Know What's Happening in Cybersecurity

Today's Cybersecurity Pulse

CISA adds critical Android and Linux flaws to KEV catalog

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) listed two high‑severity vulnerabilities in its Known Exploited Vulnerabilities catalog: Android CVE‑2025‑48595, an integer overflow that enables privilege escalation on Android 14‑16 without user interaction, and Linux CVE‑2022‑0492. Google released patches for the Android bug in June 2026.

Importance Of Hardware Security Verification In Pre-Silicon Design
NewsMar 26, 2026

Importance Of Hardware Security Verification In Pre-Silicon Design

Hardware security verification is becoming a prerequisite for any silicon destined for cloud, automotive, industrial or edge AI applications. The discipline rests on two pillars: functional security verification, which confirms that security features behave as specified, and protection verification, which...

By Semiconductor Engineering
UAE Positions Cyber Security as Pillar of National Resilience and Digital Growth
NewsMar 26, 2026

UAE Positions Cyber Security as Pillar of National Resilience and Digital Growth

The United Arab Emirates has formalized a nationally coordinated cyber‑security framework that links government, strategic industries and private partners. Continuous monitoring, AI‑enhanced threat detection and 24/7 response teams are embedded in a unified structure to protect critical infrastructure. The strategy...

By ComputerWeekly – DevOps
Dangerous DarkSword Malware Has Emerged—iPhone Users Should Take Action Now
BlogMar 26, 2026

Dangerous DarkSword Malware Has Emerged—iPhone Users Should Take Action Now

Security researchers have released the DarkSword exploit kit on a public platform, turning a previously state‑level iOS attack tool into a commodity for cyber‑criminals. The kit chains multiple Apple OS vulnerabilities, enabling drive‑by compromise of iPhones without any user interaction...

By Igor’sLAB
Grafana Security Release: Critical and High Severity Security Fixes for CVE-2026-27876 and CVE-2026-27880
NewsMar 26, 2026

Grafana Security Release: Critical and High Severity Security Fixes for CVE-2026-27876 and CVE-2026-27880

Grafana Labs announced version 12.4.2 and patched releases for 12.3, 12.2, 12.1 and 11.6, addressing two high‑impact vulnerabilities. CVE‑2026‑27876 is a critical 9.1‑rated remote‑code‑execution flaw in the sqlExpressions feature that allows arbitrary file writes. CVE‑2026‑27880 is a high‑severity 7.5‑rated denial‑of‑service...

By Grafana Labs – Blog
The Price of Privacy? HK$100k and 1 Year in Prison.
BlogMar 26, 2026

The Price of Privacy? HK$100k and 1 Year in Prison.

Hong Kong’s National Security Law implementation rules were amended to criminalize refusal to provide passwords for seized electronic devices, imposing up to one year in prison and a fine of HK$100,000 (≈US$12,800). The changes were issued by decree, bypassing Legislative...

By LikeCoin
AI Finds Vulns You Can't With Nicholas Carlini
PodcastMar 26, 20261h 16m

AI Finds Vulns You Can't With Nicholas Carlini

In this episode, host Deirdre and David Amos sit down with vulnerability researcher Nicholas Carlini to discuss how large language models (LLMs) are now being used to discover software bugs, including zero‑day vulnerabilities. Carlini explains that recent advances allow a...

By Security Cryptography Whatever
SOC 2: Theater, Yet Reveals AI Companies’ Third‑Party Stack
SocialMar 26, 2026

SOC 2: Theater, Yet Reveals AI Companies’ Third‑Party Stack

SOC 2 is largely useless theater, much like SOX compliance, but it’s quite useful for identifying the third-party providers a website relies on. DeployGraph: What infrastructure does every AI company run on? https://www.deploygraph.com/

By Sung Kim
WebAssembly Proposed as Secure Sandbox for AI‑Generated Code
NewsMar 26, 2026

WebAssembly Proposed as Secure Sandbox for AI‑Generated Code

At the Wasm I/O conference in Barcelona, Dan Phillips, founder of WebAssembly Chicago, advocated using WebAssembly to sandbox AI‑generated code, arguing it eliminates shared‑kernel risks and speeds deployment. The proposal targets DevOps teams grappling with unsafe agent execution.

By Pulse
Ledger Finds Flaw Lets Hackers Steal PINs and Crypto Keys From Powered‑Off Android Phones
NewsMar 26, 2026

Ledger Finds Flaw Lets Hackers Steal PINs and Crypto Keys From Powered‑Off Android Phones

Ledger’s Donjon research team demonstrated that attackers can retrieve PINs, encrypted storage and crypto‑wallet seed phrases from Android phones that are turned off. The flaw, present in MediaTek processors paired with Trustonic’s Trusted Execution Environment, impacts roughly one‑quarter of Android...

