw in Langflow was quickly exploited within 20 hours of its public disclosure, highlighting how rapidly hackers capitalize on new vulnerabilities. The flaw, denoted as CVE-2026-33017 (CVSS score: 9.3), involves missing authentication combined with code injection, potentially allowing remote code execution. Cloud security firm Sysdig noted the vulnerability is being used to steal sensitive information from compromised systems. Aviral Srivastava, who discovered the vulnerability, told The Hacker News that attackers crafted working exploits from the advisory description alone, indicating its ease of exploitation.”
- Interlock Ransomware Exploited Cisco FMC Flaw as Zero-Day — An Interlock ransomware campaign exploited a critical vulnerability in Cisco Secure Firewall Management Center (FMC) Software as a zero-day for more than a month before its public disclosure. The flaw, CVE-2026-20131 (CVSS score: 10.0), involved insecure deserialization of Java byte streams, potentially allowing remote unauthenticated attackers to bypass authentication and execute arbitrary Java code as root. Amazon, which detected the activity, commented that this zero-day gave Interlock a one-week head start in compromising organizations before defenders were even aware of the threat.
- New iOS Exploit Kit, DarkSword, Discovered — A “watering hole” attack targeting iPhone users used a new iOS exploit kit called DarkSword. Some attacks targeted users in Ukraine, while others focused on users in Saudi Arabia, Turkey, and Malaysia since November 2025. These exploits are ineffective on devices with Lockdown Mode or the iPhone 17 with Memory Integrity Enforcement (MIE) enabled. The kit employed six separate iOS exploits to deliver malware for surveillance and intelligence gathering. Apple has since patched these vulnerabilities. The security firm iVerify notes that DarkSword is entirely JavaScript-based, utilizing vulnerabilities to secure complete iPhone control. This makes DarkSword the second mass attack targeting iOS devices. The Russian threat actor behind DarkSword exhibited poor operational security, leaving the JavaScript code unobfuscated and easily accessible which points to a market where exploits are bought by diverse threat actors to infect unpatched iOS users on a large scale.
- Perseus Banking Malware Targets Android Users — A new Android malware disguised as a TV streaming app steals passwords and banking information and spies on personal notes. Researchers at ThreatFabric named the malware Perseus, which has been actively targeting users in Turkey and Italy. To infect devices, attackers embed the malware in apps that appear to offer IPTV services which has made user accustomed to installing these apps manually and less likely to view the installing process as suspicious. Once installed, Perseus monitors nearly everything a user does in real time using overlays and keylogging to steal credentials. The malware specifically targets note-taking apps, because they often contain sensitive information like passwords, financial details, or private thoughts.
New vulnerabilities are uncovered regularly, and the time between disclosure and active exploitation is shrinking. The following flaws are the most critical ones this week due to their high severity, widespread use, or attention from the security community.
Check these first, apply any needed fixes, and prioritize those marked urgentâCVE-2026-21992 (Oracle), CVE-2026-33017 (Langflow), CVE-2026-32746 (GNU InetUtils telnetd), CVE-2026-32297, CVE-2026-32298 (Angeet ES3 KVM), CVE-2026-3888 (Ubuntu), CVE-2026-20643 (Apple WebKit), CVE-2026-4276 (LibreChat RAG API), CVE-2026-24291 aka RegPwn (Microsoft Windows), CVE-2026-21643 (Fortinet FortiClient), CVE-2026-3864 (Kubernetes), CVE-2026-32635 (Angular), CVE-2026-25769 (Wazuh), CVE-2026-3564 (ConnectWise ScreenConnect), CVE-2026-22557, CVE-2026-22558 (Ubiquiti), CVE-2025-14986 (Temporal), CVE-2026-31381, CVE-2026-31382 (Gainsight Assist), CVE-2026-26189 (Trivy), CVE-2026-4439, CVE-2026-4440, CVE-2026-4441 (Google Chrome), CVE-2026-33001, CVE-2026-33002 (Jenkins), CVE-2026-21570 (Atlassian Bamboo Center), and CVE-2026-21884 (Atlassian Crowd Data Center).
ð¥ Cybersecurity Webinars
- Automate Exposure Management with OpenCTI & OpenAEV → Learn how to automate frequent, threat-conscious testing using open-source tools like OpenCTI and OpenAEV to confirm your security controls against real attacker activity, all while staying within your current budget. View a live demo of verifying your security setup, identifying weak spots, and implementing free integration into your SOC workflow.
- Identity Maturity in 2026: New Data + How to Catch Up → Identity programs are stretched thin in 2026, with disparate apps, AI agents, and credential sprawl causing risks and audit problems. Join this webinar for new 2026 Ponemon Institute research based on insights from 600 experts, revealing the size of the problem and practical steps to address gaps, ease friction, and rapidly modernize your security practices.
