Google is accelerating its timeline for migrating its products to quantum resistant encryption to 2029, the latest sign that tech leaders are worried that they haven’t been aggressive enough in planning for a post-quantum future. In a blog posted Wednesday, vice president of security engineering Heather Adkins and senior staff cryptology engineer Sophie Schmieg said … Read More “Google moves post-quantum encryption timeline up to 2029 – CyberScoop” »
Category: Attack Feeds
An operation to crack down on the widely used RedLine infostealer has netted the extradition of an Armenian man to the United States, where he made an initial appearance in a Texas court Wednesday. Authorities charged Hambardzum Minasyan with conspiracy to commit access device fraud, conspiracy to violate the Computer Fraud and Abuse Act and … Read More “Alleged RedLine infostealer conspirator extradited to US – CyberScoop” »
Mirai Malware Evolves into Hundreds of Variants Driving Botnet Growth – Hackread – Cybersecurity News, Data Breaches, AI and More
Mirai malware evolves into hundreds of variants, driving botnet growth, including Aisuru and KimWolf, powering large-scale attacks, and increasing risks to vulnerable IoT devices worldwide. – Read More – Hackread – Cybersecurity News, Data Breaches, AI and More
US Bans New Foreign-Made Home Routers Over National Security Fears – Hackread – Cybersecurity News, Data Breaches, AI and More
The FCC has officially added foreign-made consumer routers to its restricted Covered List, citing major cybersecurity risks. Find out what it means for your current devices. – Read More – Hackread – Cybersecurity News, Data Breaches, AI and More
The alleged administrator of the LeakBase cybercrime forum has been arrested by Russian law enforcement authorities, state media reported Thursday. According to TASS and MVD Media, a news website linked to the Russian Interior Ministry, the suspect is a resident of the city of Taganrog. The suspect is said to have been detained for creating … Read More “LeakBase Admin Arrested in Russia Over Massive Stolen Credential Marketplace – The Hacker News” »
How AI Translation Fixes Multilingual Content Chaos – Hackread – Cybersecurity News, Data Breaches, AI and More
AI translation fixes multilingual content chaos by improving consistency, workflows, and speed, helping teams reduce errors and scale global content faster. – Read More – Hackread – Cybersecurity News, Data Breaches, AI and More
Best Klaviyo Alternatives for Revenue Growth and Advanced Analytics – Hackread – Cybersecurity News, Data Breaches, AI and More
Top Klaviyo alternatives offer advanced analytics, automation, and insights to help e-commerce brands improve campaigns, boost revenue, and track performance. – Read More – Hackread – Cybersecurity News, Data Breaches, AI and More
GlassWorm Malware Uses Solana Dead Drops to Deliver RAT and Steal Browser, Crypto Data – The Hacker News
Cybersecurity researchers have flagged a new evolution of the GlassWorm campaign that delivers a multi-stage framework capable of comprehensive data theft and installing a remote access trojan (RAT), which deploys an information-stealing Google Chrome extension masquerading as an offline version of Google Docs. “It logs keystrokes, dumps cookies and session tokens, captures screenshots, and – … Read More “GlassWorm Malware Uses Solana Dead Drops to Deliver RAT and Steal Browser, Crypto Data – The Hacker News” »
2026 Cybersecurity Excellence Awards Winners Announced during RSA Conference as AI Security Dominates – Hackread – Cybersecurity News, Data Breaches, AI and More
San Francisco, USA, 25th March 2026, CyberNewswire – Read More – Hackread – Cybersecurity News, Data Breaches, AI and More
Fake OpenClaw Token Giveaway Targets GitHub Devs with Wallet-Draining Scam – Hackread – Cybersecurity News, Data Breaches, AI and More
OX Security reveals a new phishing campaign targeting GitHub developers. Scammers use fake OpenClaw token giveaways to trick users into connecting and draining their crypto wallets – Read More – Hackread – Cybersecurity News, Data Breaches, AI and More
Device Code Phishing Hits 340+ Microsoft 365 Orgs Across Five Countries via OAuth Abuse – The Hacker News
