Ghostwire — Live Cybersecurity Feed

Real-time cybersecurity news from 130+ sources. Updated every 5 minutes.

Attackers hijack Axios npm account to spread RAT malware

Security Affairs · Pierluigi Paganini · 2026-03-31 18:30 UTC

Threat actors hijacked the npm account of Axios to distribute RAT malware via malicious package updates. Threat actors compromised the npm account of Axios, a widely used library with over 100M weekly...

Breaking NewsCyber CrimeHackingMalwareSecurity

Android Developer Verification Rollout Begins Ahead of September Enforcement

The Hacker News · Ravie Lakshmanan · 2026-03-31 18:28 UTC

Google on Monday said it's officially rolling out Android developer verification to all developers to combat the problem of bad actors distributing harmful apps while "hiding behind anonymity." The de...

Quantum computers need vastly fewer resources than thought to break vital encryption

Ars Technica · Dan Goodin · 2026-03-31 18:25 UTC

No, the sky isn't falling, but Q Day is coming, and it won't be as expensive as thought.

Biz & ITSecurityelliptic curve cryptographyneutral atomsquantum computing

Wordfence Bug Bounty Program Monthly Report – February 2026

Wordfence · Chloe Chamberland · 2026-03-31 18:24 UTC

Last month in February 2026, the Wordfence Bug Bounty Program received 1078 vulnerability submissions from our growing community of security researchers working to improve the overall security posture...

VulnerabilitiesWordPress Security

Social gaming platform Rec Room, once valued at $3.5B, is shutting down

TechCrunch · Lauren Forristal · 2026-03-31 18:05 UTC

Rec Room, the social platform for user-generated games and virtual experiences, will shutter on June 1.

GamingSocialRec RoomVR

Our Favorite Affordable Air Purifier Is Temporarily Even Cheaper

Feed: All Latest · Brad Bourque · 2026-03-31 18:02 UTC

Amazon has the Coway Airmega Mighty marked down to two-thirds its normal price.

GearGear / DealsGear / ProductsGear / Products / Home

(Otra) Vulnerabilidad SQLi está siendo explotada en Fortinet FortiClient EMS (CVE-2026-21643)

Segu-Info · SeguInfo · 2026-03-31 18:01 UTC

Empresas de inteligencia de amenazas advierten que ciberdelincuentes han comenzado a explotar una vulnerabilidad crítica en Fortinet FortiClient EMS. FortiClient EMS, un servidor de administraci...

Inside the Axios supply chain compromise - one RAT to rule them all

Elastic Security Labs · Elastic Security Labs · 2026-03-31 17:58 UTC

Elastic Security Labs analyzes a supply chain compromise of the axios npm package delivering a unified cross-platform RAT

security-labs

You can finally change the goofy Gmail address you chose years ago

Ars Technica · Ryan Whitwam · 2026-03-31 17:55 UTC

All your data remains intact, and you can go back to your original address at any time.

GoogleTechgmailgoogle

US indicts Maryland man for 2021 theft of $54 million from Uranium Finance

The Record · The Record · 2026-03-31 17:55 UTC

U.S. Attorney Jay Clayton said Spalletta “repeatedly hacked smart contracts to steal millions of dollars’ worth of other people’s money for himself, and destroyed a cryptocurrency exchange in the proc...

CybercrimeGovernmentNews

Cisco source code stolen in Trivy-linked dev environment breach

BleepingComputer · Lawrence Abrams · 2026-03-31 17:53 UTC

Cisco has suffered a cyberattack after threat actors used stolen credentials from the recent Trivy supply chain attack to breach its internal development environment and steal source code belonging to...

Security

CVE-2025-62184 - Pega Platform versions 8.1.0 through 25.1.0 are affected by a Stored Cross-site Scripting vulnerability in a user interface component.

CVE Feed · CVE Feed · 2026-03-31 17:52 UTC

CVE ID :CVE-2025-62184 Published : March 31, 2026, 5:52 p.m. | 27 minutes ago Description :Pega Platform versions 8.1.0 through 25.1.0 are affected by a Stored Cross-site Scripting vulnerabi...

Google Now Lets You Change Your Gmail Address. Here’s How

Feed: All Latest · Reece Rogers · 2026-03-31 17:51 UTC

You’ve probably had the same Gmail address for years. Now, it’s easy to make a name change without worrying about the transition.

GearGear / How To and AdviceGear / Products / Apps

2026 SANS Identity Threats Report: Why Attacks Still Work

Security Boulevard · Enzoic · 2026-03-31 17:45 UTC

SANS findings highlight the real issue, compromised credentials enable access long before traditional security controls detect a problem. The post 2026 SANS Identity Threats Report: Why Attacks Still ...

Data SecuritySecurity Bloggers NetworkThreats & Breachesaccount takeoverActive Directory

CVE-2026-33415 - Discourse: Improper Access Control in discourse-ai Allows Unauthorized Category Content Exposure

CVE Feed · CVE Feed · 2026-03-31 17:42 UTC

CVE ID :CVE-2026-33415 Published : March 31, 2026, 5:42 p.m. | 37 minutes ago Description :Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, ...

CVE-2026-33300 - Discourse: Hidden group names and access metadata are exposed to moderators through the `category-chatables` endpoint

CVE Feed · CVE Feed · 2026-03-31 17:42 UTC

CVE ID :CVE-2026-33300 Published : March 31, 2026, 5:42 p.m. | 37 minutes ago Description :Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, ...

CVE-2026-33185 - Discourse: Group SMTP test endpoint susceptible to SSRF

CVE Feed · CVE Feed · 2026-03-31 17:41 UTC

CVE ID :CVE-2026-33185 Published : March 31, 2026, 5:41 p.m. | 37 minutes ago Description :Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, ...

Alexa+ gets new food ordering experiences with Uber Eats and Grubhub

TechCrunch · Lauren Forristal · 2026-03-31 17:41 UTC

You can now order from Uber Eats and Grubhub using Alexa+, an experience Amazon says will be similar to chatting with a waiter at a restaurant or placing an order at a drive-thru.

AIAlexaAmazonfood deliverygrubhub

CVE-2026-33074 - Discourse: Vulnerability in discourse-subscriptions plugin allowing users to self-grant to higher tier subscriptions

CVE Feed · CVE Feed · 2026-03-31 17:41 UTC

CVE ID :CVE-2026-33074 Published : March 31, 2026, 5:41 p.m. | 37 minutes ago Description :Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, ...

CVE-2026-32951 - Discourse: Authorization bypass in oneboxer via user-controlled category id

CVE Feed · CVE Feed · 2026-03-31 17:41 UTC

CVE ID :CVE-2026-32951 Published : March 31, 2026, 5:41 p.m. | 37 minutes ago Description :Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, ...

CVE-2026-32620 - Discourse: Missing post-level authorization allows whisper metadata disclosure

CVE Feed · CVE Feed · 2026-03-31 17:41 UTC

CVE ID :CVE-2026-32620 Published : March 31, 2026, 5:41 p.m. | 38 minutes ago Description :Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, ...

CVE-2026-32618 - Discourse: Unauthorized channel membership inference via excluded_memberships_channel_id

CVE Feed · CVE Feed · 2026-03-31 17:40 UTC

CVE ID :CVE-2026-32618 Published : March 31, 2026, 5:40 p.m. | 38 minutes ago Description :Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, ...

CVE-2026-32619 - Discourse: Insufficient topic visibility check allows unauthorized poll manipulation in private categories

CVE Feed · CVE Feed · 2026-03-31 17:40 UTC

CVE ID :CVE-2026-32619 Published : March 31, 2026, 5:40 p.m. | 38 minutes ago Description :Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, ...

CVE-2026-32615 - Discourse: Category group moderators can perform actions on topics in restricted categories without read access

CVE Feed · CVE Feed · 2026-03-31 17:40 UTC

CVE ID :CVE-2026-32615 Published : March 31, 2026, 5:40 p.m. | 39 minutes ago Description :Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, ...

CVE-2026-32607 - Discourse: Stored XSS via unescaped assignee name

CVE Feed · CVE Feed · 2026-03-31 17:40 UTC

CVE ID :CVE-2026-32607 Published : March 31, 2026, 5:40 p.m. | 39 minutes ago Description :Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, ...

CVE-2026-32273 - Discourse: XSS on category description update via API

CVE Feed · CVE Feed · 2026-03-31 17:39 UTC

CVE ID :CVE-2026-32273 Published : March 31, 2026, 5:39 p.m. | 39 minutes ago Description :Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, ...

CVE-2026-32143 - Discourse: Admin-only report can be exported by moderators

CVE Feed · CVE Feed · 2026-03-31 17:39 UTC

CVE ID :CVE-2026-32143 Published : March 31, 2026, 5:39 p.m. | 39 minutes ago Description :Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, ...