- WhatsApp to Trial Usernames Instead of Phone Numbers — WhatsApp plans to implement usernames and unique IDs instead of using phone numbers, allowing messaging and calls to happen without sharing phone numbers. The planned privacy feature is slated for global release by June 2026, enabling individuals and businesses to secure unique identifiers. According to a statement shared with The Economic Times, the change will help people connect with new contacts without needing to disclose phone numbers. Testing of the feature started in early January 2026. Signal launched a similar feature in early 2024.
- FBI Provides Details on SE Asia Scam Centers — The FBI shared details on its collaboration with Thai authorities to dismantle fraudulent call centers prevalent across Southeast Asia. These schemes, which frequently target retirees, small business owners, and individuals seeking relationships, involve cyber fraud, money laundering, and human trafficking, leading to yearly losses of billions of dollars. These scam operations run much like legitimate companies. The FBI explains that workers are lured overseas with promises of high-paying jobs, only to find that the jobs don’t exist, passports are taken, and armed guards secure the facilities. Victims face violence if they refuse to pose as romantic partners or financial advisors to gain the trust of victims. While recent operations in countries have rescued thousands of workers from scam compounds, the FBI cautions that these wins may be temporary, with criminal networks adapting by relocating, rebranding, or changing their methods in response.
- APT28 Server Leak Exposes SquirrelMail XSS Payload — An exposed open directory discovered on a server (“203.161.50[.]145“) linked to APT28 (aka Fancy Bear) revealed insight into espionage against government and military entities in countries, including Ukraine, Romania, Bulgaria, Greece, Serbia, and North Macedonia. Ctrl-Alt-Intel reports the directory contained command-and-control (C2) source code, scripts to exfiltrate emails, credentials, and 2FA tokens from Roundcube mailboxes, telemetry logs, and stolen data. The leaked information consisted of 2,870 emails, 244 sets of credentials, 143 Sieve forwarding rules, and 11,527 email addresses. Key among these tools existed an XSS payload directed at SquirrelMail, which highlights the hackers’ ongoing efforts to leverage vulnerabilities in email to extract information. It’s noteworthy that the Computer Emergency Response Team of Ukraine (CERT-UA) previously identified server as linked to APT28 back in September 2024. Ctrl-Alt-Intel explains that Fancy Bear devised a modular system so that merely viewing a malicious email (without needing further interaction) enables credential theft, 2FA bypass, email information extraction, and adding a lasting forwarding rule.”
- Analysis of Beast Ransomware Server — An analysis of an open directory residing at “5.78.84[.]144”, correlated to Beast (a suspected ransomware-as-a-service (RaaS) successor to Monster), investigated tools used by the threat actors and their attack sequences. The identified programs included Advanced IP Scanner and Advanced Port Scanner for identifying internal resources and open remote desktop (RDP) or server message block (SMB) ports, programs to find sensitive files for exfiltration and prioritize valuable servers, Mimikatz, LaZagne, and Automim for harvesting credentials, AnyDesk for establishing persistence, PsExec for lateral movement, and MEGASync for exfiltration. Beast’s operations paused in November 2025 before resuming in January 2026.
- GrapheneOS Disputes Unified Attestation Initiative — GrapheneOS strongly opposes the Unified Attestation approach arguing the technology “serves no use beyond giving the technology’s developers an imbalanced advantage while portraying it as a contribution to security”. Unified Attestation represents an open-source, decentralized stand-in for the Google Play Integrity API to manage device and app integrity checks for custom ROMs without Google Play Services. GrapheneOS advises developers who prioritize privacy, security, and freedom to avoid supporting the Unified Attestation methods. They contend that phone vendors shouldn’t dictate what operating systems end-users are permitted to have installed for apps.
- VoidStealer Employs Chrome Debugger to Access Secrets — The VoidStealer information stealer leverages a novel technique using the debugger (noted as Application-Bound Encryption or ABE) to access the “v20_master_key” from browser memory via hardware breakpoints, using this key to decrypt cached user data. VoidStealer sells its theft-as-a-service on multiple dark web forums since December 2025. The announced debugger bypass was incorporated into version 2.0 of the stealer on March 13. Gen Digital explains that the hack involves neither privilege escalations nor code injection, making the approach more difficult to quickly identify than prior methods. VoidStealer likely learned from the open-source project called ElevationKatz.
- FBI Admits Purchasing U.S. Location Data — FBI director Kash Patel acknowledged that the agency buys location data to track individuals without needing a warrant. Patel stated to the Senate Intelligence Committee that the agency leverages commercially available information, consistent with the Constitution and Electronic Communications Privacy Act, which has enabled valuable intelligence for the agency.