By Pulse
Bitcoin Community Mobilizes Against Long‑Term Quantum Threat to Crypto Security
NewsMar 26, 2026

Bitcoin Community Mobilizes Against Long‑Term Quantum Threat to Crypto Security

Bitcoin developers and governance bodies are racing to harden the network against a future quantum computer capable of breaking elliptic‑curve signatures. Proposals such as Pay‑to‑Merkle‑Root, the Hourglass mitigation, and post‑quantum hash‑based signatures aim to protect millions of BTC that could...

By Pulse
SANS Stormcast Thursday, March 26th, 2026: Apple Patches; SmatApeSG Update; Trivy/LiteLLM/TeamPCP Update; Google Accelerates Quantum Save Crypto Rollout
PodcastMar 26, 20266 min

SANS Stormcast Thursday, March 26th, 2026: Apple Patches; SmatApeSG Update; Trivy/LiteLLM/TeamPCP Update; Google Accelerates Quantum Save Crypto Rollout

In this 7‑minute Stormcast episode, Johannes Ulrich reviews Apple’s latest patch cycle—85 vulnerabilities across iOS, macOS, and watchOS—emphasizing the importance of timely updates even though none are known to be actively exploited. He then provides an update on the LiteLLM...

By SANS Internet StormCast
Incident Response & Hiring Trends: What HR Can Learn From Semperis
NewsMar 26, 2026

Incident Response & Hiring Trends: What HR Can Learn From Semperis

Semperis has positioned its platform as a full‑stack incident response solution, offering real‑time threat detection, automated alerting, and rapid containment tools. The suite also streamlines recovery by rolling back unauthorized changes and supports compliance with detailed audit logs. In addition...

By Onrec
Stay Incognito: Hide Your Chats From AI Profiling
SocialMar 26, 2026

Stay Incognito: Hide Your Chats From AI Profiling

Every chat you have with your favorite AI is fuel for its analysis of you and the profile that it's building of your interests. Instead, here's how to go incognito or private in ChatGPT, Gemini, Claude, and Copilot: https://t.co/YHaJYbOh9E #ai...

By Dave Taylor
LEO Satellite Operators Could Be Beyond Australian Data Laws
NewsMar 25, 2026

LEO Satellite Operators Could Be Beyond Australian Data Laws

Australia’s Cyber Security Centre, together with international partners, warned that commercial low‑Earth‑orbit (LEO) satellite operators can deliver connectivity to Australian users without a local footprint, leaving data outside the reach of domestic privacy laws. The advisory highlights that LEO constellations...

By iTnews (Australia) – Government
Got One of Those Weird Fake Microsoft Security Warning Screens
NewsMar 25, 2026

Got One of Those Weird Fake Microsoft Security Warning Screens

A fake Microsoft security warning overlay appeared in the Brave browser, locking the screen and preventing normal navigation. The pop‑up, triggered by malicious ads—often from Facebook—forced the user to terminate the browser via Task Manager. Upon restart, the warning did...

By AnandTech
GitHub Adds AI-Powered Bug Detection to Expand Security Coverage
NewsMar 25, 2026

GitHub Adds AI-Powered Bug Detection to Expand Security Coverage

GitHub announced an AI‑powered scanning layer for its Code Security suite, complementing the existing CodeQL static analysis. The hybrid approach expands vulnerability detection to languages and frameworks such as Bash, Dockerfiles, Terraform, and PHP, while CodeQL continues deep semantic analysis...

By BleepingComputer
European Officials Highlight Private Sector Help in Major Cybercrime Takedowns
NewsMar 25, 2026

European Officials Highlight Private Sector Help in Major Cybercrime Takedowns

European cyber law enforcement leaders at RSAC highlighted the growing role of private‑sector partners in dismantling major ransomware groups such as LockBit and Scattered Spider. Officials from the Netherlands, UK and Germany noted that industry briefings helped legitimize takedowns and...

By FCW (GovExec Technology)
Beyond IOCs: A Framework for High-Impact Cyber Threat Intelligence - Samuel Hassine - RSAC26 #3
NewsMar 25, 2026

Beyond IOCs: A Framework for High-Impact Cyber Threat Intelligence - Samuel Hassine - RSAC26 #3

Samuel Hassine, CEO of Filigran, outlined a shift from reactive indicator‑of‑compromise (IOC) alerts to a business‑focused Continuous Threat Exposure Management (CTEM) framework. He emphasized unifying threat intelligence with adversarial attack simulation using platforms like OpenCTI to drive measurable risk reduction....

