‘CanisterWorm’ Springs Wiper Attack Targeting Iran

Blog WriterCybersecurity News - Original News Source is krebsonsecurity.com

March 23, 2026 0 Comments A financially motivated data theft and extortion group is attempting to inject itself into the Iran war, unleashing a worm that spreads through poorly secured cloud services and wipes data on infected systems that use …

Oblivion RAT Turns Fake Play Store Updates Into a Full-Service Android Spyware Operation

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly discovered Android remote access trojan known as Oblivion RAT has emerged on cybercrime networks as a complete malware-as-a-service (MaaS) platform, turning fake Google Play Store update pages into a full-scale spyware operation. First reported by Certo Software, the …

Trivy Supply Chain Attack Expands as Compromised Docker Images Hit Docker Hub

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A supply chain attack targeting Trivy, the widely used open-source vulnerability scanner, has grown well beyond its initial scope. What started as a GitHub Actions compromise has now extended to Docker Hub, where three malicious Docker image versions were silently …

Windows 11 Emergency Update to Fix ‘No Internet’ Sign-In Errors for OneDrive, Teams, and More

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has released an out-of-band (OOB) update, KB5085516, for Windows 11 versions 25H2 and 24H2 to address a critical sign-in issue introduced by the March 2026 Patch Tuesday update. The emergency patch, released on March 21, 2026, targets a bug …

CISA Warns of Craft CMS Code Injection Vulnerability Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability in Craft CMS (CVE-2025-32432) has been added to the Known Exploited Vulnerabilities catalog following confirmed active exploitation in the wild. Security teams and system administrators are advised to address this issue immediately to prevent severe network compromises. …

$30 IP-KVM Flaws Could Give Attackers BIOS-Level Control Across Enterprise Networks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

$30 IP-KVM Flaws Attackers BIOS-Level Control Across Enterprise Networks A recent security assessment by researchers has uncovered nine severe vulnerabilities across four popular low-cost IP-KVM devices. These flaws uncovered by Eclypsium allow attackers to gain complete, BIOS-level control over connected …

New CanisterWorm Steals npm Tokens and Spreads Through Compromised Publisher Accounts

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new wave of supply chain attacks is hitting the npm ecosystem through a self-propagating malware campaign known as CanisterWorm. The threat, linked to a group tracked as “TeamPCP,” compromises legitimate publisher namespaces and pushes poisoned package versions, effectively turning …

CISA Warns of Apple Vulnerabilities Linked to DarkSword iOS Exploit Chain Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

CISA Warns Apple Vulnerabilities Linked to DarkSword iOS Exploit Chain An urgent warning regarding three critical Apple vulnerabilities that threat actors are actively exploiting in the wild. These security flaws, officially tracked as CVE-2025-31277, CVE-2025-43510, and CVE-2025-43520, were recently added …

Copyright-Themed Lures Deliver Multi-Stage PureLog Stealer in New Credential Theft Campaign

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new malware campaign is targeting organizations across healthcare, government, education, and hospitality sectors using cleverly disguised copyright violation notices to deliver PureLog Stealer, a powerful information-stealing malware. The campaign, first analyzed in March 2026, tricks victims into executing a …

Microsoft Emergency Out-of-Band Update for Windows 11 to Fix Microsoft Account Sign-In Failure

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has issued an out-of-band (OOB) update for Windows 11 versions 25H2 and 24H2, identified as KB5085516, addressing a critical sign-in bug introduced by the March 2026 Patch Tuesday release. The update carries OS builds 26200.8039 and 26100.8039 and was …