The alleged administrator of the LeakBase cybercrime forum has been arrested by Russian law enforcement authorities, state media reported Thursday. According to TASS and MVD Media, a news website linked to the Russian Interior Ministry, the suspect is a resident of the city of Taganrog. The suspect is said to have been detained for creating … Read More “LeakBase Admin Arrested in Russia Over Massive Stolen Credential Marketplace – The Hacker News” »
UK organisations encouraged to take immediate action to mitigate two recently disclosed vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway. – Read More – All Feed
How AI Translation Fixes Multilingual Content Chaos – Hackread – Cybersecurity News, Data Breaches, AI and More
AI translation fixes multilingual content chaos by improving consistency, workflows, and speed, helping teams reduce errors and scale global content faster. – Read More – Hackread – Cybersecurity News, Data Breaches, AI and More
Best Klaviyo Alternatives for Revenue Growth and Advanced Analytics – Hackread – Cybersecurity News, Data Breaches, AI and More
Top Klaviyo alternatives offer advanced analytics, automation, and insights to help e-commerce brands improve campaigns, boost revenue, and track performance. – Read More – Hackread – Cybersecurity News, Data Breaches, AI and More
Cybersecurity company’s annual report issues warning over a “mass-marketed impersonation crisis” over attackers abusing legitimate credentials – Read More –
Cloud Android phones fuel financial fraud, evading detection and enabling dropper accounts – Read More –
GlassWorm Malware Uses Solana Dead Drops to Deliver RAT and Steal Browser, Crypto Data – The Hacker News
Cybersecurity researchers have flagged a new evolution of the GlassWorm campaign that delivers a multi-stage framework capable of comprehensive data theft and installing a remote access trojan (RAT), which deploys an information-stealing Google Chrome extension masquerading as an offline version of Google Docs. “It logs keystrokes, dumps cookies and session tokens, captures screenshots, and – … Read More “GlassWorm Malware Uses Solana Dead Drops to Deliver RAT and Steal Browser, Crypto Data – The Hacker News” »
2026 Cybersecurity Excellence Awards Winners Announced during RSA Conference as AI Security Dominates – Hackread – Cybersecurity News, Data Breaches, AI and More
San Francisco, USA, 25th March 2026, CyberNewswire – Read More – Hackread – Cybersecurity News, Data Breaches, AI and More
Fake OpenClaw Token Giveaway Targets GitHub Devs with Wallet-Draining Scam – Hackread – Cybersecurity News, Data Breaches, AI and More
OX Security reveals a new phishing campaign targeting GitHub developers. Scammers use fake OpenClaw token giveaways to trick users into connecting and draining their crypto wallets – Read More – Hackread – Cybersecurity News, Data Breaches, AI and More
Device Code Phishing Hits 340+ Microsoft 365 Orgs Across Five Countries via OAuth Abuse – The Hacker News
Cybersecurity researchers are calling attention to an active device code phishing campaign that’s targeting Microsoft 365 identities across more than 340 organizations in the U.S., Canada, Australia, New Zealand, and Germany. The activity, per Huntress, was first spotted on February 19, 2026, with subsequent cases appearing at an accelerated pace since then. Notably, the campaign … Read More “Device Code Phishing Hits 340+ Microsoft 365 Orgs Across Five Countries via OAuth Abuse – The Hacker News” »
The U.S. Department of Justice (DoJ) said a Russian national has been sentenced to two years in prison for managing a botnet that was used to launch ransomware attacks against U.S. companies. Ilya Angelov, 40, of Tolyatti, Russia, was also fined $100,000. Angelov, who went by the online aliases “milan” and “okart,” is said to … Read More “Russian Hacker Sentenced to 2 Years for TA551 Botnet-Driven Ransomware Attacks – The Hacker News” »
In September 2025, Anthropic disclosed that a state-sponsored threat actor used an AI coding agent to execute an autonomous cyber espionage campaign against 30 global targets. The AI handled 80-90% of tactical operations on its own, performing reconnaissance, writing exploit code, and attempting lateral movement at machine speed. This incident is worrying, but there’s a … Read More “The Kill Chain Is Obsolete When Your AI Agent Is the Threat – The Hacker News” »
The US Federal Communications Commission has placed all “consumer-grade” internet routers produced outside the US on its “covered list” – Read More –
TeamPCP, the threat actor behind the recent compromises of Trivy and KICS, has now compromised a popular Python package named litellm, pushing two malicious versions containing a credential harvester, a Kubernetes lateral movement toolkit, and a persistent backdoor. Multiple security vendors, including Endor Labs and JFrog, revealed that litellm versions 1.82.7 and 1.82.8 were published … Read More “TeamPCP Backdoors LiteLLM Versions 1.82.7–1.82.8 via Trivy CI/CD Compromise – The Hacker News” »
TeamPCP Hits Trivy, Checkmarx, and LiteLLM in Credential Theft Campaign – Hackread – Cybersecurity News, Data Breaches, AI and More
Hackers compromised Trivy, Checkmarx, and LiteLLM in a supply chain attack, stealing cloud credentials, tokens, and crypto wallet data from developers. – Read More – Hackread – Cybersecurity News, Data Breaches, AI and More