By SC Media
Alleged RedLine Infostealer Conspirator Extradited to US
NewsMar 25, 2026

Alleged RedLine Infostealer Conspirator Extradited to US

An Armenian national, Hambardzum Minasyan, was extradited to the United States and appeared in a Texas federal court on charges tied to the RedLine infostealer. Prosecutors allege he helped develop, host, and monetize the malware, which siphons billions of user...

By CyberScoop
ORNL Introduces ‘Photon’ Framework for Accelerating AI Vulnerability Discovery on Frontier
NewsMar 25, 2026

ORNL Introduces ‘Photon’ Framework for Accelerating AI Vulnerability Discovery on Frontier

Oak Ridge National Laboratory’s CAISER team unveiled Photon, a new framework that uses the Frontier exascale supercomputer to accelerate AI vulnerability discovery. By repurposing the DeepHyper training system, Photon runs thousands of jailbreak prompts in parallel, achieving over 95% GPU...

By EnterpriseAI (AIwire)
7 Employer Tips For Handling Calif. Privacy Risk Assessments
NewsMar 25, 2026

7 Employer Tips For Handling Calif. Privacy Risk Assessments

California employers must now meet the California Consumer Privacy Act’s (CCPA) risk assessment mandate, which requires a systematic review of personal data practices. Law360 outlines seven practical steps, including data mapping, privacy impact analyses, vendor oversight, employee training, documentation, continuous...

By Littler – Insights/News
Convicted Spyware Chief Hints that Greece’s Government Was Behind Dozens of Phone Hacks
NewsMar 25, 2026

Convicted Spyware Chief Hints that Greece’s Government Was Behind Dozens of Phone Hacks

Intellexa founder Tal Dilian, convicted of orchestrating a mass‑wiretapping campaign in Greece, announced his intention to appeal the eight‑year prison sentence. The scandal, dubbed “Greek Watergate,” involved the Predator spyware compromising phones of ministers, opposition leaders, military officials and journalists....

By TechCrunch (Cybersecurity)
AI Supply Chain Attacks Don’t Even Require Malware…just Post Poisoned Documentation
NewsMar 25, 2026

AI Supply Chain Attacks Don’t Even Require Malware…just Post Poisoned Documentation

Andrew Ng's Context Hub service supplies up‑to‑date API documentation to AI coding agents, but its open‑pull‑request workflow lacks any content sanitisation. Security researcher Mickey Shmueli demonstrated a proof‑of‑concept where poisoned documentation caused agents to add malicious PyPI packages to generated code....

By The Register — Networks
AI Agent Identity and Next‑gen Enterprise Authentication Prominent at RSAC 2026
NewsMar 25, 2026

AI Agent Identity and Next‑gen Enterprise Authentication Prominent at RSAC 2026

At RSA Conference 2026, vendors highlighted password‑less authentication for both humans and AI agents, with Swissbit unveiling a biometric FIDO2 key that adds post‑quantum resistance, and RSA extending its identity suite to Microsoft 365 E7. IBM, Auth0 and Yubico introduced...

By Biometric Update
Readying Industrial Connectivity for Cybersecurity Requirements
NewsMar 25, 2026

Readying Industrial Connectivity for Cybersecurity Requirements

Cyber attacks on industrial operations have highlighted the lag in OT cybersecurity compared with IT. The EU Cyber Resilience Act (CRA), effective from December 2024, forces manufacturers to report vulnerabilities and obtain CE marking for new digital products by December 2027. Standards...

By Control Design
Identity Theft: Verizon Account Opened without Consent
SocialMar 25, 2026

Identity Theft: Verizon Account Opened without Consent

Someone opened up a Verizon Business account in my name, got two lines and internet, but never changed the billing address so I just got the bill. Currently on hold with their fraud department

By Kyle Benjamin
Built‑in Cyber Defense Keeps Public Safety Communications Uninterrupted
SocialMar 25, 2026

Built‑in Cyber Defense Keeps Public Safety Communications Uninterrupted

In public safety, cyber security can’t be an add-on. It needs to be designed into the network. @T_Priority on T-Mobile’s 5G network isolates threat traffic at the network layer, so priority communications stay secure. Resilience should be built in, not bolted on....

By Glen Gilmore
Why Revenue Cycle Teams Must Prepare for Extended Downtime in the Age of Cyber Threats
NewsMar 25, 2026

Why Revenue Cycle Teams Must Prepare for Extended Downtime in the Age of Cyber Threats

Healthcare providers face escalating ransomware and cloud‑outage threats that can instantly cripple revenue cycle operations, halting claim submissions and cash flow. Recent incidents, such as the Change Healthcare clearinghouse outage and a regional system’s backup encryption, exposed critical blind spots...