CVE-2026-32113 - Discourse: Open redirect via `sso_destination_url` cookie in `enter`

CVE Feed · CVE Feed · 2026-03-31 17:39 UTC

CVE ID :CVE-2026-32113 Published : March 31, 2026, 5:39 p.m. | 39 minutes ago Description :Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, ...

CVE-2026-33073 - discourse-subscriptions plugin leaking stripe API key in multisite environment

CVE Feed · CVE Feed · 2026-03-31 17:38 UTC

CVE ID :CVE-2026-33073 Published : March 31, 2026, 5:38 p.m. | 40 minutes ago Description :Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, ...

The US Military’s GPS Software Is an $8 Billion Mess

Feed: All Latest · Stephen Clark, Ars Technica · 2026-03-31 17:34 UTC

The GPS Next-Generation Operational Control System was due for completion in 2016. Ten years later, the software for controlling the military’s GPS satellites still doesn’t work.

SecuritySecurity / Security NewsScience / Space

OkCupid gave 3 million dating-app photos to facial recognition firm, FTC says

Ars Technica · Jon Brodkin · 2026-03-31 17:33 UTC

OkCupid and Match settle with Trump FTC, don't have to pay any financial penalty.

PolicymatchOKCupid

The Promise of 'Woke 2' Is Fueling a Leftist Fever Dream

Feed: All Latest · Miles Klee · 2026-03-31 17:32 UTC

Progressives are dreaming about a new political order that rights the wrongs of the Trump administration and the shortcomings of “Woke 1.” Does it have a shot?

CultureCulture / Digital Culture

CVE-2026-5206 - code-projects Simple Gym Management System Payment sql injection

CVE Feed · CVE Feed · 2026-03-31 17:30 UTC

CVE ID :CVE-2026-5206 Published : March 31, 2026, 5:30 p.m. | 49 minutes ago Description :A security vulnerability has been detected in code-projects Simple Gym Management System 1.0. This v...

Для управления стилером MaskGram используются Spotify и Chess[.]com

Xakep · Мария Нефёдова · 2026-03-31 17:30 UTC

Исследователи Solar 4RAYS (ГК «Солар») заметили, что хакеры скрывают адреса управляющих серверов стилера MaskGram в профилях Spotify и Chess[.]com. Вредонос использует технику Dead Drop Resolver (DDR)...

НовостиChess.comDead Drop ResolverInfostealerMalware

CVE-2026-2123 - Privilege escalation vulnerability in Operations Agent

CVE Feed · CVE Feed · 2026-03-31 17:18 UTC

CVE ID :CVE-2026-2123 Published : March 31, 2026, 5:18 p.m. | 1 hour ago Description :A security audit identified a privilege escalation vulnerability in Operations Agent( Severity: 8.6 | ...

CVE-2026-5205 - chatwoot Webhook API trigger.rb Trigger server-side request forgery

CVE Feed · CVE Feed · 2026-03-31 17:16 UTC

CVE ID :CVE-2026-5205 Published : March 31, 2026, 5:16 p.m. | 1 hour, 2 minutes ago Description :A vulnerability was identified in chatwoot up to 4.11.2. Affected by this vulnerability is th...

CVE-2026-34361 - HAPI FHIR: Unauthenticated SSRF via /loadIG Chains with startsWith() Credential Leak for Authentication Token Theft

CVE Feed · CVE Feed · 2026-03-31 17:16 UTC

CVE ID :CVE-2026-34361 Published : March 31, 2026, 5:16 p.m. | 1 hour, 2 minutes ago Description :HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperabil...

CVE-2026-24165 - NVIDIA BioNeMo Deserialization Vulnerability

CVE Feed · CVE Feed · 2026-03-31 17:16 UTC

CVE ID :CVE-2026-24165 Published : March 31, 2026, 5:16 p.m. | 1 hour, 2 minutes ago Description :NVIDIA BioNeMo contains a vulnerability where a user could cause a deserialization of untrus...

CVE-2026-34359 - HAPI FHIR: Authentication Credential Leakage via Improper URL Prefix Matching on HTTP Redirect in HAPI FHIR Core

CVE Feed · CVE Feed · 2026-03-31 17:16 UTC

CVE ID :CVE-2026-34359 Published : March 31, 2026, 5:16 p.m. | 1 hour, 2 minutes ago Description :HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperabil...

CVE-2026-24154 - NVIDIA Jetson Linux initrd Argument Injection Vulnerability

CVE Feed · CVE Feed · 2026-03-31 17:16 UTC

CVE ID :CVE-2026-24154 Published : March 31, 2026, 5:16 p.m. | 1 hour, 2 minutes ago Description :NVIDIA Jetson Linux has vulnerability in initrd, where an unprivileged attacker with physica...

This is my third Orion launch, but it feels totally different

Ars Technica · Eric Berger · 2026-03-31 17:09 UTC

The first two launches of Orion felt hollow, but NASA is finally on a better course.

FeaturesSpaceartemis Iartemis IIGateway

The threat to critical infrastructure has changed. Has your readiness?

Microsoft Security · Sherrod DeGrippo · 2026-03-31 17:00 UTC

Five facts critical infrastructure (CI) leaders need to act on in 2026, grounded in what Microsoft Threat Intelligence is observing across sectors right now. The post The threat to critical infrastruc...

Tesla Admits Its Robotaxis Are Sometimes Driven by Remote Humans

Feed: All Latest · Aarian Marshall · 2026-03-31 17:00 UTC

The electric-car maker says it happens rarely and at speeds below 10 mph. But the disclosure—in response to a US senator's questions—occasioned a call for more transparency.

GearGear / Gear News and Events

Whoop’s valuation just tripled to $10 billion

TechCrunch · Connie Loizos · 2026-03-31 16:58 UTC

The fitness tracking startup just closed a $575 million Series G with Cristiano Ronaldo and LeBron James among its investors. The obvious question looming over a round of this size at this valuation: ...

FundraisingHardwareStartupsfundraisingHealth

VRP 2025 Year in Review

Google Security Blog · Kimberly Samra · 2026-03-31 16:55 UTC

Posted by Dirk Göhmann, Tony Mendez, and the Vulnerability Rewards Program Team2025 marked a special year in the history of vulnerability rewards and bug bounty programs at Google: our 15th anniversar...

To-Do List Application In Vue.JS With Source Code

Source Code & Projects · Fabian Ros · 2026-03-31 16:51 UTC

Project: To-do list application in Vue.js with source code The to-do list application is developed using Vue.js and bootstrap. Talking […] The post To-Do List Application In Vue.JS With Source C...

JavaScript Projectsbootstrapvuejs

Pondurance MDR Essentials uses autonomous SOC to tackle AI-driven attacks

Help Net Security · Sinisa Markovic · 2026-03-31 16:39 UTC

Pondurance announced MDR Essentials, MDR Essentials, an MDR service providing an autonomous SOC that reduces the time from threat detection to containment by 90%. Threat actors today use AI to attack ...

Industry newsPondurance

The Best Time to Drink Coffee for Productivity (and When Not To)

Feed: All Latest · Matthew Korfhage · 2026-03-31 16:36 UTC

Caffeine is the original biohack for energy, focus, and alertness. But are you doing it wrong?

GearGear / How To and AdviceGear / Products / Home

Uber increases stake in WeRide as robotaxi partnership ramps up in Dubai

TechCrunch · Kirsten Korosec · 2026-03-31 16:26 UTC

Uber and WeRide have launched robotaxi operations without a human safety operator in Dubai as part of a broader expansion in the Middle East.

TransportationrobotaxiUberweride

Attack on axios software developer tool threatens widespread compromises

CyberScoop · mbracken · 2026-03-31 16:25 UTC

Researchers at numerous firms are sounding warnings about the supply-chain attack on an open-source project with 100 million weekly downloads. The post Attack on axios software developer tool threaten...

RansomwareJavascriptmalwaresupply chain attacks

CVE-2026-5087 - PAGI::Middleware::Session::Store::Cookie versions through 0.001003 for Perl generates random bytes insecurely

CVE Feed · CVE Feed · 2026-03-31 16:16 UTC

CVE ID :CVE-2026-5087 Published : March 31, 2026, 4:16 p.m. | 1 hour, 2 minutes ago Description :PAGI::Middleware::Session::Store::Cookie versions through 0.001003 for Perl generates random ...

CVE-2026-5203 - CMS Made Simple UserGuide Module XML Import class.UserGuideImporterExporter.php _copyFilesToFolder path traversal

CVE Feed · CVE Feed · 2026-03-31 16:16 UTC

CVE ID :CVE-2026-5203 Published : March 31, 2026, 4:16 p.m. | 1 hour, 2 minutes ago Description :A vulnerability was found in CMS Made Simple up to 2.2.22. This impacts the function _copyFil...