Cybersecurity researchers are calling attention to an active device code phishing campaign that’s targeting Microsoft 365 identities across more than 340 organizations in the U.S., Canada, Australia, New Zealand, and Germany. The activity, per Huntress, was first spotted on February 19, 2026, with subsequent cases appearing at an accelerated pace since then. Notably, the campaign … Read More “Device Code Phishing Hits 340+ Microsoft 365 Orgs Across Five Countries via OAuth Abuse – The Hacker News” »
The U.S. Department of Justice (DoJ) said a Russian national has been sentenced to two years in prison for managing a botnet that was used to launch ransomware attacks against U.S. companies. Ilya Angelov, 40, of Tolyatti, Russia, was also fined $100,000. Angelov, who went by the online aliases “milan” and “okart,” is said to … Read More “Russian Hacker Sentenced to 2 Years for TA551 Botnet-Driven Ransomware Attacks – The Hacker News” »
In September 2025, Anthropic disclosed that a state-sponsored threat actor used an AI coding agent to execute an autonomous cyber espionage campaign against 30 global targets. The AI handled 80-90% of tactical operations on its own, performing reconnaissance, writing exploit code, and attempting lateral movement at machine speed. This incident is worrying, but there’s a … Read More “The Kill Chain Is Obsolete When Your AI Agent Is the Threat – The Hacker News” »
TeamPCP, the threat actor behind the recent compromises of Trivy and KICS, has now compromised a popular Python package named litellm, pushing two malicious versions containing a credential harvester, a Kubernetes lateral movement toolkit, and a persistent backdoor. Multiple security vendors, including Endor Labs and JFrog, revealed that litellm versions 1.82.7 and 1.82.8 were published … Read More “TeamPCP Backdoors LiteLLM Versions 1.82.7–1.82.8 via Trivy CI/CD Compromise – The Hacker News” »
TeamPCP Hits Trivy, Checkmarx, and LiteLLM in Credential Theft Campaign – Hackread – Cybersecurity News, Data Breaches, AI and More
Hackers compromised Trivy, Checkmarx, and LiteLLM in a supply chain attack, stealing cloud credentials, tokens, and crypto wallet data from developers. – Read More – Hackread – Cybersecurity News, Data Breaches, AI and More
A man has pleaded guilty to defrauding online music streaming platforms out of more than US $8 million, after creating hundreds of thousands of songs with AI, and then using bots to play them billions of times. Read more in my article on the Hot for Security blog. – Read More – GRAHAM CLULEY
The U.S. Federal Communications Commission (FCC) said on Monday that it was banning the import of new, foreign-made consumer routers, citing “unacceptable” risks to cyber and national security. The action was designed to safeguard Americans and the underlying communications networks the country relies on, FCC Chairman Brendan Carr said in a post on X. The … Read More “FCC Bans New Foreign-Made Routers Over Supply Chain and Cyber Risk Concerns – The Hacker News” »
HackerOne, Mazda, Infinite Campus and Dutch Ministry Hit by Data Breaches – Hackread – Cybersecurity News, Data Breaches, AI and More
HackerOne, Mazda, Infinite Campus and the Dutch Ministry report data breaches, exposing employee and partner data across multiple sectors worldwide. – Read More – Hackread – Cybersecurity News, Data Breaches, AI and More
Understanding Wiz’s Approach to Securing the AI Supply Chain – Hackread – Cybersecurity News, Data Breaches, AI and More
As organizations race to deploy AI, securing the rapidly expanding ecosystem of models, data, and dependencies has become a critical priority, much of which can be addressed by Wiz’s CNAPP solution. – Read More – Hackread – Cybersecurity News, Data Breaches, AI and More
DarkSword’s GitHub leak threatens to turn elite iPhone hacking into a tool for the masses – CyberScoop
Leaked iOS spyware has some cybersecurity professionals raising urgent alarms about potential mass iPhone compromises, a development that pairs ominously with the recent discovery of two sophisticated iOS exploit kits. At the same time, some other experts say Apple’s defensive features for iPhones remain elite. But several factors have created unprecedented circumstances: the public accessibility … Read More “DarkSword’s GitHub leak threatens to turn elite iPhone hacking into a tool for the masses – CyberScoop” »
OVHcloud Founder Denies Massive 590TB Data Breach Claims – Hackread – Cybersecurity News, Data Breaches, AI and More