By HFMA – Healthcare Financial Management Association
Public Allocator Flaw Cost Morpho $5K Hack
SocialMar 25, 2026

Public Allocator Flaw Cost Morpho $5K Hack

"At the time of the hack, the damage in Morpho was $5k. But the 'public allocator' feature, which was supposed to be good, was not." https://t.co/FwY7H6TiKM

By Laura Shin
Preventing USR Hacks: Expert Advice From Omer Goldberg
SocialMar 25, 2026

Preventing USR Hacks: Expert Advice From Omer Goldberg

"There are ways to prevent this type of hacks," says @omeragoldberg on Uneasy Money, speaking about USR https://t.co/FwY7H6TiKM

By Laura Shin
In-Sensor Cryptography Links Physical Process to Digital Identity
NewsMar 25, 2026

In-Sensor Cryptography Links Physical Process to Digital Identity

Researchers unveiled a monolithic in‑sensor cryptographic system that hashes and digitally signs data at the moment of capture, linking each measurement to an immutable digital identity. The prototype, built on 180 nm CMOS, demonstrated real‑time signing of cardiac cell voltage recordings...

By Bioengineer.org
Curators Set Morpho Caps to Zero, Unaware It Fails
SocialMar 25, 2026

Curators Set Morpho Caps to Zero, Unaware It Fails

The moment curators realized the Resolv hack was happening, they set Morpho supply caps to zero. Morpho's own documentation warns that setting caps to zero doesn't stop the attack. Most curators didn't know that. https://t.co/P1vIs3eM4Z

By Laura Shin
Bubble AI App Builder Abused to Steal Microsoft Account Credentials
NewsMar 25, 2026

Bubble AI App Builder Abused to Steal Microsoft Account Credentials

Threat actors are exploiting Bubble, an AI‑powered no‑code app builder, to host malicious web apps that impersonate Microsoft login pages. By serving phishing pages from the trusted *.bubble.io domain, email security solutions fail to flag the links, allowing credentials to...

By BleepingComputer
TeamPCP Supply Chain Attack Hits LiteLLM PyPI Package
NewsMar 25, 2026

TeamPCP Supply Chain Attack Hits LiteLLM PyPI Package

Open‑source Python library LiteLLM was compromised by the TeamPCP threat group, which uploaded malicious versions to PyPI that have since been removed. The packages deployed a three‑stage intrusion: credential harvesting, a Kubernetes lateral‑movement toolkit, and a persistent systemd backdoor. Endor...

By SC Media
Trojanized ConnectWise ScreenConnect Installers Deployed in Tax-Themed Malvertising Campaign
NewsMar 25, 2026

Trojanized ConnectWise ScreenConnect Installers Deployed in Tax-Themed Malvertising Campaign

Cybercriminals have been running a tax‑season malvertising campaign since January 2026, hijacking Google Ads to serve fake W‑2 and W‑9 download pages that redirect to malicious ConnectWise ScreenConnect installers. The trojanized installers launch a trial instance, inject a multi‑stage crypter...

By SC Media
Updates to GitHub Copilot Interaction Data Usage Policy
NewsMar 25, 2026

Updates to GitHub Copilot Interaction Data Usage Policy

GitHub announced that, starting April 24, interaction data from Copilot Free, Pro, and Pro+ users will be used to train its AI models unless users opt out. The policy excludes Copilot Business and Enterprise customers, whose data remains untouched. Users can...

By Hacker News
BSidesSLC 2025 – LLM-Powered Network Intrusion Detection
NewsMar 25, 2026

BSidesSLC 2025 – LLM-Powered Network Intrusion Detection

At BSidesSLC 2025, Pattern Inc. Machine Learning Engineer Taeyang Kim unveiled an LLM‑powered network intrusion detection system (NIDS). The solution leverages large language models to parse raw packet data and identify malicious patterns in real time. Kim demonstrated a prototype...

By Security Boulevard
Trends Revealed in Fortinet’s FortiGuard Labs 2026 Global Threat Landscape Report - Aamir Lakhani - RSAC26 #3
NewsMar 25, 2026

Trends Revealed in Fortinet’s FortiGuard Labs 2026 Global Threat Landscape Report - Aamir Lakhani - RSAC26 #3

Fortinet’s FortiGuard Labs released its 2026 Global Threat Landscape Report, highlighting a sharp rise in AI‑enabled cybercrime. The report shows AI is accelerating attack techniques, from automated ransomware encryption to AI‑driven supply‑chain exploits. Aamir Lakhani, Fortinet’s Global Director of Threat Intelligence...