CVE-2026-5204 - Tenda CH22 Parameter webtypelibrary formWebTypeLibrary stack-based overflow

CVE Feed · CVE Feed · 2026-03-31 16:16 UTC

CVE ID :CVE-2026-5204 Published : March 31, 2026, 4:16 p.m. | 1 hour, 2 minutes ago Description :A vulnerability was determined in Tenda CH22 1.0.0.1. Affected is the function formWebTypeLib...

CVE-2026-34595 - Parse Server: LiveQuery protected-field guard bypass via array-like logical operator value

CVE Feed · CVE Feed · 2026-03-31 16:16 UTC

CVE ID :CVE-2026-34595 Published : March 31, 2026, 4:16 p.m. | 1 hour, 2 minutes ago Description :Parse Server is an open source backend that can be deployed to any infrastructure that can r...

CVE-2026-4818 - Some management operations on data streams are not properly restricted when user does not have the necessary privileges

CVE Feed · CVE Feed · 2026-03-31 16:16 UTC

CVE ID :CVE-2026-4818 Published : March 31, 2026, 4:16 p.m. | 1 hour, 2 minutes ago Description :In Search Guard FLX versions from 3.0.0 up to 4.0.1, there exists an issue which allows users...

CVE-2026-4819 - Search Guard audit logs can contain under certain conditions user credentials

CVE Feed · CVE Feed · 2026-03-31 16:16 UTC

CVE ID :CVE-2026-4819 Published : March 31, 2026, 4:16 p.m. | 1 hour, 2 minutes ago Description :In Search Guard FLX versions from 1.0.0 up to 4.0.1, the audit logging feature might log user...

CVE-2026-34240 - jose vulnerable to untrusted JWK header key acceptance during signature verification

CVE Feed · CVE Feed · 2026-03-31 16:16 UTC

CVE ID :CVE-2026-34240 Published : March 31, 2026, 4:16 p.m. | 1 hour, 2 minutes ago Description :JOSE is a Javascript Object Signing and Encryption (JOSE) library. Prior to version 0.3.5+1,...

CVE-2026-34243 - wenxian: Command Injection in GitHub Actions Workflow via `issue_comment.body`

CVE Feed · CVE Feed · 2026-03-31 16:16 UTC

CVE ID :CVE-2026-34243 Published : March 31, 2026, 4:16 p.m. | 1 hour, 2 minutes ago Description :wenxian is a tool to generate BIBTEX files from given identifiers (DOI, PMID, arXiv ID, or p...

CVE-2026-34573 - Parse Server: GraphQL complexity validator exponential fragment traversal DoS

CVE Feed · CVE Feed · 2026-03-31 16:16 UTC

CVE ID :CVE-2026-34573 Published : March 31, 2026, 4:16 p.m. | 1 hour, 2 minutes ago Description :Parse Server is an open source backend that can be deployed to any infrastructure that can r...

CVE-2026-34221 - MikroORM has Prototype Pollution in Utils.merge

CVE Feed · CVE Feed · 2026-03-31 16:16 UTC

CVE ID :CVE-2026-34221 Published : March 31, 2026, 4:16 p.m. | 1 hour, 2 minutes ago Description :MikroORM is a TypeScript ORM for Node.js based on Data Mapper, Unit of Work and Identity Map...

CVE-2026-34227 - Sliver One-Click Remote Access: Insecure CORS & Unauthenticated MCP Interface

CVE Feed · CVE Feed · 2026-03-31 16:16 UTC

CVE ID :CVE-2026-34227 Published : March 31, 2026, 4:16 p.m. | 1 hour, 2 minutes ago Description :Sliver is a command and control framework that uses a custom Wireguard netstack. Prior to ve...

CVE-2026-34231 - Slippers: Cross-Site Scripting (XSS) in `attrs` Template Tag

CVE Feed · CVE Feed · 2026-03-31 16:16 UTC

CVE ID :CVE-2026-34231 Published : March 31, 2026, 4:16 p.m. | 1 hour, 2 minutes ago Description :Slippers is a UI component framework for Django. Prior to version 0.6.3, a Cross-Site Script...

CVE-2026-34235 - PJSIP: Heap OOB read in VPX unpacketizer

CVE Feed · CVE Feed · 2026-03-31 16:16 UTC

CVE ID :CVE-2026-34235 Published : March 31, 2026, 4:16 p.m. | 1 hour, 2 minutes ago Description :PJSIP is a free and open source multimedia communication library written in C. Prior to vers...

CVE-2026-34220 - MikroORM is vulnerable to SQL Injection via specially crafted object

CVE Feed · CVE Feed · 2026-03-31 16:16 UTC

CVE ID :CVE-2026-34220 Published : March 31, 2026, 4:16 p.m. | 1 hour, 2 minutes ago Description :MikroORM is a TypeScript ORM for Node.js based on Data Mapper, Unit of Work and Identity Map...

CVE-2026-34237 - MCP Java SDK has a Hardcoded Wildcard CORS (Access-Control-Allow-Origin: *)

CVE Feed · CVE Feed · 2026-03-31 16:16 UTC

CVE ID :CVE-2026-34237 Published : March 31, 2026, 4:16 p.m. | 1 hour, 2 minutes ago Description :MCP Java SDK is the official Java SDK for Model Context Protocol servers and clients. Prior ...

CVE-2026-34218 - ClearanceKit: Managed and user-defined policy rules not enforced between opfilter start and first policy modification

CVE Feed · CVE Feed · 2026-03-31 16:16 UTC

CVE ID :CVE-2026-34218 Published : March 31, 2026, 4:16 p.m. | 34 minutes ago Description :ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies...

CVE-2026-34219 - libp2p-gossipsub: Gossipsub PRUNE Backoff Heartbeat Instant Overflow

CVE Feed · CVE Feed · 2026-03-31 16:16 UTC

CVE ID :CVE-2026-34219 Published : March 31, 2026, 4:16 p.m. | 34 minutes ago Description :libp2p-rust is the official rust language Implementation of the libp2p networking stack. Prior to v...

CVE-2026-30284 - Voice Recorder File Overwrite Arbitrary Code Execution

CVE Feed · CVE Feed · 2026-03-31 16:16 UTC

CVE ID :CVE-2026-30284 Published : March 31, 2026, 4:16 p.m. | 34 minutes ago Description :An arbitrary file overwrite vulnerability in UXGROUP LLC Voice Recorder v10.0 allows attackers to o...

Iran Warns US Tech Firms Could Become Targets as War Expands

Feed: All Latest · Dana Alomar · 2026-03-31 16:15 UTC

Companies including Google, Microsoft, and Palantir were listed as targets by Iranian media as the conflict with Israel and the US spills into digital infrastructure.

BusinessBusiness / Big Tech

AWS Security Agent on-demand penetration testing now generally available

AWS Security · Ayush Singh · 2026-03-31 16:13 UTC

AWS Security Agent on-demand penetration testing is now generally available, enabling you to run comprehensive security tests across all your applications, not only your most critical ones. This miles...

Security, Identity, & Compliance

UK watchdog targets Microsoft licensing in cloud competition probe

The Register · Dan Robinson · 2026-03-31 16:12 UTC

CMA to assess whether the company's terms unfairly favor Azure over rival platforms The UK's competition watchdog will investigate Microsoft's business software ecosystem over concerns that its licens...

Axios Hijacked: npm Account Takeover Deploys Cross-Platform RAT to Millions

Security Boulevard · Omer Guetta · 2026-03-31 16:10 UTC

Axios Hijacked: npm Account Takeover Deploys Cross-Platform RAT to Millions The post Axios Hijacked: npm Account Takeover Deploys Cross-Platform RAT to Millions appeared first on Security Boulevard.

Security Bloggers NetworkAI in CybersecurityAppSecLegitthreats

Costco sued for seeking refunds on tariffs customers paid

Ars Technica · Ashley Belanger · 2026-03-31 16:09 UTC

Proposed class action accuses Costco of unjust enrichment.

PolicyCostcoDonald Trumpieepa tariffstariff refunds

TrueConf Zero-Day Exploited in Attacks on Southeast Asian Government Networks

The Hacker News · Ravie Lakshmanan · 2026-03-31 16:03 UTC

A high-severity security flaw in the TrueConf client video conferencing software has been exploited in the wild as a zero-day as part of a campaign targeting government entities in Southeast Asia dubb...