OVHcloud denies breach after hacker claims 600TB data theft affecting millions of sites, with experts doubting authenticity due to weak proof – Read More – Hackread – Cybersecurity News, Data Breaches, AI and More
All AI and Security Teams Need Transparent Data Pipelines – Hackread – Cybersecurity News, Data Breaches, AI and More
Transparent AI data pipelines help organizations verify sources, reduce errors, meet regulations, and build trust by making outputs auditable and reliable. – Read More – Hackread – Cybersecurity News, Data Breaches, AI and More
OVHcloud denies breach after hacker claims 600TB data theft affecting millions of sites, with experts doubting authenticity due to weak proof – Read More – Hackread – Cybersecurity News, Data Breaches, AI and More
A large-scale malvertising campaign active since January 2026 has been observed targeting U.S.-based individuals searching for tax-related documents to serve rogue installers for ConnectWise ScreenConnect that drop a tool named HwAudKiller to blind security programs using the bring your own vulnerable driver (BYOVD) technique. “The campaign abuses Google Ads to serve rogue ScreenConnect ( – … Read More “Tax Search Ads Deliver ScreenConnect Malware Using Huawei Driver to Disable EDR – The Hacker News” »
SAN FRANCISCO — Mandiant is responding to a major, ongoing supply-chain attack involving the compromise of Trivy, a widely used open-source tool from Aqua Security that’s designed to find vulnerabilities and misconfigurations in code repositories. The fallout from the attack spree, which was first detected March 19, is extensive and poses substantial risk for follow-on … Read More “Experts warn of a ‘loud and aggressive’ extortion wave following Trivy hack – CyberScoop” »
FBI Warns of Iran’s Handala Hack Group Using Fake Apps to Spy on Windows Users – Hackread – Cybersecurity News, Data Breaches, AI and More
The FBI has issued a warning about Iran-linked Handala Hack Group, targeting Windows users through fake versions of WhatsApp and Telegram. – Read More – Hackread – Cybersecurity News, Data Breaches, AI and More
An ongoing phishing campaign is targeting French-speaking corporate environments with fake resumes that lead to the deployment of cryptocurrency miners and information stealers. “The campaign uses highly obfuscated VBScript files disguised as resume/CV documents, delivered through phishing emails,” Securonix researchers Shikha Sangwan, Akshay Gaikwad, and Aaron Beardslee said in a report shared – Read More … Read More “Hackers Use Fake Resumes to Steal Enterprise Credentials and Deploy Crypto Miner – The Hacker News” »
Critics call FCC router rule a ‘big swing’ that could create more supply chain uncertainty – CyberScoop
The Federal Communications Commission’s move to ban foreign-made routers touches on a real threat, but critics say the agency rule is overly broad, practically unworkable and doesn’t meaningfully address weaknesses in router security that have led to major breaches on American governments and businesses. Under the Secure Equipment Act and Secure Networks Act, the FCC … Read More “Critics call FCC router rule a ‘big swing’ that could create more supply chain uncertainty – CyberScoop” »
The Treasury Department is soliciting public feedback on whether it should change a terrorism risk insurance program to address cyber-related losses. In a Federal Register notice set for publication Wednesday, Treasury seeks comment from the public for a mandatory report it must deliver to Congress this summer on the effectiveness of the terrorism risk insurance … Read More “Treasury asks whether terrorism risk insurance program should bolster cyber coverage – CyberScoop” »
A federal court in Indiana sentenced a Russian cybercriminal to 81 months in prison on charges related to his role as an initial access broker for ransomware groups. Aleksei Volkov, 26, of St. Petersburg, Russia, pleaded guilty in November 2025 to six federal charges stemming from his work with the Yanluowang ransomware group and other … Read More “Russian access broker sentenced to over 6 years in prison for ransomware schemes – CyberScoop” »
DarkSword iPhone Exploit Leaked Online, Hundreds of Millions at Risk – Hackread – Cybersecurity News, Data Breaches, AI and More