Python package LiteLLM compromised with credential-stealing malware linked to TeamPCP threat group – Read More –
A man has pleaded guilty to defrauding online music streaming platforms out of more than US $8 million, after creating hundreds of thousands of songs with AI, and then using bots to play them billions of times. Read more in my article on the Hot for Security blog. – Read More – GRAHAM CLULEY
Expel has warned of malicious Chrome extensions stealing users’ AI conversations – Read More –
UK police trumpet success of Operation Henhouse as they seize and freeze over £27m in suspected fraud proceeds – Read More –
The U.S. Federal Communications Commission (FCC) said on Monday that it was banning the import of new, foreign-made consumer routers, citing “unacceptable” risks to cyber and national security. The action was designed to safeguard Americans and the underlying communications networks the country relies on, FCC Chairman Brendan Carr said in a post on X. The … Read More “FCC Bans New Foreign-Made Routers Over Supply Chain and Cyber Risk Concerns – The Hacker News” »
HackerOne, Mazda, Infinite Campus and Dutch Ministry Hit by Data Breaches – Hackread – Cybersecurity News, Data Breaches, AI and More
HackerOne, Mazda, Infinite Campus and the Dutch Ministry report data breaches, exposing employee and partner data across multiple sectors worldwide. – Read More – Hackread – Cybersecurity News, Data Breaches, AI and More
Understanding Wiz’s Approach to Securing the AI Supply Chain – Hackread – Cybersecurity News, Data Breaches, AI and More
As organizations race to deploy AI, securing the rapidly expanding ecosystem of models, data, and dependencies has become a critical priority, much of which can be addressed by Wiz’s CNAPP solution. – Read More – Hackread – Cybersecurity News, Data Breaches, AI and More
DarkSword’s GitHub leak threatens to turn elite iPhone hacking into a tool for the masses – CyberScoop
Leaked iOS spyware has some cybersecurity professionals raising urgent alarms about potential mass iPhone compromises, a development that pairs ominously with the recent discovery of two sophisticated iOS exploit kits. At the same time, some other experts say Apple’s defensive features for iPhones remain elite. But several factors have created unprecedented circumstances: the public accessibility … Read More “DarkSword’s GitHub leak threatens to turn elite iPhone hacking into a tool for the masses – CyberScoop” »
Dr Richard Horne delivered a keynote about cyber risks and opportunities at the RSAC Conference in San Francisco – Read More – All Feed
If ‘vibe coding’ disrupts the software market like SaaS did 20 years ago, what does this mean for cyber security? – Read More – All Feed
The head of the UK’s NCSC is calling the cybersecurity industry to “seize the disruptive vibe coding opportunity” to make software more secure – Read More –
OVHcloud Founder Denies Massive 590TB Data Breach Claims – Hackread – Cybersecurity News, Data Breaches, AI and More
OVHcloud denies breach after hacker claims 600TB data theft affecting millions of sites, with experts doubting authenticity due to weak proof – Read More – Hackread – Cybersecurity News, Data Breaches, AI and More
All AI and Security Teams Need Transparent Data Pipelines – Hackread – Cybersecurity News, Data Breaches, AI and More
Transparent AI data pipelines help organizations verify sources, reduce errors, meet regulations, and build trust by making outputs auditable and reliable. – Read More – Hackread – Cybersecurity News, Data Breaches, AI and More
OVHcloud denies breach after hacker claims 600TB data theft affecting millions of sites, with experts doubting authenticity due to weak proof – Read More – Hackread – Cybersecurity News, Data Breaches, AI and More
A large-scale malvertising campaign active since January 2026 has been observed targeting U.S.-based individuals searching for tax-related documents to serve rogue installers for ConnectWise ScreenConnect that drop a tool named HwAudKiller to blind security programs using the bring your own vulnerable driver (BYOVD) technique. “The campaign abuses Google Ads to serve rogue ScreenConnect ( – … Read More “Tax Search Ads Deliver ScreenConnect Malware Using Huawei Driver to Disable EDR – The Hacker News” »
SAN FRANCISCO — Mandiant is responding to a major, ongoing supply-chain attack involving the compromise of Trivy, a widely used open-source tool from Aqua Security that’s designed to find vulnerabilities and misconfigurations in code repositories. The fallout from the attack spree, which was first detected March 19, is extensive and poses substantial risk for follow-on … Read More “Experts warn of a ‘loud and aggressive’ extortion wave following Trivy hack – CyberScoop” »
FBI Warns of Iran’s Handala Hack Group Using Fake Apps to Spy on Windows Users – Hackread – Cybersecurity News, Data Breaches, AI and More
The FBI has issued a warning about Iran-linked Handala Hack Group, targeting Windows users through fake versions of WhatsApp and Telegram. – Read More – Hackread – Cybersecurity News, Data Breaches, AI and More
An ongoing phishing campaign is targeting French-speaking corporate environments with fake resumes that lead to the deployment of cryptocurrency miners and information stealers. “The campaign uses highly obfuscated VBScript files disguised as resume/CV documents, delivered through phishing emails,” Securonix researchers Shikha Sangwan, Akshay Gaikwad, and Aaron Beardslee said in a report shared – Read More … Read More “Hackers Use Fake Resumes to Steal Enterprise Credentials and Deploy Crypto Miner – The Hacker News” »