North Korean hackers blamed for hijacking popular Axios open-source project to spread malware

TechCrunch · Lorenzo Franceschi-Bicchierai · 2026-03-31 16:01 UTC

A hacker inserted malware in Axios, an open-source web tool downloaded tens of millions of times weekly, in a widespread hack.

Securityaxioscybercrimecybersecurityhackers

Amazon sends AI agents into pen testing and DevOps

Help Net Security · Sinisa Markovic · 2026-03-31 16:00 UTC

Amazon’s latest AI capabilities bring on-demand penetration testing through the AWS Security Agent, alongside the AWS DevOps Agent. “These agents are changing the way we secure and operate softw...

Newsagentic AIArtificial intelligenceAWScybersecurity

New personal health coach features are coming to Fitbit.

The Keyword · The Keyword · 2026-03-31 16:00 UTC

Fitbit adds cycle, mental wellbeing & nutrition tools in Public Preview. Now available for those without a Premium membership.

Fitbit

Build with Veo 3.1 Lite, our most cost-effective video generation model

The Keyword · The Keyword · 2026-03-31 16:00 UTC

Veo 3.1 Lite is now available in paid preview through the Gemini API and for testing in Google AI Studio.

Developer toolsAI

Applying security fundamentals to AI: Practical advice for CISOs

Microsoft Security · Yonatan Zunger · 2026-03-31 16:00 UTC

Read actionable advice for CISOs on securing AI, managing risk, and applying core security principles in today’s AI‑powered environment. The post Applying security fundamentals to AI: Practical advice...

Censys Raises $70 Million for Internet Intelligence Platform

SecurityWeek · Eduard Kovacs · 2026-03-31 15:59 UTC

The latest funding round brings the total venture capital investment in Censys to $149 million. The post Censys Raises $70 Million for Internet Intelligence Platform appeared first on SecurityWeek.

Cybersecurity FundingCensysfunding

SecWiki News 2026-03-31 Review

SecWiki · SecWiki · 2026-03-31 15:58 UTC

SecWiki周刊(第630期) by ourrenLeakBase围剿复盘 by ourren更多最新文章,请访问SecWiki

FedEx chooses partnerships over proprietary tech for its automation strategy

TechCrunch · Rebecca Szkutak · 2026-03-31 15:46 UTC

FedEx recently announced a partnership with Berkshire Gray as the company works with external players to develop its automation tech.

EnterpriseRoboticsAurora InnovationAutomationfedex

Novos Fascículos sobre Golpes

CERT Brazil · CERT.br · 2026-03-31 15:45 UTC

Novos Fascículos da Cartilha de Segurança para Internet Fascículo Golpes: Não se Deixe Enganar Golpistas estão sempre criando novos truques para enganar e tirar vantagem, v...

Latest Xloader Obfuscation Methods and Network Protocol

Security Boulevard · ThreatLabz (Zscaler) · 2026-03-31 15:42 UTC

Introduction Xloader is an information stealing malware family that evolved from Formbook and targets web browsers, email clients, and File Transfer Protocol (FTP) applications. Additionally, Xloader ...

Security Bloggers Network

Beyond the Spectacle – RSAC 2026 and The 5 Layers of AI Security – FireTail Blog

Security Boulevard · FireTail - AI and API Security Blog · 2026-03-31 15:39 UTC

Mar 31, 2026 - Jeremy Snyder - If you were at RSA Conference last year, you probably remember the goats. Or the puppies. Or the miniature petting zoos. It was a year of "over-the-top" spectacle. A bit...

Security Bloggers Network

美国军人向脱衣舞女泄露部署计划 — US military leaks deployment plans to strippers

Weibo Hot Search · Weibo · 2026-03-31 15:37 UTC

Weibo Hot Search · 336K views · new · +100% velocity

Weibo Hot SearchChina

Rethinking Vulnerability Management Strategies for Mid-Market Security

Dark Reading · Terry Sweeney · 2026-03-31 15:35 UTC

Intruder's Chris Wallis argues mid-market teams should prioritize CVE remediation speed over vulnerability counts, while expanding defenses beyond CVEs to include attack surface management.

The Next Cybersecurity Crisis Isn’t Breaches—It’s Data You Can’t Trust

SecurityWeek · Steve Durbin · 2026-03-31 15:35 UTC

Data integrity shouldn’t be seen only through the prism of a technical concern but also as a leadership issue. The post The Next Cybersecurity Crisis Isn’t Breaches—It’s Data You Can’t Trust appeared...

Data Protectiondata protection

Lumina Gray App Using HTML, CSS, and JavaScript with Source Code

SourceCodester - Visual Basic, VB.NET, C#, PHP/MySQL, C/C++, Java/JavaScript, ASP/ASP.NET, MS Access, FoxPro, SQL · razormist · 2026-03-31 15:31 UTC

Lumina Gray App Using HTML, CSS, and JavaScript with Source Code razormist Tue, 03/31/2026 - 23:31

Apple добавляет предупреждение о ClickFix-атаках в терминал macOS

Xakep · Мария Нефёдова · 2026-03-31 15:30 UTC

Разработчики Apple добавили в macOS Tahoe 26.4 защитный механизм, который блокирует вставку и выполнение потенциально опасных команд в терминале. Нововведение направлено против атак типа ClickFix — по...

НовостиAppleClickFixmacOSЗащита

AI and Quantum Are Forcing a Rethink of Digital Trust

Dark Reading · Terry Sweeney · 2026-03-31 15:29 UTC

In a conversation with Dark Reading’s Terry Sweeney, DigiCert CEO Amit Sinha explains how AI-driven identities and quantum threats are reshaping the foundations of digital trust.

Codenotary AgentMon monitors agentic AI activity and behavior

Help Net Security · Industry News · 2026-03-31 15:22 UTC

Codenotary launched AgentMon, an enterprise-grade monitoring designed specifically for agentic networks, providing organizations with real-time visibility into the security, performance and cost of AI...

Industry newsCodenotary

Whack a Mole Game Using Tkinter in Python with Source Code

SourceCodester - Visual Basic, VB.NET, C#, PHP/MySQL, C/C++, Java/JavaScript, ASP/ASP.NET, MS Access, FoxPro, SQL · razormist · 2026-03-31 15:21 UTC

Whack a Mole Game Using Tkinter in Python with Source Code razormist Tue, 03/31/2026 - 23:21

Stolen Logins Are Fueling Everything From Ransomware to Nation-State Cyberattacks

SecurityWeek · Kevin Townsend · 2026-03-31 15:04 UTC

Report shows how industrialized credential theft underpins ransomware, SaaS breaches, and geopolitical attacks, shifting security focus from prevention to detecting misuse of legitimate access. The po...

CybercrimeIdentity & Accesscredentialsidentitymalware

DoControl provides security coverage for Google Gemini Gems

Help Net Security · Industry News · 2026-03-31 15:03 UTC

DoControl announced new capabilities that provide visibility, monitoring, and automated control for Google Gemini Gems, a newly introduced feature within Google Gemini that enables teams to create cus...

Industry newsDoControl

What's the best cabin layout for aircraft evacuation?

Ars Technica · Jennifer Ouellette · 2026-03-31 15:00 UTC

The key is to evenly distribute elderly passengers, who move more slowly, among the aircraft cabins.

Scienceair safetyair travelaircraftComputer simulations

GenAI Security Project ramps up guidance

ReversingLabs · John P. Mello Jr. · 2026-03-31 15:00 UTC

With AI ramping up risk, OWASP stepped up its project to help AppSec teams get up to speed — and take action.

AppSec & Supply Chain Security

Nomadic raises $8.4 million to wrangle the data pouring off autonomous vehicles

TechCrunch · Tim Fernholz · 2026-03-31 15:00 UTC

The company turns footage from robots into structured, searchable datasets with a deep learning model.

AIRoboticsStartupsExclusivenomadic

BSidesSLC 2025 – Considering Cloud Coverage In SIEM/XDR Design

Security Boulevard · Marc Handelman · 2026-03-31 15:00 UTC

Author, Creator & Presenter: Chris Beckman - Principal Security Engineer at TaxBit Our thanks to BSidesSLC for publishing their Creators, Authors and Presenter’s outstanding BSidesSLC 2025 conten...

Network SecuritySecurity Bloggers Networkappsec educationBSidesSLCcybersecurity education

ServiceNow allegedly says salesman 'overachieved' and is not entitled to comp

The Register · O'Ryan Johnson · 2026-03-31 14:55 UTC

The 13-year sales vet closed two deals worth $27 million, but ServiceNow has “nullified” his compensation saying he “overachieved” his quota. ServiceNow is refusing to pay a salesman commissions on mo...