DarkSword exploit leak puts up to 270 million iPhones at risk, with hackers able to access data through… – Read More – Hackread – Cybersecurity News, Data Breaches, AI and More
On February 25, 2026, Gartner published its inaugural Market Guide for Guardian Agents, marking an important milestone for this emerging category. For those unfamiliar with the various Gartner report types, “a Market Guide defines a market and explains what clients can expect it to do in the short term. With the focus on early, more … Read More “5 Learnings from the First-Ever Gartner Market Guide for Guardian Agents – The Hacker News” »
Cybersecurity researchers have uncovered a new set of malicious npm packages that are designed to steal cryptocurrency wallets and sensitive data. The activity is being tracked by ReversingLabs as the Ghost campaign. The list of identified packages, all published by a user named mikilanjillo, is below – react-performance-suite react-state-optimizer-core react-fast-utilsa ai-fast-auto-trader – Read More – … Read More “Ghost Campaign Uses 7 npm Packages to Steal Crypto Wallets and Credentials – The Hacker News” »
Two more GitHub Actions workflows have become the latest to be compromised by credential-stealing malware by a threat actor known as TeamPCP, the cloud-native cybercriminal operation also behind the Trivy supply chain attack. The workflows, both maintained by the supply chain security company Checkmarx, are listed below – checkmarx/ast-github-action checkmarx/kics-github-action Cloud security – Read More … Read More “TeamPCP Hacks Checkmarx GitHub Actions Using Stolen CI Credentials – The Hacker News” »
Cybersecurity has changed fast. Roles are more specialized, and tooling is more advanced. On paper, this should make organizations more secure. But in practice, many teams struggle with the same basic problems they faced years ago: unclear risk priorities, misaligned tooling decisions, and difficulty explaining security issues in terms the business understands. These challenges do not … Read More “The Hidden Cost of Cybersecurity Specialization: Losing Foundational Skills – The Hacker News” »
Gcore Radar report reveals 150% surge in DDoS attacks year-on-year – Hackread – Cybersecurity News, Data Breaches, AI and More
Luxembourg, Luxembourg, 24th March 2026, CyberNewswire – Read More – Hackread – Cybersecurity News, Data Breaches, AI and More
Citrix has released security updates to address two vulnerabilities in NetScaler ADC and NetScaler Gateway, including a critical flaw that could be exploited to leak sensitive data from the application. The vulnerabilities are listed below – CVE-2026-3055 (CVSS score: 9.3) – Insufficient input validation leading to memory overread CVE-2026-4368 (CVSS score: 7.7) – Race condition … Read More “Citrix Urges Patching Critical NetScaler Flaw Allowing Unauthenticated Data Leaks – The Hacker News” »
A 26-year-old Russian citizen has been sentenced in the U.S. to 6.75 years (81 months) in prison for his role in assisting major cybercrime groups, including the Yanluowang ransomware crew, in conducting numerous attacks against U.S. companies and other organizations. According to the U.S. Department of Justice (DoJ), Aleksei Olegovich Volkov facilitated dozens of ransomware … Read More “U.S. Sentences Russian Hacker to 6.75 Years for Role in $9M Ransomware Damage – The Hacker News” »
New CanisterWorm Targets Kubernetes Clusters, Deploys “Kamikaze” Wiper – Hackread – Cybersecurity News, Data Breaches, AI and More
CanisterWorm spreads via npm supply chain attack, hijacks developer accounts, targets Kubernetes clusters, and deploys destructive Kamikaze wiper payload. – Read More – Hackread – Cybersecurity News, Data Breaches, AI and More
Playnance Introduces Participation-First Model for Social Gaming with New Protocol Launch – Hackread – Cybersecurity News, Data Breaches, AI and More
Playnance launches social gaming protocol powered by GCOIN, enabling user participation in ecosystem value, transparency, and shared digital growth. – Read More – Hackread – Cybersecurity News, Data Breaches, AI and More
SAN FRANCISCO — The Trump administration’s two-week old cyber strategy that aims to promote more proactive, offensive actions while bolstering federal networks and critical infrastructure, is a significant shift that’s already materializing in meaningful ways, a group of experts said Monday at the RSAC 2026 Conference. Despite the federal government’s absence from the industry’s largest … Read More “Experts insist Trump administration’s cyber strategy is already paying off – CyberScoop” »