- Iranian Botnet Exposed via Open Directory — The “185.221.239[.]162:8080” Open Directory revealed many payloads, including a Python botnet script, a compiled DDoS tool, several C-language denial-of-service files, plus accessible SSH credentials. Credential extraction for this Python script (ohhhh.py) reads data in the specific host:port|username|password method and opens 500 concurrent SSH sessions, automatically compiling and launching the client on each host, according to Hunt.io reports. The .bash_history highlighted three distinct phases: initial tunnel set up, creating and testing custom DDoS tools against live targets, and continually refining the botnet through continual script revisions. This activity is not directly connected to government-directed activity.
- OpenClaw Developers Targeted in Phishing Scheme — Given OpenClaw’s flexibility, decentralized model, and burgeoning ecosystem, it quickly became popular among software developers. That rapid adoption (which has given rise to its own concerns due to the existence of vulnerabilities and some potentially harmful skills on ClawHub and SkillsMP) gave cybercriminal organizations a new reason to use the brand name to design fake GitHub accounts who then promise free $CLAW tokens to lure developers into connecting their cryptocurrency wallets. According to OX Security’s researchers Moshe Siman Tov Bustan and Nir Zadok, the attackers operate fake GitHub accounts to initiate discussions in attacker-controlled repositories and tag numerous GitHub developers. The posts explain that targets have been granted $5,000 worth of CLAW tokens which may be claimed by visiting a webpage, “token-claw[.]xyz”, to connect to their wallet. The deceptive webpage closely resembles an OpenClaw product rigged with a wallet drainer to execute cryptocurrency theft.
- Energy Personnel in Pakistan Face New Campaign — A targeted attack on employees at Pakistani energy firms is delivered through phishing emails mimicking upcoming invites to an upcoming trade conference. These messages originate from compromised organizations tied to Pakistani universities or other government groups and attempt to trick targets into enabling PDF attachments that promise Adobe Acrobat Reader updates. Allowing Acrobat Reader grants access to a ClickOnce application and drops a Havoc Demon C2 framework. This delivery chain implemented both geofencing and browser fingerprinting to constrain impact towards specific individuals, according to a Proofpoint report. The activity (dubbed UNK_VaporVibes) is correlated activity to SloppyLemming.
- Over 373K Dark Web Sites Taken Down — International law enforcement branches announced a large takedown that shuttered hundreds of thousands of scam pages that victims used to find child sexual abuse content. A 10-day period targeting that involved German authorities and supported by Europol took down more than 373,000 dark web pages run by (as of 2021) a Chinese citizen. These fraudulent websites advertised child abuse and offered resources for cybercrime assistance, but actually delivered nothing after Bitcoin payments. With this pattern, the operation produced an estimated €345,000 from nearly 10,000 people across 23 countries. Investigators are now actively looking into 440 purchasers across 23 countries.
- Malicious npm Packages Facilitate Secret Theft — Two packages found on the npm directory, sbx-mask and touch-adv, have taken information from victims’ machines via malicious code in their postinstall scripts or during execution after developer importing. This is likely due to an account takeover that did not rely on malicious coding. Sonatype argues that hijacked publisher accounts are problematic since maintainers over years of work had established trusting relationships with users. Attackers are attempting to use these existing relationships to access personal data from impacted machines.
- China to Standardize Post-Quantum Cryptography in Next 3 Years — A report from Reuters claims China hopes to standardize and establish unique post-quantum cryptography within the next 3 years. The U.S. completed similar work in developing its standards in 2024 and plans to adopt industry-wide migrations to the new pattern by 2035.
- The Future of Tycoon2FA — Recent law enforcement actions crippled the infrastructure of the Tycoon2FA phishing platform. Researchers believe some sites are still live which may indicate that operations are continuing on compromised and SaaS platforms. These sites can also transition to new platforms if the infrastructure is rebuilt. Bridewell believes that CAPTCHA websites may belong to secondary networks that look to continue old campaigns.
- MESH → This BARGHEST open-source utility offers remote mobile forensics monitoring over encrypted censorship-resistant peer-to-peer networks. MESH connects devices that use wireless ADB or libimobiledevice. This tool also uses PCAP capture and Suricata IDS technologies.
- enject → This lightweight tool from Rust protects secrets from AI assistants like Copilot. The utility replaces values with placeholders that have encrypted states. The encrypted data stays behind project stores. When enject run decrypts the data in memory, enject also removes plaintext.
Disclaimer: This information is only for educational use. This code has not received audits, so examine any code before executing.
That’s the highlight for security this week. The overall challenge highlighted has roots in the lag, lag from identifying problems through implementation and lack of awareness. Most of the problems that came to fore this week happened in this gap, which is not a new issue.
Consider updating mobile devices or anything tied to development pipelines, and also don’t place keys into notes apps.