Axios supply chain attack chops away at npm trust

Malwarebytes Labs · Malwarebytes Labs · 2026-03-31 14:53 UTC

Developers using the axios package from npm may have downloaded a malicous version that drops a Remote Access Trojan

News axios supply chain

Axios supply chain attack chops away at npm trust

Security Boulevard · Malwarebytes · 2026-03-31 14:53 UTC

Developers using the axios package from npm may have downloaded a malicous version that drops a Remote Access Trojan The post Axios supply chain attack chops away at npm trust appeared first on Securi...

Security Bloggers NetworkAxiosSBN Newssupply chain

Venom Stealer Raises Stakes With Continuous Credential Harvesting

SecurityWeek · Kevin Townsend · 2026-03-31 14:51 UTC

Licensed malware with built-in persistence and automation enables attackers to continuously siphon credentials, session data, and cryptocurrency assets. The post Venom Stealer Raises Stakes With Conti...

Malware & Threats

Health data giant CareCloud says hackers accessed patients’ medical records

TechCrunch · Zack Whittaker · 2026-03-31 14:50 UTC

CareCloud, a major provider of medical records storage, said hackers accessed one of its repositories of patient data earlier in March. It provides technology for more than 45,000 providers covering m...

Securitycarecloudcyberattackcybersecuritydata breach

EvilTokens ramps up device code phishing targeting Microsoft 365 users

Help Net Security · Zeljka Zorz · 2026-03-31 14:46 UTC

Security researchers report a notable increase in device code phishing activity aimed at Microsoft 365 users, and have attributed this rise to the availability of EvilTokens, a new, specialized phishi...

Don't missHot stuffNewsaccount hijackingBEC scams

CVE-2026-34532 - Parse Server: Cloud function validator bypass via prototype chain traversal

CVE Feed · CVE Feed · 2026-03-31 14:42 UTC

CVE ID :CVE-2026-34532 Published : March 31, 2026, 2:42 p.m. | 37 minutes ago Description :Parse Server is an open source backend that can be deployed to any infrastructure that can run Node...

CVE-2026-4799 - Open redirect vulnerability in Search Guard Kibana Plugin via manipulated requests

CVE Feed · CVE Feed · 2026-03-31 14:41 UTC

CVE ID :CVE-2026-4799 Published : March 31, 2026, 2:41 p.m. | 38 minutes ago Description :In Search Guard FLX up to version 4.0.1, it is possible to use specially crafted requests to redirec...

CVE-2026-34373 - Parse Server: GraphQL API endpoint ignores CORS origin restriction

CVE Feed · CVE Feed · 2026-03-31 14:38 UTC

CVE ID :CVE-2026-34373 Published : March 31, 2026, 2:38 p.m. | 40 minutes ago Description :Parse Server is an open source backend that can be deployed to any infrastructure that can run Node...

CVE-2026-34363 - Parse Server: LiveQuery protected field leak via shared mutable state across concurrent subscribers

CVE Feed · CVE Feed · 2026-03-31 14:35 UTC

CVE ID :CVE-2026-34363 Published : March 31, 2026, 2:35 p.m. | 43 minutes ago Description :Parse Server is an open source backend that can be deployed to any infrastructure that can run Node...

Rivian spinoff Also will build autonomous delivery vehicles for DoorDash

TechCrunch · Sean O'Kane · 2026-03-31 14:32 UTC

DoorDash joins Greenoaks Capital in another $200 million funding round for Also, bringing its total funding to more than $500 million.

Transportationalsoautonomous delivery vehiclesautonomous vehiclesDoorDash

In a Big Reversal, Zohran Mamdani Tells NYC Agencies They Can Use TikTok

Feed: All Latest · Makena Kelly · 2026-03-31 14:30 UTC

The city will allow agencies to return to TikTok, but with strict new device and security rules.

PoliticsPolitics / Politics News

Foxit flags hidden security risks in PDFs with new tool

Help Net Security · Industry News · 2026-03-31 14:26 UTC

Foxit Software introduced a new capability designed to uncover hidden security risks inside PDFs as part of its latest PDF Editor 2026.1 release for Windows and macOS. The update is led by PDF Action ...

Industry newsFoxit

After more than 53 years, humans may finally return to the Moon this week

Ars Technica · Stephen Clark · 2026-03-31 14:25 UTC

"Things are certainly starting to feel real here at the Cape."

ScienceSpaceartemisartemis IIhuman spaceflight

CVE-2026-0596 - Command Injection in mlflow/mlflow

CVE Feed · CVE Feed · 2026-03-31 14:25 UTC

CVE ID :CVE-2026-0596 Published : March 31, 2026, 2:25 p.m. | 53 minutes ago Description :A command injection vulnerability exists in mlflow/mlflow when serving a model with `enable_mlserver...

CVE-2026-34224 - Parse Server: MFA single-use token bypass via concurrent authData login requests

CVE Feed · CVE Feed · 2026-03-31 14:25 UTC

CVE ID :CVE-2026-34224 Published : March 31, 2026, 2:25 p.m. | 53 minutes ago Description :Parse Server is an open source backend that can be deployed to any infrastructure that can run Node...

New criminal service plans to monetize data stolen by ransomware gangs

The Record · The Record · 2026-03-31 14:25 UTC

A site called Leak Bazaar pitches itself as something closer to a data-processing business than a typical hacking or ransomware-as-a-service operation.

CybercrimeNewsTechnology

Synthetic Data and GDPR Compliance

Security Boulevard · Irina · 2026-03-31 14:24 UTC

The post <b>Synthetic Data and GDPR Compliance</b> appeared first on Sovy. The post Synthetic Data and GDPR Compliance appeared first on Security Boulevard.

Security Bloggers Networkdata protection officerData security and privacy

Roku launches a standalone app for Howdy, its $2.99 streaming service

TechCrunch · Aisha Malik · 2026-03-31 14:23 UTC

With this new app, Roku says subscribers can access Howdy's library of content on the go.

AppsMedia & EntertainmentHowdyrokustreaming services

CVE-2026-34156 - NocoBase Affected by Sandbox Escape to RCE via console._stdout Prototype Chain Traversal in Workflow Script Node

CVE Feed · CVE Feed · 2026-03-31 14:16 UTC

CVE ID :CVE-2026-34156 Published : March 31, 2026, 2:16 p.m. | 1 hour, 2 minutes ago Description :NocoBase is an AI-powered no-code/low-code platform for building business applications and e...

CVE-2026-3308 - CVE-2026-3308

CVE Feed · CVE Feed · 2026-03-31 14:16 UTC

CVE ID :CVE-2026-3308 Published : March 31, 2026, 2:16 p.m. | 1 hour, 2 minutes ago Description :An integer overflow vulnerability in 'pdf-image.c' in Artifex's MuPDF version 1.27.0 allows a...

CVE-2026-34155 - RAUC: Improper Signing of Plain Bundles Exceeding 2 GiB

CVE Feed · CVE Feed · 2026-03-31 14:16 UTC

CVE ID :CVE-2026-34155 Published : March 31, 2026, 2:16 p.m. | 1 hour, 2 minutes ago Description :RAUC controls the update process on embedded Linux systems. Prior to version 1.15.2, RAUC bu...

Meta launches two new Ray-Ban glasses designed for prescription wearers

TechCrunch · Aisha Malik · 2026-03-31 14:15 UTC

Meta says these glasses are the most comfortable ones it has ever designed, as they're made for all-day comfort.

HardwareMetaray-ban metaSMART Glasses

CVE-2026-34214 - Trino: Iceberg REST catalog static and vended credentials are accessible via query JSON

CVE Feed · CVE Feed · 2026-03-31 14:14 UTC

CVE ID :CVE-2026-34214 Published : March 31, 2026, 2:14 p.m. | 1 hour, 4 minutes ago Description :Trino is a distributed SQL query engine for big data analytics. From version 439 to before v...

Panera’s 5.1 Million User Breach: When ‘No Hack’ Becomes a Ransomware Business Model

Security Boulevard · Deepak Gupta - Tech Entrepreneur, Cybersecurity Author · 2026-03-31 14:13 UTC

ShinyHunters leaked 5.1M Panera accounts after extortion failed. Contact data can't be changed like passwords—it's permanent exposure fueling years of scams. The post Panera’s 5.1 Million User B...

Data SecuritySecurity Bloggers NetworkThreats & BreachesBreachcustomer data

How DataDome Blocked an 80M-Request Scraping Attack on a Leading Review Platform

Security Boulevard · Jérôme Segura · 2026-03-31 14:11 UTC

DataDome stopped a 13-day, 80M-request scraping attack targeting a leading review platform. See how we blocked this attack with no friction for real users. The post How DataDome Blocked an 80M-Request...