By SC Media
Trivy Compromise Spreads to Major Python Package
SocialMar 25, 2026

Trivy Compromise Spreads to Major Python Package

Aqua Security’s Trivy vulnerability scanner compromise is trickling down into a hugely popular Python package. https://t.co/oj8J8KJrGo

By TechRadar
New Torg Grabber Infostealer Malware Targets 728 Crypto Wallets
NewsMar 25, 2026

New Torg Grabber Infostealer Malware Targets 728 Crypto Wallets

Researchers at Gen Digital have uncovered Torg Grabber, a rapidly evolving infostealer that has harvested data from 850 browser extensions, including 728 cryptocurrency wallets, between December 2025 and February 2026. The malware gains initial access via the ClickFix clipboard‑hijacking technique, then executes...

By BleepingComputer
Gov Proposes Disclosure Delay for Most Serious Cyberattacks
NewsMar 25, 2026

Gov Proposes Disclosure Delay for Most Serious Cyberattacks

Australia is consulting on new rules that would allow a temporary, roughly 30‑day delay in publicly disclosing serious cyber‑attacks on critical‑infrastructure operators, including ASX‑listed firms. The proposal aims to give entities time to mitigate threats without compromising national security or...

By iTnews (Australia) – Government
Chained Vulnerabilities in Cisco Catalyst Switches Could Induce Denial-of-Service
NewsMar 25, 2026

Chained Vulnerabilities in Cisco Catalyst Switches Could Induce Denial-of-Service

Cisco disclosed four vulnerabilities in its widely deployed Catalyst 9300 series switches, two of which (CVE‑2026‑20114 and CVE‑2026‑20110) can be chained to elevate a low‑privilege Lobby Ambassador account into maintenance mode, effectively causing a denial‑of‑service outage. The chain requires only...

By CSO Online
$300 AI Tool Kits Let Criminals Bypass Bank Security
NewsMar 25, 2026

$300 AI Tool Kits Let Criminals Bypass Bank Security

Criminals can now purchase AI‑enabled identity‑fraud kits for under $300, combining stolen personal data, synthetic‑material printers and deep‑fake software to bypass bank KYC checks in minutes. Demonstrations at the 2026 RSAC conference showed tools like ProKYC feeding fabricated videos into...

By American Banker
The United States Router Ban, Explained
NewsMar 25, 2026

The United States Router Ban, Explained

The FCC announced a ban on future consumer Wi‑Fi routers that are manufactured abroad, citing national‑security concerns. Existing routers can remain in use and receive firmware updates through March 1 2027, but no new foreign‑made devices will receive FCC authorization. The rule...

By The Verge – Policy
AI Social Media Scams Are Coming for Your Accounting Firm: Why DNS Filtering Belongs in Your Security Stack
NewsMar 25, 2026

AI Social Media Scams Are Coming for Your Accounting Firm: Why DNS Filtering Belongs in Your Security Stack

Artificial intelligence is enabling highly personalized social‑media phishing campaigns that target accountants with fake client messages, ads and login pages. These AI‑driven scams increase the risk of wire fraud, data theft and ransomware for firms handling sensitive financial information. DNS...

By CPA Practice Advisor
What Is Antivirus Software and Do You Still Need It in 2026?
NewsMar 25, 2026

What Is Antivirus Software and Do You Still Need It in 2026?

Antivirus software remains relevant in 2026 as cyber threats grow more sophisticated, with AI‑driven phishing, malicious app bundles, and polymorphic malware outpacing built‑in defenses. While Microsoft Defender and macOS XProtect provide a solid baseline, they often miss newer variants and...

By ZDNet Robotics
Chinese Firms Boost AWS Compliance Demand 250% Abroad
SocialMar 25, 2026

Chinese Firms Boost AWS Compliance Demand 250% Abroad

Chinese companies' demand for Amazon Web Services compliance has increased by 250% as they expand overseas | Going Global · Technology _ https://t.co/YUHaLiFdIV https://t.co/w6d3n4u8bd

By Paul Triolo
The Dark Side of DDoS: Why DDoS Downtime Is Harder to Prevent
NewsMar 25, 2026

The Dark Side of DDoS: Why DDoS Downtime Is Harder to Prevent

Cloudflare’s 2026 report reveals DDoS attacks are growing larger, more frequent, and increasingly AI‑driven, shifting from blunt traffic floods to precise, low‑volume Layer 7 assaults timed around high‑impact events. Traditional point‑in‑time testing can’t keep pace with rapid network changes, leading to...

By Security Boulevard