Critics call FCC router rule a ‘big swing’ that could create more supply chain uncertainty – CyberScoop
The Federal Communications Commission’s move to ban foreign-made routers touches on a real threat, but critics say the agency rule is overly broad, practically unworkable and doesn’t meaningfully address weaknesses in router security that have led to major breaches on American governments and businesses. Under the Secure Equipment Act and Secure Networks Act, the FCC … Read More “Critics call FCC router rule a ‘big swing’ that could create more supply chain uncertainty – CyberScoop” »
Silver Fox pivots from ValleyRAT tax lures to WhatsApp‑style stealers, blending espionage & phishing – Read More –
The Treasury Department is soliciting public feedback on whether it should change a terrorism risk insurance program to address cyber-related losses. In a Federal Register notice set for publication Wednesday, Treasury seeks comment from the public for a mandatory report it must deliver to Congress this summer on the effectiveness of the terrorism risk insurance … Read More “Treasury asks whether terrorism risk insurance program should bolster cyber coverage – CyberScoop” »
A critical vulnerability in Citrix’s NetScaler products allows unauthenticated remote attackers to leak information from the appliance’s memory – Read More –
A federal court in Indiana sentenced a Russian cybercriminal to 81 months in prison on charges related to his role as an initial access broker for ransomware groups. Aleksei Volkov, 26, of St. Petersburg, Russia, pleaded guilty in November 2025 to six federal charges stemming from his work with the Yanluowang ransomware group and other … Read More “Russian access broker sentenced to over 6 years in prison for ransomware schemes – CyberScoop” »
Former Ukrainian Foreign Minister Dmytro Kuleba to Address the New Cyber Frontline at Infosecurity Europe –
Geopolitics and cyber warfare take center stage at Infosecurity Europe as Dmytro Kuleba discusses Ukraine’s hybrid war experience – Read More –
Ghost npm campaign fakes install logs to steal sudo passwords and drop RATs that loot crypto and data – Read More –
DarkSword iPhone Exploit Leaked Online, Hundreds of Millions at Risk – Hackread – Cybersecurity News, Data Breaches, AI and More
DarkSword exploit leak puts up to 270 million iPhones at risk, with hackers able to access data through… – Read More – Hackread – Cybersecurity News, Data Breaches, AI and More
Poor patch management, increasingly complex IT environments and continued use of obsolete software puts organizations at risk from cyber threats, says the Absolute Security 2026 Resilience Risk Index – Read More –
On February 25, 2026, Gartner published its inaugural Market Guide for Guardian Agents, marking an important milestone for this emerging category. For those unfamiliar with the various Gartner report types, “a Market Guide defines a market and explains what clients can expect it to do in the short term. With the focus on early, more … Read More “5 Learnings from the First-Ever Gartner Market Guide for Guardian Agents – The Hacker News” »
Cybersecurity researchers have uncovered a new set of malicious npm packages that are designed to steal cryptocurrency wallets and sensitive data. The activity is being tracked by ReversingLabs as the Ghost campaign. The list of identified packages, all published by a user named mikilanjillo, is below – react-performance-suite react-state-optimizer-core react-fast-utilsa ai-fast-auto-trader – Read More – … Read More “Ghost Campaign Uses 7 npm Packages to Steal Crypto Wallets and Credentials – The Hacker News” »
Two more GitHub Actions workflows have become the latest to be compromised by credential-stealing malware by a threat actor known as TeamPCP, the cloud-native cybercriminal operation also behind the Trivy supply chain attack. The workflows, both maintained by the supply chain security company Checkmarx, are listed below – checkmarx/ast-github-action checkmarx/kics-github-action Cloud security – Read More … Read More “TeamPCP Hacks Checkmarx GitHub Actions Using Stolen CI Credentials – The Hacker News” »
Cybersecurity has changed fast. Roles are more specialized, and tooling is more advanced. On paper, this should make organizations more secure. But in practice, many teams struggle with the same basic problems they faced years ago: unclear risk priorities, misaligned tooling decisions, and difficulty explaining security issues in terms the business understands. These challenges do not … Read More “The Hidden Cost of Cybersecurity Specialization: Losing Foundational Skills – The Hacker News” »
Russian cybercriminal Aleksei Volkov has received close to seven years behind bars for role in Yanluowang ransomware – Read More –
The FBI has warned that Iranian hacking group Handala has been targeting opponents of the regime since 2023 – Read More –
The FBI has warned that Iranian hacking group Handala has been targeting opponents of the regime since 2023 – Read More –
Gcore Radar report reveals 150% surge in DDoS attacks year-on-year – Hackread – Cybersecurity News, Data Breaches, AI and More
Luxembourg, Luxembourg, 24th March 2026, CyberNewswire – Read More – Hackread – Cybersecurity News, Data Breaches, AI and More