Security Bloggers Networkbot managementScrapingThreat Research

No more Chinese Polestar 3s as production shifts entirely to the US

Ars Technica · Jonathan M. Gitlin · 2026-03-31 14:11 UTC

Building the big electric SUV at two sites doesn't make sense anymore.

CarsPolestarvolvo

CVE-2026-34209 - mppx: Tempo has a session close voucher bypass vulnerability due to settled amount equality

CVE Feed · CVE Feed · 2026-03-31 14:10 UTC

CVE ID :CVE-2026-34209 Published : March 31, 2026, 2:10 p.m. | 1 hour, 8 minutes ago Description :mppx is a TypeScript interface for machine payments protocol. Prior to version 0.4.11, the t...

CVE-2026-34504 - OpenClaw < 2026.3.28 - Server-Side Request Forgery via Unguarded Image Download in fal Provider

CVE Feed · CVE Feed · 2026-03-31 14:10 UTC

CVE ID :CVE-2026-34504 Published : March 31, 2026, 2:10 p.m. | 1 hour, 8 minutes ago Description :OpenClaw before 2026.3.28 contains a server-side request forgery vulnerability in the fal pr...

CVE-2026-34503 - OpenClaw < 2026.3.28 - Incomplete WebSocket Session Termination on Device Removal and Token Revocation

CVE Feed · CVE Feed · 2026-03-31 14:10 UTC

CVE ID :CVE-2026-34503 Published : March 31, 2026, 2:10 p.m. | 1 hour, 8 minutes ago Description :OpenClaw before 2026.3.28 fails to disconnect active WebSocket sessions when devices are rem...

CVE-2026-33580 - OpenClaw < 2026.3.28 - Brute Force Attack via Missing Rate Limiting on Webhook Shared Secret Authentication

CVE Feed · CVE Feed · 2026-03-31 14:10 UTC

CVE ID :CVE-2026-33580 Published : March 31, 2026, 2:10 p.m. | 1 hour, 8 minutes ago Description :OpenClaw before 2026.3.28 contains a missing rate limiting vulnerability in the Nextcloud Ta...

CVE-2026-33581 - OpenClaw < 2026.3.24 - Arbitrary File Read via mediaUrl and fileUrl Parameters

CVE Feed · CVE Feed · 2026-03-31 14:10 UTC

CVE ID :CVE-2026-33581 Published : March 31, 2026, 2:10 p.m. | 1 hour, 8 minutes ago Description :OpenClaw before 2026.3.24 contains a sandbox bypass vulnerability in the message tool that a...

CVE-2026-33579 - OpenClaw < 2026.3.28 - Privilege Escalation via Missing Caller Scope Validation in Device Pair Approval

CVE Feed · CVE Feed · 2026-03-31 14:10 UTC

CVE ID :CVE-2026-33579 Published : March 31, 2026, 2:10 p.m. | 1 hour, 8 minutes ago Description :OpenClaw before 2026.3.28 contains a privilege escalation vulnerability in the /pair approve...

CVE-2026-33578 - OpenClaw < 2026.3.28 - Sender Policy Allowlist Bypass via Policy Downgrade in Google Chat and Zalouser Extensions

CVE Feed · CVE Feed · 2026-03-31 14:10 UTC

CVE ID :CVE-2026-33578 Published : March 31, 2026, 2:10 p.m. | 1 hour, 8 minutes ago Description :OpenClaw before 2026.3.28 contains a sender policy bypass vulnerability in the Google Chat a...

CVE-2026-33576 - OpenClaw < 2026.3.28 - Unauthorized Media Download via Zalo Channel

CVE Feed · CVE Feed · 2026-03-31 14:10 UTC

CVE ID :CVE-2026-33576 Published : March 31, 2026, 2:10 p.m. | 1 hour, 8 minutes ago Description :OpenClaw before 2026.3.28 downloads and stores inbound media from Zalo channels before valid...

CVE-2026-34210 - mppx has Stripe charge credential replay via missing idempotency check

CVE Feed · CVE Feed · 2026-03-31 14:10 UTC

CVE ID :CVE-2026-34210 Published : March 31, 2026, 2:10 p.m. | 1 hour, 9 minutes ago Description :mppx is a TypeScript interface for machine payments protocol. Prior to version 0.4.11, the s...

CVE-2026-34377 - Zebra has a Consensus Failure due to Improper Verification of V5 Transactions

CVE Feed · CVE Feed · 2026-03-31 14:05 UTC

CVE ID :CVE-2026-34377 Published : March 31, 2026, 2:05 p.m. | 1 hour, 13 minutes ago Description :ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.0 and zebra-con...

El panorama descontrolado del "Estado de los Secretos"

Segu-Info · SeguInfo · 2026-03-31 14:04 UTC

La proliferación de secretos no se detiene: en 2025, se aceleró más de lo que la mayoría de los equipos de seguridad anticipaban. El informe "State of Secrets Sprawl 2026" de GitGuardian analizó...

CVE-2026-34202 - Zebra node crash — V5 transaction hash panic (P2P reachable)

CVE Feed · CVE Feed · 2026-03-31 14:02 UTC

CVE ID :CVE-2026-34202 Published : March 31, 2026, 2:02 p.m. | 1 hour, 16 minutes ago Description :ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.0 and zebra-cha...

How did Anthropic measure AI&#039;s "theoretical capabilities" in the job market?

Ars Technica · Kyle Orland · 2026-03-31 14:01 UTC

2023 study made a lot of assumptions about future "anticipated LLM-powered software."

AIAnthropicArtificial IntelligenceClaudeeconomy

Between AI Urgency and AI Fatigue at RSAC 2026

Security Boulevard · Dwayne McDaniel · 2026-03-31 14:00 UTC

AI was everywhere at RSAC 2026, but the real focus was operational security: managing agents, protecting secrets, and controlling trusted integrations at scale. The post Between AI Urgency and AI Fati...

EventsSecurity Bloggers NetworkConferences

How to Categorize AI Agents and Prioritize Risk

BleepingComputer · Sponsored by Token Security · 2026-03-31 14:00 UTC

AI agent risk isn't equal, it scales with access to systems and level of autonomy. Token Security explains how CISOs should categorize agents and prioritize what to secure first. [...]

Security

Exclusive: Runway launches $10M fund, Builders program to support early-stage AI startups

TechCrunch · Rebecca Bellan · 2026-03-31 14:00 UTC

Runway is launching a $10 million fund and startup program to back companies building with its AI video models, as it pushes toward interactive, real-time “video intelligence” applications.

AIStartupsVentureAI video generationExclusive

Aston Martin Valhalla (2026) Review: A $1 Million Plug-In Hybrid

Feed: All Latest · Jeremy White · 2026-03-31 14:00 UTC

A robot could apparently drive this million-dollar supercar faster than a fleshy human, but the unbelievable experience would be entirely lost on it.

GearGear / ReviewsGear / Products / Car Reviews

The company behind ClassPass and Mindbody just got a lot bigger with a $7.5B merger

TechCrunch · Lauren Forristal · 2026-03-31 14:00 UTC

The merger is a sign that the fitness industry is continuing to move toward consolidation to compete at a larger scale. Recent moves include MyFitnessPal acquiring Cal AI, an AI calorie counting app, ...

Biotech & HealthStartupsclasspassegymfitness

Nearly half a Million mobile customers of Lloyds Banking Group affected by security incident

Security Affairs · Pierluigi Paganini · 2026-03-31 13:58 UTC

Lloyds Banking Group data incident exposed transactions of ~450,000 mobile banking users due to a faulty update. A faulty software update at Lloyds Banking Group exposed transaction details of nearly ...

Breaking NewsData BreachMalwareSecurityHacking

Nearly half a Million mobile customers of Lloyds Banking Group affected by security incident

Security Affairs · Pierluigi Paganini · 2026-03-31 13:58 UTC

Lloyds Banking Group data incident exposed transactions of ~450,000 mobile banking users due to a faulty update. A faulty software update at Lloyds Banking Group exposed transaction details of nearly ...

Breaking NewsData BreachMalwareSecurityHacking

Hacker stripped more than $50 million from Uranium crypto exchange, spent it on trading cards

Help Net Security · Sinisa Markovic · 2026-03-31 13:58 UTC

US prosecutors have charged a Maryland man in connection with two hacks of the Uranium Finance cryptocurrency exchange that led to losses exceeding $50 million. Jonathan Spalletta, also known as “Cthu...

Newscryptocurrencycybercrimelaw enforcementscams

CVE-2026-34200 - Nhost CLI MCP Server: Missing Inbound Authentication on Explicitly Bound Network Port

CVE Feed · CVE Feed · 2026-03-31 13:57 UTC

CVE ID :CVE-2026-34200 Published : March 31, 2026, 1:57 p.m. | 1 hour, 21 minutes ago Description :Nhost is an open source Firebase alternative with GraphQL. Prior to version 1.41.0, The Nho...

