Latest Cybersecurity News and Articles


Coruna iOS Kit Reuses 2023 Triangulation Exploit Code in New Mass Attacks

26 March 2026
The kernel exploit for two security vulnerabilities used in the recently uncovered Apple iOS exploit kit known as Coruna is an updated version of the same exploit that was used in the Operation Triangulation campaign back in 2023, according to new findings from Kaspersky. "When Coruna was first reported, the public evidence wasn't sufficient to link its code to Triangulation — shared

[Webinar] Stop Guessing. Learn to Validate Your Defenses Against Real Attacks

26 March 2026
Most teams have security tools in place. Alerts are firing, dashboards look clean, threat intel is flowing in. On the surface, everything feels under control. But one question usually stays unanswered: Would your defenses actually stop a real attack? That’s where things get shaky. A control exists, so it’s assumed to work. A detection rule is active, so it’s expected to catch something. But very

Alleged RedLine Malware Administrator Extradited to US

26 March 2026
Hambardzum Minasyan of Armenia has been accused of being involved in the development and administration of the infostealer malware. The post Alleged RedLine Malware Administrator Extradited to US appeared first on SecurityWeek.

Dell and HP Roll Out Quantum-Resistant Device Security and AI-Era Cyber Resilience

26 March 2026
The computer giants have announced new security capabilities for PCs and printers. The post Dell and HP Roll Out Quantum-Resistant Device Security and AI-Era Cyber Resilience appeared first on SecurityWeek.

WebRTC Skimmer Bypasses CSP to Steal Payment Data from E-Commerce Sites

26 March 2026
Cybersecurity researchers have discovered a new payment skimmer that uses WebRTC data channels as a means to receive payloads and exfiltrate data, effectively bypassing security controls. "Instead of the usual HTTP requests or image beacons, this malware uses WebRTC data channels to load its payload and exfiltrate stolen payment data," Sansec said in a report published this week. The attack,

LeakBase Admin Arrested in Russia Over Massive Stolen Credential Marketplace

25 March 2026
The alleged administrator of the LeakBase cybercrime forum has been arrested by Russian law enforcement authorities, state media reported Thursday. According to TASS and MVD Media, a news website linked to the Russian Interior Ministry, the suspect is a resident of the city of Taganrog. The suspect is said to have been detained for creating and managing a criminal site that allowed stolen

Onit Security Raises $11 Million for Exposure Management Platform

25 March 2026
The startup will invest in product development and go-to-market efforts as it expands into new sectors. The post Onit Security Raises $11 Million for Exposure Management Platform appeared first on SecurityWeek.

Russian Cybercriminal Gets 2-Year Prison Sentence in US 

25 March 2026
Ilya Angelov was a member of the cybercrime group tracked as TA-551, Shathak, Gold Cabin, Monster Libra, and ATK236. The post Russian Cybercriminal Gets 2-Year Prison Sentence in US  appeared first on SecurityWeek.

GlassWorm Malware Uses Solana Dead Drops to Deliver RAT and Steal Browser, Crypto Data

25 March 2026
Cybersecurity researchers have flagged a new evolution of the GlassWorm campaign that delivers a multi-stage framework capable of comprehensive data theft and installing a remote access trojan (RAT), which deploys an information-stealing Google Chrome extension masquerading as an offline version of Google Docs. "It logs keystrokes, dumps cookies and session tokens, captures screenshots, and

AI Speeds Attacks, But Identity Remains Cybersecurity’s Weakest Link

25 March 2026
PwC finds AI is amplifying speed and scale of attacks, as identity theft evolves into a cybercriminal supply chain. The post AI Speeds Attacks, But Identity Remains Cybersecurity’s Weakest Link appeared first on SecurityWeek.

iOS, macOS 26.4 Roll Out With Fresh Security Patches

25 March 2026
Apple released security fixes for older devices as well, in iOS 18.7.7, iPadOS 18.7.7, macOS Sequoia 15.7.5, and macOS Sonoma 14.8.5. The post iOS, macOS 26.4 Roll Out With Fresh Security Patches appeared first on SecurityWeek.

Investors Want To Know: Is Cybersecurity A Growth Sector Or A Cost Center?

25 March 2026
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Mar. 25, 2026 – Read the full story from StocksToday.com This past weekend, Stocks today.com shared an economic observation about physical constraints—blocked shipping lanes, sold-out memory chips, smuggled semiconductors—that no monetary policy lever can The post Investors Want To Know: Is Cybersecurity A Growth Sector Or A Cost Center? appeared first on Cybercrime Magazine.

FCC Bans New Routers Made Outside the US Over National Security Risks

25 March 2026
The ban aligns with a White House determination that all routers produced abroad are a threat to national security. The post FCC Bans New Routers Made Outside the US Over National Security Risks appeared first on SecurityWeek.

RSAC 2026 Conference Announcements Summary (Day 2)

25 March 2026
A summary of the announcements made by vendors on the second day of the RSAC 2026 Conference. The post RSAC 2026 Conference Announcements Summary (Day 2) appeared first on SecurityWeek.

Vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway

25 March 2026
UK organisations encouraged to take immediate action to mitigate two recently disclosed vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway.

The Kill Chain Is Obsolete When Your AI Agent Is the Threat

25 March 2026
In September 2025, Anthropic disclosed that a state-sponsored threat actor used an AI coding agent to execute an autonomous cyber espionage campaign against 30 global targets. The AI handled 80-90% of tactical operations on its own, performing reconnaissance, writing exploit code, and attempting lateral movement at machine speed. This incident is worrying, but there's a scenario that should

From Trivy to Broad OSS Compromise: TeamPCP Hits Docker Hub, VS Code, PyPI

25 March 2026
The hackers compromised GitHub Action tags, then shifted to NPM, Docker Hub, VS Code, and PyPI, and teamed with Lapsus$. The post From Trivy to Broad OSS Compromise: TeamPCP Hits Docker Hub, VS Code, PyPI appeared first on SecurityWeek.

Russian Hacker Sentenced to 2 Years for TA551 Botnet-Driven Ransomware Attacks

25 March 2026
The U.S. Department of Justice (DoJ) said a Russian national has been sentenced to two years in prison for managing a botnet that was used to launch ransomware attacks against U.S. companies. Ilya Angelov, 40, of Tolyatti, Russia, was also fined $100,000. Angelov, who went by the online aliases "milan" and "okart," is said to have co-managed a Russia-based cybercriminal group known as TA551 (aka

Device Code Phishing Hits 340+ Microsoft 365 Orgs Across Five Countries via OAuth Abuse

25 March 2026
Cybersecurity researchers are calling attention to an active device code phishing campaign that's targeting Microsoft 365 identities across more than 340 organizations in the U.S., Canada, Australia, New Zealand, and Germany. The activity, per Huntress, was first spotted on February 19, 2026, with subsequent cases appearing at an accelerated pace since then. Notably, the campaign leverages

US Prisons Russian Access Broker for Aiding Ransomware Attacks

25 March 2026
Aleksei Volkov has been sentenced to 81 months in prison for his role in Yanluowang ransomware attacks.  The post US Prisons Russian Access Broker for Aiding Ransomware Attacks appeared first on SecurityWeek.