The North Korean threat actors behind the Contagious Interview campaign, also tracked as WaterPlum, have been attributed to a malware family tracked as StoatWaffle that’s distributed via malicious Microsoft Visual Studio Code (VS Code) projects. The use of VS Code “tasks.json” to distribute malware is a relatively new tactic adopted by the threat actor since … Read More “North Korean Hackers Abuse VS Code Auto-Run Tasks to Deploy StoatWaffle Malware – The Hacker News” »
A California county sheriff and Republican contender for the state’s gubernatorial race has seized 650,000 physical ballots from Riverside County, saying they were part of an investigation into election fraud tied to redistricting wars. State officials and election security experts say that the underlying allegations are spurious and local law enforcement do not have the … Read More “State officials, election experts question California sheriff’s seizure of ballots – CyberScoop” »
Iranian government-connected groups are deploying malware via the Telegram messaging app, taking aim at dissidents and other opponents of Tehran around the world, the FBI said in an alert Friday. The FBI said attackers linked to the Ministry of Intelligence and Security are behind the campaign, which stretches back to 2023. The bureau is escalating … Read More “FBI: Iranian hackers targeting opponents with Telegram malware – CyberScoop” »
North Korean Hacker Lands Remote IT Job, Caught After VPN Slip – Hackread – Cybersecurity News, Data Breaches, AI and More
New research from LevelBlue reveals how a suspected North Korean operative landed a remote IT role to fund national weapons programmes. – Read More – Hackread – Cybersecurity News, Data Breaches, AI and More
A phishing campaign tied to AI cloud-hosting service Railway has given hackers access to the Microsoft cloud accounts for hundreds of businesses, according to researchers at Huntress. Rich Mozeleski, product manager for Huntress’ identity team, told CyberScoop the campaign is currently tied to a smaller actor and approximately a dozen IP addresses, but has managed … Read More “An AI-powered phishing campaign has compromised hundreds of organizations – CyberScoop” »
Voice-based phishing, a form of social engineering where attackers call employees or IT help desks under false pretenses in an attempt to gain access to victim networks, surged in 2025, Mandiant said Monday in its annual M-Trends report. These points of intrusion, which have been a hallmark of attacks attributed to members of the cybercrime … Read More “The phone call is the new phishing email – CyberScoop” »
A financially motivated data theft and extortion group is attempting to inject itself into the Iran war, unleashing a worm that spreads through poorly secured cloud services and wipes data on infected systems that use Iran’s time zone or have Farsi set as the default language. Experts say the wiper campaign against Iran materialized this … Read More “‘CanisterWorm’ Springs Wiper Attack Targeting Iran – Krebs on Security” »
⚡ Weekly Recap: CI/CD Backdoor, FBI Buys Location Data, WhatsApp Ditches Numbers & More – The Hacker News
Another week, another reminder that the internet is still a mess. Systems people thought were secure are being broken in simple ways, showing many still ignore basic advisories. This edition covers a mix of issues: supply chain attacks hitting CI/CD setups, long-abused IoT devices being shut down, and exploits moving quickly from disclosure to real … Read More “⚡ Weekly Recap: CI/CD Backdoor, FBI Buys Location Data, WhatsApp Ditches Numbers & More – The Hacker News” »
We Found Eight Attack Vectors Inside AWS Bedrock. Here’s What Attackers Can Do with Them – The Hacker News
AWS Bedrock is Amazon’s platform for building AI-powered applications. It gives developers access to foundation models and the tools to connect those models directly to enterprise data and systems. That connectivity is what makes it powerful – but it’s also what makes Bedrock a target. When an AI agent can query your Salesforce instance, trigger … Read More “We Found Eight Attack Vectors Inside AWS Bedrock. Here’s What Attackers Can Do with Them – The Hacker News” »