TeamPCP Moves From OSS to AWS Environments

SecurityWeek · Ionut Arghire · 2026-03-31 13:53 UTC

After validating stolen credentials using TruffleHog, the hacking group started AWS services enumeration and lateral movement activities. The post TeamPCP Moves From OSS to AWS Environments appeared f...

Application SecurityCloud SecurityAWSsupply chain attackTeamPCP

Hackers compromise Axios npm package to drop cross-platform malware

BleepingComputer · Bill Toulas · 2026-03-31 13:53 UTC

Hackers hijacked the npm account of the Axios package, a JavaScript HTTP client with 100M+ weekly downloads, to deliver remote access trojans to Linux, Windows, and macOS systems. [...]

Security

CVE-2026-20915 - Stored cross-site scripting in Pending Changes sidebar

CVE Feed · CVE Feed · 2026-03-31 13:51 UTC

CVE ID :CVE-2026-20915 Published : March 31, 2026, 1:51 p.m. | 1 hour, 28 minutes ago Description :Stored cross-site scripting (XSS) in Checkmk version 2.5.0 (beta) before 2.5.0b2 allows aut...

Hackers Poison Axios npm Package with 100 Million Weekly Downloads

HackRead · Deeba Ahmed · 2026-03-31 13:49 UTC

Axios npm Package compromised in a supply chain attack, exposing developers to malware, data theft, and full system takeover risks worldwide.

SecurityMalwareAxiosCyber AttackCybersecurity

Axios NPM Packages Compromised in Active Supply Chain Attack

CyberPress · AnuPriya · 2026-03-31 13:46 UTC

A severe and sophisticated supply chain attack has struck the widely used Axios HTTP client on the npm registry, exposing millions of developers worldwide to a cross-platform remote access trojan (RAT...

Cyber AttackCyber Security NewsCybersecurity

Raspberry Pi leans into semiconductors as sales climb – especially in US and China

The Register · Richard Speed · 2026-03-31 13:45 UTC

Chip shipments overtake boards and modules as industrial demand grows, raising questions about hobbyist roots Raspberry Pi has reported impressive revenue and profit growth, but its hobbyist origins r...

WhatsApp malware campaign delivers VBScript and MSI backdoors

Microsoft Security · Microsoft Defender Security Research Team · 2026-03-31 13:43 UTC

A malware campaign uses WhatsApp messages to deliver VBS scripts that initiate a multi-stage infection chain. The attack leverages renamed Windows tools and cloud-hosted payloads to install MSI backdo...

Windows

The Broken System That Keeps Shipping Crews Stranded in the Strait of Hormuz

Feed: All Latest · Ruchi Kumar · 2026-03-31 13:38 UTC

Vessels are increasingly being abandoned during the war on Iran, revealing a hidden failure in the global systems that keep goods—and people—moving.

SecuritySecurity / Security News

Iran&#039;s hackers are on the offensive against the US and Israel

Ars Technica · Jacob Judah, Financial Times · 2026-03-31 13:37 UTC

Tehran hopes to stoke fear and extract intel in a series of cyber attacks.

SecuritycybersecurityhackingUSA-Iran War

CrewAI Vulnerabilities Expose Devices to Hacking

SecurityWeek · Ionut Arghire · 2026-03-31 13:37 UTC

Attackers can exploit the bugs through prompt injection, chaining them together to escape the sandbox and execute arbitrary code. The post CrewAI Vulnerabilities Expose Devices to Hacking appeared fir...

Artificial IntelligenceAICrewAIvulnerability

US Treasury Weighs Cyber Insurance Backstop

Bank Info Security · 2026-03-31 13:33 UTC
Bank Info Security

Iran Deploys 'Pseudo-Ransomware,' Revives Pay2Key Operations

Dark Reading · Elizabeth Montalbano · 2026-03-31 13:31 UTC

Iranian APTs are blurring the lines between state-sponsored and cybercriminal activities to target high-impact US organizations.

Закрытый контур без боли для разработчиков — миф или реальность?

Habr InfoSec · abarykov (MOEX) · 2026-03-31 13:31 UTC

Всем привет! Меня зовут Александр Барыков, я руковожу платформенной командой DevOps и являюсь лидером DevOps-комьюнити в нашей компании.Сегодня хочу поделиться опытом, который мы накопили за последние...

devopsdevsecopsинформационная безопасностьпроверка подлинностиsandbox

New Bitdefender assessment helps organizations identify and eliminate hidden internal attack paths

Help Net Security · Industry News · 2026-03-31 13:30 UTC

Bitdefender has announced the Bitdefender Internal Attack Surface Assessment, a complimentary evaluation that helps organizations identify and reduce hidden internal cyber risks caused by unnecessary ...

Industry newsBitdefender

MEGANews. Cамые важные события в мире инфосека за март

Xakep · Мария Нефёдова · 2026-03-31 13:30 UTC

В этом месяце: исследователи изучили сторонние клиенты Telegram; группировка TeamPCP скомпрометировала сканер Trivy, ИБ‑компанию Checkmarx и библиотеку LiteLLM; в Android ограничат доступ к Accessibil...

НовостиAndroidCheckmarxLeakBaseLiteLLM

Seqrite Uncovers Operation CamelClone: Multi-Region Espionage Campaign Targeting Government and Defense Amidst Geopolitical Tensions

Malware · 2026-03-31 13:28 UTC
Malware

PNG Vulnerabilities Allow Attackers to Crash Systems and Leak Sensitive Data

CyberPress · AnuPriya · 2026-03-31 13:27 UTC

Security researchers have disclosed two high-severity vulnerabilities in libpng, the widely deployed reference library used for processing Portable Network Graphics (PNG) image files. These critical f...

Cyber Security NewsCybersecurityVulnerability

Waymo starts robotaxi services at San Antonio International Airport

TechCrunch · Sean O'Kane · 2026-03-31 13:25 UTC

It's the fourth major airport Waymo is serving, adding to Phoenix Sky Harbor, San Francisco, and San Jose international airports.

Transportationautonomous vehiclesavsrobotaxiWaymo

Skadliga versioner av Axios JavaScript-bibliotek

CERT Sweden · CERT-SE · 2026-03-31 13:22 UTC

StepSecurity informerar om ett skadligt Axios JavaScript-bibliotek som funnits tillgängligt för nedladdning via NPM. [1] Enligt Socradar rör det sig om uppskattningsvis knappt tre timmar innan det tog...

Operation TrueChaos: 0-Day Exploitation Against Southeast Asian Government Targets

Check Point Research · stcpresearch · 2026-03-31 13:16 UTC

Key Points Introduction At the beginning of 2026, Check Point Research observed a series of targeted attacks against government entities in Southeast Asia carried out via a legitimate TrueConf softwar...

Check Point Research Publications

[Перевод] Запрет роутеров в США: объясняем ситуацию

Habr InfoSec · Den_ok · 2026-03-31 13:16 UTC

Пытаемся найти логику в очередном наезде Трампа и Карра на иностранные гаджеты.Вы наверняка слышали: правительство США запретило потребительские Wi-Fi роутеры иностранного производства из-за «угроз на...

роутерысша

Speechify&#8217;s Windows app uses local models for transcription and dictation

TechCrunch · Ivan Mehta · 2026-03-31 13:11 UTC

Speechify just launched a native Windows app that employs locally stored models to enable dictation and transcription across apps.

AppsSpeechifyvoice AIWindows

Vertex AI Vulnerability Exposes Google Cloud Data and Private Artifacts

The Hacker News · Ravie Lakshmanan · 2026-03-31 13:09 UTC

Cybersecurity researchers have disclosed a security "blind spot" in Google Cloud's Vertex AI platform that could allow artificial intelligence (AI) agents to be weaponized by an attacker to gain unaut...

Sevii Redefines Cybersecurity at RSAC 2026, Winning Multiple Global InfoSec Awards for Autonomous Defense & Remediation

Cybersecurity · 2026-03-31 13:07 UTC
Cybersecurity

CISA tells federal agencies to patch Citrix NetScaler bug by Thursday

The Record · The Record · 2026-03-31 13:04 UTC

The bug enables threat actors to send requests that disclose sensitive information and carries a severity score of 9.3 out of 10, indicating a critical risk.

CybercrimeNewsNews BriefsTechnology

ChatGPT Security Issue Enabled Data Theft via Single Prompt

Infosecurity Magazine · Infosecurity Magazine · 2026-03-31 13:01 UTC

OpenAI has patched vulnerability, which Check Point said was because of a DNS loophole

Download: 2026 SANS Identity Threats &#038; Defenses Survey

Help Net Security · Help Net Security · 2026-03-31 13:00 UTC

New research from the 2026 SANS Identity Threats &#038; Defenses Survey shows that 55% of organizations experienced an identity-related compromise last year, while 26% reported MFA fatigue as a factor...

NewsEnzoicWhitepapers and webinars

Arm says agentic AI needs a new kind of CPU. Intel's DC chief isn't buying it

The Register · Tobias Mann · 2026-03-31 13:00 UTC

Cores it's got what agents crave Interview  In recent weeks, the likes of Nvidia and Arm have revealed CPUs designed expressly to run AI agents like OpenClaw.…

Iranian hackers target US critical infrastructure through ransomware proxies, KELA warns

State-Sponsored Cyber · 2026-03-31 13:00 UTC
State-Sponsored Cyber

Is Your Repository Ready for What&#8217;s Next?

Security Boulevard · Michael Prescott · 2026-03-31 13:00 UTC

Most software teams don't start out planning to adopt an enterprise artifact repository. The post Is Your Repository Ready for What&#8217;s Next? appeared first on Security Boulevard.

Security Bloggers Networkartifact repositorydependenciesEnterprise Repository ManagementNexus Repository

Bitdefender Launches Complimentary Internal Attack Surface Assessment to Help Organizations Uncover Hidden Cyber Risk

Cyber Attacks · 2026-03-31 13:00 UTC
Cyber Attacks

Initial Access Brokers have Shifted to High-Value Targets and Premium Pricing

Rapid7 · Rapid7 Labs · 2026-03-31 13:00 UTC

Initial Access Brokers (IABs) are a key component of the cybercrime ecosystem, offering hassle-free building blocks for ransomware, data theft, and extortion. Rapid7’s analysis of H2 2025 activity acr...

LabsPhishingDark Web

Introducing Programmable Flow Protection: custom DDoS mitigation logic for Magic Transit customers

Cloudflare Blog · Cloudflare Blog · 2026-03-31 13:00 UTC

Magic Transit customers can now program their own DDoS mitigation logic and deploy it across Cloudflare’s global network. This enables precise, stateful mitigation for custom and proprietary UDP proto...

BetaDDoSUDPeBPFMagic Transit

Initial Access Brokers have Shifted to High-Value Targets and Premium Pricing

Rapid7 Cybersecurity Blog · Rapid7 Labs · 2026-03-31 13:00 UTC

Initial Access Brokers (IABs) are a key component of the cybercrime ecosystem, offering hassle-free building blocks for ransomware, data theft, and extortion. Rapid7’s analysis of H2 2025 activity acr...

LabsPhishingDark Web

AI Has Flooded All the Weather Apps

Feed: All Latest · Boone Ashworth · 2026-03-31 13:00 UTC

Weather forecasting has gotten a big boost from machine learning. How that translates into what users see can vary.

GearGear / Gear News and EventsGear / Products / Apps

What’s new in Tenable Cloud Security: Custom policies, AWS ABAC, and research-driven protection

Security Boulevard · Yoel Calderon · 2026-03-31 13:00 UTC

Stop the noise and scale your cloud security. Our latest updates introduce custom policy automation via Explorer, AWS ABAC support for true least privilege, and research-backed protection against crit...

Security Bloggers Network

With its new app store, Ring bets on AI to go beyond home security

TechCrunch · Sarah Perez · 2026-03-31 13:00 UTC

Ring's app store will allow the company to target broader use cases beyond security, like elder care or business needs.

HardwareAIAppsAmazonRing

APT groups and ransomware gangs are turning Singapore into prime cyber target, Cyfirma report finds

APT Groups · 2026-03-31 12:55 UTC
APT Groups

Axios Software Tool Used by Millions Compromised in Hack

Bloomberg Cyber · 2026-03-31 12:51 UTC
Bloomberg Cyber

Windows Tools Abused to Kill AV Ahead of Ransomware Attacks

GBHackers · GBHackers · 2026-03-31 12:51 UTC

Hackers are increasingly turning legitimate Windows administration tools into stealthy weapons to disable antivirus and EDR before launching ransomware, making attacks faster, quieter, and harder to s...

cyber securityCyber Security NewsRansomwareWindows

Windows 11 gets a rebuilt console engine with regex search, Sixel images and a 10x speed boost

Help Net Security · Anamarija Pogorelec · 2026-03-31 12:48 UTC

Microsoft released Windows 11 Insider Preview Build 29558.1000 to the Canary Channel, part of the optional 29500 build series. The build carries a set of changes focused on the Windows Console, a hand...

NewsMicrosoftWindows

Apple counters ClickFix attacks with macOS Terminal warning

Help Net Security · Sinisa Markovic · 2026-03-31 12:43 UTC

Apple has added a new security feature in macOS Tahoe 26.4 that warns users before they enter commands in Terminal that could cause harm. The goal is to stop ClickFix attacks, a social engineering tri...

NewsApplecybersecuritymacOSmalware

Axios NPM Packages Breached in Ongoing Supply Chain Attack

GBHackers · GBHackers · 2026-03-31 12:40 UTC

A severe supply chain attack has compromised the widely used Axios HTTP client on the npm registry. Attackers injected a malicious dependency into specific Axios releases, exposing millions of develop...

Cyber Security News

Google is now letting users in the US change their Gmail address

TechCrunch · Ivan Mehta · 2026-03-31 12:30 UTC

Users will be able to change their username only once every 12 months. Plus, they won't be able to delete their new email address for that period of time.

AppsgmailGoogleusername

В Еврокомиссии сообщили о взломе и утечке данных

Xakep · Мария Нефёдова · 2026-03-31 12:30 UTC

Европейская комиссия сообщила об утечке данных после взлома облачной инфраструктуры, на которой размещены сайты платформы Europa[.]eu. Инцидент обнаружили еще 24 марта, и атака затронула как минимум о...

НовостиShinyHuntersВзломЕврокомиссияКибератаки

As electric truck demand craters, GM lays off workers and idles plant

Ars Technica · Jonathan M. Gitlin · 2026-03-31 12:28 UTC

Factory Zero went idle on March 16, workers expected to return April 13.

CarsEV adoptionGeneral Motors

Конвергенция NGFW и SASE: гибридная модель защиты для распределённых команд. Когда периметр теряет смысл

Habr InfoSec · Ideco (Ideco) · 2026-03-31 12:28 UTC

Классическая архитектура сетевой безопасности строилась вокруг одной предпосылки: существует чёткая граница между «внутри» и «снаружи». Межсетевой экран нового поколения (NGFW) стоит на этой границе и...

NGFWSASEZTNAZero TrustSD-WAN

CVE-2026-3139 - User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor <= 3.15.5 - Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary Post Author Reassignment via Avatar Field

CVE Feed · CVE Feed · 2026-03-31 12:16 UTC

CVE ID :CVE-2026-3139 Published : March 31, 2026, 12:16 p.m. | 1 hour, 28 minutes ago Description :The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Edi...

CVE-2026-3191 - Minify HTML <= 2.1.12 - Cross-Site Request Forgery to Plugin Settings Update

CVE Feed · CVE Feed · 2026-03-31 12:16 UTC

CVE ID :CVE-2026-3191 Published : March 31, 2026, 12:16 p.m. | 1 hour, 28 minutes ago Description :The Minify HTML plugin for WordPress is vulnerable to Cross-Site Request Forgery in all ver...

CVE-2026-4267 - Query Monitor <= 3.20.3 - Reflected Cross-Site Scripting via Request URI

CVE Feed · CVE Feed · 2026-03-31 12:16 UTC

CVE ID :CVE-2026-4267 Published : March 31, 2026, 12:16 p.m. | 1 hour, 28 minutes ago Description :The Query Monitor – The developer tools panel for WordPress plugin for WordPress is vulnera...

CVE-2026-5198 - code-projects Student Membership System Admin Login index.php sql injection

CVE Feed · CVE Feed · 2026-03-31 12:16 UTC

CVE ID :CVE-2026-5198 Published : March 31, 2026, 12:16 p.m. | 1 hour, 28 minutes ago Description :A vulnerability was determined in code-projects Student Membership System 1.0. The impacted...

CVE-2026-32988 - OpenClaw < 2026.3.11 - Sandbox Boundary Bypass via Unvalidated Temporary File Creation

CVE Feed · CVE Feed · 2026-03-31 12:16 UTC

CVE ID :CVE-2026-32988 Published : March 31, 2026, 12:16 p.m. | 1 hour, 28 minutes ago Description :OpenClaw before 2026.3.11 contains a sandbox boundary bypass vulnerability in fs-bridge st...